1. Cross-site scripting (reflected)
1.1. http://www.olark.com/signup/create_new_account [user%5Bemail%5D parameter]
1.2. http://www.olark.com/signup/create_new_account [user%5Bemail%5D parameter]
1.3. http://www.olark.com/signup/create_new_account [user%5Bemail%5D parameter]
1.4. http://www.olark.com/signup/create_new_account [user%5Busername%5D parameter]
2. Cleartext submission of password
2.1. http://www.olark.com/account/login
2.2. http://www.olark.com/signup/create_new_account
3. Cookie without HttpOnly flag set
3.1. http://www.olark.com/about
3.2. http://www.olark.com/account/login
3.3. http://www.olark.com/features
3.4. http://www.olark.com/plans
3.5. http://www.olark.com/signup/create_new_account
4. Password field with autocomplete enabled
4.1. http://www.olark.com/account/login
4.2. http://www.olark.com/signup/create_new_account
6. Social security numbers disclosed
6.1. http://www.olark.com/about
6.2. http://www.olark.com/account/login
6.3. http://www.olark.com/assets/common.js
6.4. http://www.olark.com/features
6.5. http://www.olark.com/plans
6.6. http://www.olark.com/signup/create_new_account
6.7. http://www.olark.com/stylesheets/compiled/print.css
6.8. http://www.olark.com/stylesheets/compiled/screen.css
7. Content type is not specified
7.1. http://www.olark.com/assets/common.js
7.2. http://www.olark.com/stylesheets/compiled/print.css
7.3. http://www.olark.com/stylesheets/compiled/screen.css
Severity: | High |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /signup/create_new |
GET /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive Referer: http://www.olark.com Cache-Control: max-age=0 Origin: http://www.olark.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:54:39 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "920efee028f097fd73f X-Runtime: 158 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 23004 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... </script>5ee3b<script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /signup/create_new |
POST /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive Referer: http://www.olark.com Content-Length: 191 Cache-Control: max-age=0 Origin: http://www.olark.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e user%5Busername%5D=&user |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:54:32 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "003fbc8753613adc304 X-Runtime: 282 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 23413 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <script>var hbl_to_set_username="44466";alert(1)/ ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /signup/create_new |
GET /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive Referer: http://www.olark.com Cache-Control: max-age=0 Origin: http://www.olark.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:54:29 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "f99b1c2dbb830ba4a63 X-Runtime: 160 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 22952 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <input type="text" value="3f59d"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /signup/create_new |
GET /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive Referer: http://www.olark.com Cache-Control: max-age=0 Origin: http://www.olark.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:54:23 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "c26169d7ee62a391fb1 X-Runtime: 130 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 23006 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <input type="text" value="4b89a"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /account/login |
GET /account/login HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:00 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "8cd3f804092786bb7af X-Runtime: 13 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 11776 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <div class='prepend-2 span-9 colborder'> <form action="login" id="loginform" method="post"> <ul class='label-left half_width'> ...[SNIP]... </label> <input id="password" name="password" type="password" /> <input id="old" name="old" type="hidden" /> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /signup/create_new |
GET /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:03 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "25c7afdb94b8a957ff7 X-Runtime: 173 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 22903 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <div class='span-16'> <form action="/signup/create <ul class='label-top'> ...[SNIP]... </label> <input id="user_password" name="user[password]" size="30" type="password" /> </div> ...[SNIP]... </label> <input id="user_password </div> ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.olark.com |
Path: | /about |
GET /about HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:42:58 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "bf3a914387de784c374 X-Runtime: 94 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 11481 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.olark.com |
Path: | /account/login |
GET /account/login HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:00 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "8cd3f804092786bb7af X-Runtime: 13 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 11776 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.olark.com |
Path: | /features |
GET /features HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:42:53 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "d327c6e4b616c33c9eb X-Runtime: 115 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 20057 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.olark.com |
Path: | /plans |
GET /plans HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:42:56 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "73585166b16790be50e X-Runtime: 482 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 34761 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www.olark.com |
Path: | /signup/create_new |
GET /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:03 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "25c7afdb94b8a957ff7 X-Runtime: 173 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 22903 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /account/login |
GET /account/login HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:00 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "8cd3f804092786bb7af X-Runtime: 13 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 11776 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <div class='prepend-2 span-9 colborder'> <form action="login" id="loginform" method="post"> <ul class='label-left half_width'> ...[SNIP]... </label> <input id="password" name="password" type="password" /> <input id="old" name="old" type="hidden" /> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /signup/create_new |
