1. Cross-site scripting (stored)
1.1. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp [REST URL parameter 2]
1.2. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp [REST URL parameter 2]
2. Cross-site scripting (reflected)
2.1. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp [sourceid parameter]
2.2. http://www.pogo.com/login/Scripts/AC_RunActiveContent.js [Referer HTTP header]
2.3. http://www.pogo.com/login/entry.jsp [Referer HTTP header]
2.4. http://www.pogo.com/login/media/Pogo_General_LP_2.swf [Referer HTTP header]
2.5. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp [Referer HTTP header]
3.1. http://www.pogo.com/login/Scripts/AC_RunActiveContent.js
3.2. http://www.pogo.com/login/media/Pogo_General_LP_2.swf
3.3. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp
4. Cross-domain Referer leakage
4.1. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp
4.2. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp
4.3. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp
4.4. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp
4.5. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp
4.6. http://www.pogo.com/pogo-online-games/lp-GeneralPogo-withoutFB.jsp
6. Content type incorrectly stated
7. Content type is not specified
Severity: | High |
Confidence: | Firm |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:30:21 GMT Server: Apache-Coyote/1.1 Content-Length: 12389 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... } } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="Template without FB Marketing Landing Page"; s.prop2=" ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: prod.JID=3E01A5E24CD |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: prod.JID=3E01A5E24CD |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:30:29 GMT Server: Apache-Coyote/1.1 Content-Length: 12410 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... } } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="Template without FB Marketing Landing Page"; s.prop2="pogo ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:30:22 GMT Server: Apache-Coyote/1.1 Content-Length: 12595 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... linkTrackVars + 'events';} s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="Template without FB Marketing Landing Page"; s.prop2="pogo"; s.eVar12="6618690632 s.campaign="free_internet ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /login/Scripts/AC |
GET /login/Scripts/AC Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.google.com Cookie: com.pogo.site=pogo; s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 404 /login/Scripts/AC Expires: 0 Cache-Control: max-age=0, private Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:38:24 GMT Server: Apache-Coyote/1.1 Content-Length: 4044 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Pogo: Error: Invalid URL </title> ...[SNIP]... =s.linkTrackVars + 'prop6,' } } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="ERROR: Invalid URL Page"; s.prop2="pogo"; s.channel="pogo"; s.prop7="POGO:pogo:error: s.prop8="Non Authenticated"; if (typeof( ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /login/entry.jsp |
GET /login/entry.jsp?sl=1 Host: www.pogo.com Proxy-Connection: keep-alive Referer: http://www.google.com Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: com.pogo.site=pogo; s_pers=%20s_nr%3D130 |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:37:55 GMT Server: Apache-Coyote/1.1 Content-Length: 12481 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... =s.linkTrackVars + 'prop6,' } } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="Template without FB Marketing Landing Page"; s.prop2="pogo"; s.eVar12="6618939740 s.campaign="free_internet ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /login/media/Pogo_General |
GET /login/media/Pogo_General Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.google.com Cookie: com.pogo.site=pogo; s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 404 /login/media/Pogo_General Expires: 0 Cache-Control: max-age=0, private Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:38:25 GMT Server: Apache-Coyote/1.1 Content-Length: 4044 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Pogo: Error: Invalid URL </title> ...[SNIP]... =s.linkTrackVars + 'prop6,' } } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="ERROR: Invalid URL Page"; s.prop2="pogo"; s.channel="pogo"; s.prop7="POGO:pogo:error: s.prop8="Non Authenticated"; if (typeof( ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Referer: http://www.google.com |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:30:22 GMT Server: Apache-Coyote/1.1 Content-Length: 12270 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... =s.linkTrackVars + 'prop6,' } } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="Template without FB Marketing Landing Page"; s.prop2="pogo"; s.eVar12="6618690632 s.campaign="free_internet s.channel="g ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.pogo.com |
Path: | /login/Scripts/AC |
