1. Cross-site scripting (reflected)
3. SSL cookie without secure flag set
4. Cookie without HttpOnly flag set
5. Password field with autocomplete enabled
6.1. https://console.iservices.net.nz/
6.2. https://console.iservices.net.nz/
7. Cross-domain script include
9.1. https://console.iservices.net.nz/
9.2. https://console.iservices.net.nz/scripts/jquery.pngFix.pack.js
11. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
GET /?d729d"><script>alert(1)< Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:41 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <input type="hidden" name="d729d"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: console.iservices.net.nz |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 17:33:30 GMT Server: Apache Last-Modified: Sat, 29 May 2010 23:33:46 GMT ETag: "5c820f-c9-487c40e0e4a80" Accept-Ranges: bytes Content-Length: 201 Connection: close Content-Type: text/xml <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://console.iservices |
Path: | / |
GET / HTTP/1.1 Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:28 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://console.iservices |
Path: | / |
GET / HTTP/1.1 Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:28 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
GET / HTTP/1.1 Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:28 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <div style="display: ;" id="divLogin"> <form action="/account/login/" method="post" style="display: inline;" name="loginForm"> <table width="100%" border="0" cellspacing="0" cellpadding="0"> ...[SNIP]... <td colspan="2" class="dataTableMainCell" style="padding: 5px 5px 5px 25px;"> <input name="parameters[password ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
GET / HTTP/1.1 Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:28 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... </p> <form id="account" name="accountlogin" action="https://orcres <fieldset> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
GET / HTTP/1.1 Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:28 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... </a> <form id='site-search' name='site-search' method="post" action="http://www.orcon <div class='hiddenFields'> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
GET / HTTP/1.1 Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:28 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... </script> <script type="text/javascript" src="https://www.orcon ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
TRACE / HTTP/1.0 Host: console.iservices.net.nz Cookie: a98c30c650d097a6 |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 17:33:29 GMT Server: Apache Connection: close Content-Type: message/http TRACE / HTTP/1.0 Host: console.iservices.net.nz Cookie: a98c30c650d097a6 |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
GET / HTTP/1.1 Host: console.iservices.net.nz Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.0 200 OK Date: Sun, 15 May 2011 17:33:28 GMT Server: Apache X-Powered-By: PHP/5.3.0 Set-Cookie: ISERVICES_SESSID Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Connection: close Content-Type: text/html; charset=UTF-8 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" cont ...[SNIP]... <a href="mailto:hostingsales@orcon.net.nz"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | /scripts/jquery.pngFix |
GET /scripts/jquery.pngFix Host: console.iservices.net.nz Connection: keep-alive Referer: https://console.iservices User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ISERVICES_SESSID |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 17:36:27 GMT Server: Apache Last-Modified: Sat, 29 May 2010 23:33:47 GMT ETag: "5d0a51-9bf-487c40e1d8cc0 Accept-Ranges: bytes Content-Length: 2495 Connection: close Content-Type: application/x-javascript /** * ------------------------- * jQuery-Plugin "pngFix" * Version: 1.1, 11.09.2007 * by Andreas Eberhard, andreas.eberhard@gmail * http://jquery.andrea * * Copyright (c) 2007 Andreas Eberhard * Licensed under GPL (http://www.opensource */ eval(function(p ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: console.iservices.net.nz User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: ISERVICES_SESSID |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 17:57:43 GMT Server: Apache Last-Modified: Sat, 29 May 2010 23:33:46 GMT ETag: "5c8220-47e-487c40e0e4a80 Accept-Ranges: bytes Content-Length: 1150 Connection: close Content-Type: text/plain; charset=UTF-8 ............ .h.......(....... ..... ......................... ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | https://console.iservices |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: console.iservices.net.nz User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: ISERVICES_SESSID |
HTTP/1.1 200 OK Date: Sun, 15 May 2011 17:57:43 GMT Server: Apache Last-Modified: Sat, 29 May 2010 23:33:46 GMT ETag: "5c8220-47e-487c40e0e4a80 Accept-Ranges: bytes Content-Length: 1150 Connection: close Content-Type: text/plain; charset=UTF-8 ............ .h.......(....... ..... ......................... ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | https://console.iservices |
Path: | / |
Issued to: | console.iservices.net.nz |
Issued by: | UTN-USERFirst-Hardware |
Valid from: | Sun Aug 01 19:00:00 CDT 2010 |
Valid to: | Thu Sep 22 18:59:59 CDT 2011 |
Issued to: | UTN-USERFirst-Hardware |
Issued by: | AddTrust External CA Root |
Valid from: | Tue Jun 07 03:09:10 CDT 2005 |
Valid to: | Sat May 30 05:48:38 CDT 2020 |
Issued to: | AddTrust External CA Root |
Issued by: | AddTrust External CA Root |
Valid from: | Tue May 30 05:48:38 CDT 2000 |
Valid to: | Sat May 30 05:48:38 CDT 2020 |