1. Cross-site scripting (reflected)
1.1. http://store.jawbone.com/DRHM/store [Action parameter]
1.2. http://store.jawbone.com/DRHM/store [name of an arbitrarily supplied request parameter]
2. Cookie without HttpOnly flag set
2.1. http://store.jawbone.com/store/aliphcom/DisplayHomePage
2.2. http://store.jawbone.com/store/aliphcom/cat/CategoryID.52440000/
2.3. http://store.jawbone.com/store/aliphcom/cat/CategoryID.52440300/
3. Cross-domain script include
3.1. http://store.jawbone.com/store/aliphcom/DisplayHomePage
3.2. http://store.jawbone.com/store/aliphcom/cat/CategoryID.52440000/
3.3. http://store.jawbone.com/store/aliphcom/cat/CategoryID.52440300/
3.4. http://store.jawbone.com/store/aliphcom/en_US/home
4. Private IP addresses disclosed
4.1. http://store.jawbone.com/store/aliphcom/DisplayHomePage
4.2. http://store.jawbone.com/store/aliphcom/DisplayHomePage
4.3. http://store.jawbone.com/store/aliphcom/cat/CategoryID.52440000/
4.4. http://store.jawbone.com/store/aliphcom/cat/CategoryID.52440300/
5. Content type incorrectly stated
5.1. http://store.jawbone.com/DRHM/store
5.2. http://store.jawbone.com/favicon.ico
Severity: | High |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://store.jawbone.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/html, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 10:58:47 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Content-Length: 43336 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... ibutes: ['platform', 'miniCartImage'] } }); // Initialize the MiniCart MiniCart.init({ progressBarTop: 'DYNAMIC', errorText: 'Error:', environment: 'BASE', currentAction: 'DisplayPagec56d9';alert(1)/ nextActionParam: 'ACTION_OVERRIDE', xslUrl: '/DRHM/store?Action ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://store.jawbone.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml, text/xml, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/xml;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 10:58:49 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Content-Length: 497 <?xml version="1.0" encoding="UTF-8"?> <!-- REQUEST ID: TIME=1305629929731:NODE <!--!esi:include src="/store?8828e<a xmlns:a='http://www.w3 ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom |
GET /store/aliphcom Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://mytalk.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: ORA_WX_SESSION="10.1.2 Set-Cookie: JSESSIONID=491314B80 Set-Cookie: VISITOR_ID=971D4E8DF Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 10:58:48 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app54 Set-Cookie: BIGipServerp-drh-dc1pod5 Content-Length: 238317 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... <!--!esi:include src="/store?622aa--><script>alert(1)< ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom |
GET /store/aliphcom Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://mytalk.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: ORA_WX_SESSION="10.1.2 Set-Cookie: JSESSIONID=FCE84FC47 Set-Cookie: VISITOR_ID=971D4E8DF Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 10:58:34 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app55 Set-Cookie: BIGipServerp-drh-dc1pod5 Content-Length: 238177 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom/cat |
GET /store/aliphcom/cat Host: store.jawbone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=4F404B162 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Set-Cookie: ORA_WX_SESSION="10.1.2 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 37354 Date: Tue, 17 May 2011 11:06:32 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom/cat |
GET /store/aliphcom/cat Host: store.jawbone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=4F404B162 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Set-Cookie: ORA_WX_SESSION="10.1.2 Set-Cookie: ORA_WX_SESSION="10.1.2 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 37374 Date: Tue, 17 May 2011 11:06:36 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom |
GET /store/aliphcom Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://mytalk.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: ORA_WX_SESSION="10.1.2 Set-Cookie: JSESSIONID=FCE84FC47 Set-Cookie: VISITOR_ID=971D4E8DF Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 10:58:34 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app55 Set-Cookie: BIGipServerp-drh-dc1pod5 Content-Length: 238177 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... <link rel="stylesheet" href="//drh.img <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh1.img ...[SNIP]... <!-- OwnerIQ Retargeting Tag --> <script type="text/javascript" src="http://px.owneriq ...[SNIP]... <![endif]--> <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom/cat |