GET /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:03 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "25c7afdb94b8a957ff7 X-Runtime: 173 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 22903 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <div class='span-16'> <form action="/signup/create <ul class='label-top'> ...[SNIP]... </label> <input id="user_password" name="user[password]" size="30" type="password" /> </div> ...[SNIP]... </label> <input id="user_password </div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /signup/create_new |
POST /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive Referer: http://www.olark.com Content-Length: 279 Cache-Control: max-age=0 Origin: http://www.olark.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e user%5Busername%5D ...[SNIP]... |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:53:54 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "ea24fab43fd14048f9d X-Runtime: 517 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 23525 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... <input type="text" value="dsfgkld@rfjhg.com" name="user[username]"> ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /about |
GET /about HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:42:58 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "bf3a914387de784c374 X-Runtime: 94 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 11481 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... eturn"static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /account/login |
GET /account/login HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:00 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "8cd3f804092786bb7af X-Runtime: 13 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 11776 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... eturn"static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /assets/common.js |
GET /assets/common.js Host: www.olark.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.olark.com Cookie: rack_session=BAh7Czo If-Modified-Since: Fri, 03 Jun 2011 20:36:18 GMT If-None-Match: "57937f-102f8-4a4d4b |
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-type" content="text/html; charset=UTF-8" /> <title>Cleaning House!</title> <style type="text/ ...[SNIP]... rn "static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /features |
GET /features HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:42:53 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "d327c6e4b616c33c9eb X-Runtime: 115 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 20057 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... eturn"static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /plans |
GET /plans HTTP/1.1 Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:42:56 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "73585166b16790be50e X-Runtime: 482 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 34761 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Bzo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... eturn"static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /signup/create_new |
GET /signup/create_new Host: www.olark.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: uuid=7967ed3c59ef93e |
HTTP/1.1 200 OK Date: Sat, 04 Jun 2011 21:43:03 GMT Server: Apache/2.2.11 (Ubuntu) Phusion_Passenger/3.0.4 PHP/5.2.10-2ubuntu6 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8o X-Powered-By: Phusion Passenger (mod_rails/mod_rack) 3.0.4 ETag: "25c7afdb94b8a957ff7 X-Runtime: 173 Cache-Control: private, max-age=0, must-revalidate Status: 200 Vary: Accept-Encoding,User Content-Length: 22903 Content-Type: text/html; charset=utf-8 Set-Cookie: rack_session=BAh7Czo Set-Cookie: _habla_session_id Via: 1.1 web2.local <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <script type='text/javascript'> //<![CDATA[ ...[SNIP]... eturn"static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /stylesheets/compiled |
GET /stylesheets/compiled Host: www.olark.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.olark.com Cookie: rack_session=BAh7Czo If-Modified-Since: Fri, 03 Jun 2011 20:42:06 GMT If-None-Match: "93005f-3cb-4a4d4c9698380 Cache-Control: max-age=0 |
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-type" content="text/html; charset=UTF-8" /> <title>Cleaning House!</title> <style type="text/ ...[SNIP]... rn "static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Tentative |
Host: | http://www.olark.com |
Path: | /stylesheets/compiled |
GET /stylesheets/compiled Host: www.olark.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.olark.com Cookie: rack_session=BAh7Czo If-Modified-Since: Sat, 04 Jun 2011 13:22:34 GMT If-None-Match: "93005c-2bf75-4a4e2c Cache-Control: max-age=0 |
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-type" content="text/html; charset=UTF-8" /> <title>Cleaning House!</title> <style type="text/ ...[SNIP]... rn "static.olark.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /assets/common.js |
GET /assets/common.js Host: www.olark.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.olark.com Cookie: rack_session=BAh7Czo If-Modified-Since: Fri, 03 Jun 2011 20:36:18 GMT If-None-Match: "57937f-102f8-4a4d4b |
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-type" content="text/html; charset=UTF-8" /> <title>Cleaning House!</title> <style type="text/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /stylesheets/compiled |
GET /stylesheets/compiled Host: www.olark.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.olark.com Cookie: rack_session=BAh7Czo If-Modified-Since: Fri, 03 Jun 2011 20:42:06 GMT If-None-Match: "93005f-3cb-4a4d4c9698380 Cache-Control: max-age=0 |
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-type" content="text/html; charset=UTF-8" /> <title>Cleaning House!</title> <style type="text/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.olark.com |
Path: | /stylesheets/compiled |
GET /stylesheets/compiled Host: www.olark.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.olark.com Cookie: rack_session=BAh7Czo If-Modified-Since: Sat, 04 Jun 2011 13:22:34 GMT If-None-Match: "93005c-2bf75-4a4e2c Cache-Control: max-age=0 |
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="content-type" content="text/html; charset=UTF-8" /> <title>Cleaning House!</title> <style type="text/ ...[SNIP]... |