1. Cross-site scripting (reflected)
1.1. http://www.businessreviewcanada.ca/ [search_terms parameter]
1.2. http://www.businessreviewcanada.ca/site-search [keys parameter]
2. Cleartext submission of password
2.1. http://www.businessreviewcanada.ca/
2.2. http://www.businessreviewcanada.ca/site-search
2.3. http://www.businessreviewcanada.ca/sites/default/files/imagecache/Slide_Front_430/
3. Cookie scoped to parent domain
4. Cookie without HttpOnly flag set
5. Password field with autocomplete enabled
5.1. http://www.businessreviewcanada.ca/
5.2. http://www.businessreviewcanada.ca/site-search
5.3. http://www.businessreviewcanada.ca/site-search
5.4. http://www.businessreviewcanada.ca/site-search
5.5. http://www.businessreviewcanada.ca/sites/default/files/imagecache/Slide_Front_430/
6. Cross-domain Referer leakage
6.1. http://www.businessreviewcanada.ca/campaign/46654
6.2. http://www.businessreviewcanada.ca/site-search
7. Cross-domain script include
7.1. http://www.businessreviewcanada.ca/
7.2. http://www.businessreviewcanada.ca/campaign/46654
7.3. http://www.businessreviewcanada.ca/site-search
7.4. http://www.businessreviewcanada.ca/sites/default/files/imagecache/Slide_Front_430/
Severity: | High |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | / |
POST / HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Content-Type: application/x-www-form Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESS9cb10c66ca2495c4 Content-Length: 118 search_type=&search_terms |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:25:28 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Tue, 14 Dec 2010 15:25:28 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 Content-Length: 30357 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <span class="icon">Site Search: ''6b983<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /site-search |
GET /site-search?type=All Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:23:44 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Tue, 14 Dec 2010 15:23:45 GMT Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 Content-Length: 30353 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <span class="icon">Site Search: ''9703a<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | / |
GET / HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.businessreviewcanada |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:16 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Set-Cookie: SESS9cb10c66ca2495c4 Last-Modified: Tue, 14 Dec 2010 15:09:20 GMT ETag: "ae992ecc3ff8bcafb56 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81790 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/" accept-charset="UTF-8" method="post" id="user-login" class=" compact-form"> <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /site-search |
GET /site-search?type=All Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:57 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:55 GMT ETag: "b9581c9900577508d82 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 31281 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/site-search?type <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /sites/default/files |
GET /sites/default/files Accept: */* Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 404 Not Found Date: Tue, 14 Dec 2010 15:19:46 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:45 GMT ETag: "bf53aa3087040a921b1 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81884 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/sites/default <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.businessr |
Path: | / |
GET / HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.businessreviewcanada |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:16 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Set-Cookie: SESS9cb10c66ca2495c4 Last-Modified: Tue, 14 Dec 2010 15:09:20 GMT ETag: "ae992ecc3ff8bcafb56 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81790 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.businessr |
Path: | / |
GET / HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.businessreviewcanada |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:16 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Set-Cookie: SESS9cb10c66ca2495c4 Last-Modified: Tue, 14 Dec 2010 15:09:20 GMT ETag: "ae992ecc3ff8bcafb56 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81790 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | / |
GET / HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.businessreviewcanada |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:16 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Set-Cookie: SESS9cb10c66ca2495c4 Last-Modified: Tue, 14 Dec 2010 15:09:20 GMT ETag: "ae992ecc3ff8bcafb56 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81790 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/" accept-charset="UTF-8" method="post" id="user-login" class=" compact-form"> <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /site-search |
GET /site-search?type=All Host: www.businessreviewcanada Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:33:06 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:25:49 GMT ETag: "3ec6a59dcb5be7c5d89 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 30345 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/site-search?type <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /site-search |
GET /site-search?type=All Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:57 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:55 GMT ETag: "b9581c9900577508d82 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 31281 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/site-search?type <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /site-search |