GET /store/aliphcom/cat Host: store.jawbone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=4F404B162 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Set-Cookie: ORA_WX_SESSION="10.1.2 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 37354 Date: Tue, 17 May 2011 11:06:32 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... <link rel="stylesheet" href="//drh.img <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh1.img ...[SNIP]... <!-- OwnerIQ Retargeting Tag --> <script type="text/javascript" src="http://px.owneriq ...[SNIP]... <![endif]--> <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom/cat |
GET /store/aliphcom/cat Host: store.jawbone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=4F404B162 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Set-Cookie: ORA_WX_SESSION="10.1.2 Set-Cookie: ORA_WX_SESSION="10.1.2 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 37374 Date: Tue, 17 May 2011 11:06:36 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... <link rel="stylesheet" href="//drh.img <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh1.img ...[SNIP]... <!-- OwnerIQ Retargeting Tag --> <script type="text/javascript" src="http://px.owneriq ...[SNIP]... <![endif]--> <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom/en_US |
GET /store/aliphcom/en_US Host: store.jawbone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=4F404B162 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 347875 Date: Tue, 17 May 2011 11:06:21 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... <link rel="stylesheet" href="//drh.img <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh1.img ...[SNIP]... <!-- OwnerIQ Retargeting Tag --> <script type="text/javascript" src="http://px.owneriq ...[SNIP]... <![endif]--> <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom |
GET /store/aliphcom Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://mytalk.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: ORA_WX_SESSION="10.1.2.211:516-0#0"; path=/ Set-Cookie: JSESSIONID=FCE84FC47 Set-Cookie: VISITOR_ID=971D4E8DF Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 10:58:34 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app55 Set-Cookie: BIGipServerp-drh-dc1pod5 Content-Length: 238177 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom |
GET /store/aliphcom Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://mytalk.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_cc=true; __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: ORA_WX_SESSION="10.1.2.196:516-0#0"; path=/ Set-Cookie: JSESSIONID=67EBE9946 Set-Cookie: VISITOR_ID=971D4E8DF Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 11:06:12 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Set-Cookie: BIGipServerp-drh-dc1pod5 Content-Length: 238175 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom/cat |
GET /store/aliphcom/cat Host: store.jawbone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=4F404B162 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Set-Cookie: ORA_WX_SESSION="10.1.2.196:516-0#0"; path=/ Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 37354 Date: Tue, 17 May 2011 11:06:32 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.jawbone.com |
Path: | /store/aliphcom/cat |
GET /store/aliphcom/cat Host: store.jawbone.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: JSESSIONID=4F404B162 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Set-Cookie: ORA_WX_SESSION="10.1.2.196:516-0#0"; path=/ Set-Cookie: ORA_WX_SESSION="10.1.2.196:516-0#0"; path=/ Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 37374 Date: Tue, 17 May 2011 11:06:36 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <head> <!--!esi:include src="/esi?Sit ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://store.jawbone.com |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: store.jawbone.com Proxy-Connection: keep-alive Referer: http://store.jawbone.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/html, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=217104781 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/css;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Tue, 17 May 2011 10:58:35 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app52 Content-Length: 6614 <!-- REQUEST ID: TIME=1305629915230:NODE <!--!esi:include src="/store?Action ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://store.jawbone.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: store.jawbone.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: ORA_WX_SESSION="10.1.2.73 |
HTTP/1.1 200 OK ETag: "37e-4b6b21a0" Content-Type: text/plain Last-Modified: Thu, 04 Feb 2010 19:36:00 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 894 Date: Tue, 08 Feb 2011 04:10:09 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb02@dc1app58 Accept-Ranges: bytes ..............h.......(.. .....tOL+. ...Q. ...[SNIP]... |