GET /site-search?type=All Host: www.businessreviewcanada Proxy-Connection: keep-alive Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:34:49 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:26:22 GMT ETag: "82e7de8fffab43c643c Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 30399 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/site-search?type <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /sites/default/files |
GET /sites/default/files Accept: */* Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 404 Not Found Date: Tue, 14 Dec 2010 15:19:46 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:45 GMT ETag: "bf53aa3087040a921b1 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81884 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <td id="header-top"><form action="/sites/default <div> ...[SNIP]... </label> <input type="password" name="pass" id="edit-pass" maxlength="128" size="60" tabindex="2" class="form-text required" /> <div class="description"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /campaign/46654 |
GET /campaign/46654?KeepThis Host: www.businessreviewcanada Proxy-Connection: keep-alive Referer: http://www.businessr Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:31:15 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:07 GMT ETag: "677133ff133ac0c8e38 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 10028 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <script src='http://92.48.64.247 ...[SNIP]... </ul> <img src="http://email </div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /site-search |
GET /site-search?type=All Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:57 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:55 GMT ETag: "b9581c9900577508d82 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 31281 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <script src='http://92.48.64.247 ...[SNIP]... <noscript><a target='_blank' href='http://92.48.64.247 ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <a href="javascript:void(0); ...[SNIP]... <noscript><a target='_blank' href='http://92.48.64.247 ...[SNIP]... <div id="footer-message"> Copyright 2010 by White Digital Media Group. All rights reserved | <a href="http://www.whitedm ...[SNIP]... <noscript> <img height="1" width="1" alt="" style="display:none;" src="http://www </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | / |
GET / HTTP/1.1 Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Proxy-Connection: Keep-Alive Host: www.businessreviewcanada |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:16 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Set-Cookie: SESS9cb10c66ca2495c4 Last-Modified: Tue, 14 Dec 2010 15:09:20 GMT ETag: "ae992ecc3ff8bcafb56 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81790 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <script src='http://92.48.64.247 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /campaign/46654 |
GET /campaign/46654?KeepThis Host: www.businessreviewcanada Proxy-Connection: keep-alive Referer: http://www.businessr Accept: application/xml User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:31:15 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:07 GMT ETag: "677133ff133ac0c8e38 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 10028 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <script src='http://92.48.64.247 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /site-search |
GET /site-search?type=All Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-ms Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Pragma: no-cache Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:19:57 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:55 GMT ETag: "b9581c9900577508d82 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 31281 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <script src='http://92.48.64.247 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /sites/default/files |
GET /sites/default/files Accept: */* Referer: http://www.businessr Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729) Accept-Encoding: gzip, deflate Host: www.businessreviewcanada Proxy-Connection: Keep-Alive Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 404 Not Found Date: Tue, 14 Dec 2010 15:19:46 GMT Server: Apache/2.2.12 (Ubuntu) X-Powered-By: PHP/5.2.10-2ubuntu6.5 Last-Modified: Tue, 14 Dec 2010 15:19:45 GMT ETag: "bf53aa3087040a921b1 Expires: Sun, 19 Nov 1978 05:00:00 GMT Cache-Control: must-revalidate Content-Type: text/html; charset=utf-8 Content-Length: 81884 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <script src='http://92.48.64.247 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.businessr |
Path: | /sites/default/files/js |
GET /sites/default/files/js Host: www.businessreviewcanada Proxy-Connection: keep-alive Referer: http://www.businessr Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SESS9cb10c66ca2495c4 |
HTTP/1.1 200 OK Date: Tue, 14 Dec 2010 15:25:46 GMT Server: Apache/2.2.12 (Ubuntu) Last-Modified: Tue, 14 Dec 2010 12:09:12 GMT Accept-Ranges: bytes Cache-Control: max-age=7200 Expires: Tue, 14 Dec 2010 17:25:46 GMT Vary: Accept-Encoding Content-Type: application/javascript Content-Length: 206451 // $Id: jquery.js,v 1.12.2.3 2008/06/25 09:38:39 goba Exp $ /* * jQuery 1.2.6 - New Wave Javascript * * Copyright (c) 2008 John Resig (jquery.com) * Dual licensed under the MIT (MIT-LICENSE.txt) ...[SNIP]... <a href="http://user:pass@example.com"> ...[SNIP]... |