GET /login/Scripts/AC Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.pogo.com/login Cookie: com.pogo.site=pogo; s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 404 /login/Scripts/AC Expires: 0 Cache-Control: max-age=0, private Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:38:23 GMT Server: Apache-Coyote/1.1 Content-Length: 4347 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Pogo: Error: Invalid URL </title> ...[SNIP]... nkTrackVars=s.linkTr } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="ERROR: Invalid URL Page"; s.prop2="pogo"; s.channel="pogo"; s.prop7="POGO:pogo:error: s.prop8="Non Authenticated"; if (typeof(omniture_java if (typeof(omniture_plugin s.eVar10=s.getTimeParting s.retrieveLightProfiles = 'lsccmp'; var s_code=s.t();if(s_code //--></script> </div> <!-- end of Omniture Tag --> <div class="clear20"></div> <div align="center"> <img src="http://cdn.pogo.com <div id="bodyWrap"> <div class="whiteModule" id="pageHeader"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> Oops, something is not right... </div> <b class="bL"> </b><b class="bR"> </b> </div> <div class="clear10"></div> <div class="whiteModule mainContent"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> <h1>The page you requested could not be found.</h1> <p>Please check the URL for proper spelling and capitalization. If you're having trouble finding a particular page try visiting the<br /> <strong><a href="http://www.pogo.com <div class="clear20"></div> </div> <b class="bL"> </b><b class="bR"> </b> </div> </div> </div> </body> </html> |
GET /login/Scripts/AC Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: com.pogo.site=pogo; s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 404 /login/Scripts/AC Expires: 0 Cache-Control: max-age=0, private Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:38:23 GMT Server: Apache-Coyote/1.1 Content-Length: 4013 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Pogo: Error: Invalid URL </title> ...[SNIP]... nkTrackVars=s.linkTr } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="ERROR: Invalid URL Page"; s.prop2="pogo"; s.channel="pogo"; s.prop7="POGO:pogo:error: s.prop8="Non Authenticated"; if (typeof(omniture_java if (typeof(omniture_plugin s.eVar10=s.getTimeParting s.retrieveLightProfiles = 'lsccmp'; var s_code=s.t();if(s_code //--></script> </div> <!-- end of Omniture Tag --> <div class="clear20"></div> <div align="center"> <img src="http://cdn.pogo.com <div id="bodyWrap"> <div class="whiteModule" id="pageHeader"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> Oops, something is not right... </div> <b class="bL"> </b><b class="bR"> </b> </div> <div class="clear10"></div> <div class="whiteModule mainContent"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> <h1>The page you requested could not be found.</h1> <p>Please check the URL for proper spelling and capitalization. If you're having trouble finding a particular page try visiting the<br /> <strong><a href="http://www.pogo.com <div class="clear20"></div> </div> <b class="bL"> </b><b class="bR"> </b> </div> </div> </div> </body> </html> |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.pogo.com |
Path: | /login/media/Pogo_General |
GET /login/media/Pogo_General Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.pogo.com/login Cookie: com.pogo.site=pogo; s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 404 /login/media/Pogo_General Expires: 0 Cache-Control: max-age=0, private Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:38:24 GMT Server: Apache-Coyote/1.1 Content-Length: 4347 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Pogo: Error: Invalid URL </title> ...[SNIP]... nkTrackVars=s.linkTr } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="ERROR: Invalid URL Page"; s.prop2="pogo"; s.channel="pogo"; s.prop7="POGO:pogo:error: s.prop8="Non Authenticated"; if (typeof(omniture_java if (typeof(omniture_plugin s.eVar10=s.getTimeParting s.retrieveLightProfiles = 'lsccmp'; var s_code=s.t();if(s_code //--></script> </div> <!-- end of Omniture Tag --> <div class="clear20"></div> <div align="center"> <img src="http://cdn.pogo.com <div id="bodyWrap"> <div class="whiteModule" id="pageHeader"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> Oops, something is not right... </div> <b class="bL"> </b><b class="bR"> </b> </div> <div class="clear10"></div> <div class="whiteModule mainContent"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> <h1>The page you requested could not be found.</h1> <p>Please check the URL for proper spelling and capitalization. If you're having trouble finding a particular page try visiting the<br /> <strong><a href="http://www.pogo.com <div class="clear20"></div> </div> <b class="bL"> </b><b class="bR"> </b> </div> </div> </div> </body> </html> |
GET /login/media/Pogo_General Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: com.pogo.site=pogo; s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 404 /login/media/Pogo_General Expires: 0 Cache-Control: max-age=0, private Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:38:25 GMT Server: Apache-Coyote/1.1 Content-Length: 4010 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html> <head> <title> Pogo: Error: Invalid URL </title> ...[SNIP]... nkTrackVars=s.linkTr } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www s.eVar2="pogo"; s.pageName="ERROR: Invalid URL Page"; s.prop2="pogo"; s.channel="pogo"; s.prop7="POGO:pogo:error: s.prop8="Non Authenticated"; if (typeof(omniture_java if (typeof(omniture_plugin s.eVar10=s.getTimeParting s.retrieveLightProfiles = 'lsccmp'; var s_code=s.t();if(s_code //--></script> </div> <!-- end of Omniture Tag --> <div class="clear20"></div> <div align="center"> <img src="http://cdn.pogo.com <div id="bodyWrap"> <div class="whiteModule" id="pageHeader"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> Oops, something is not right... </div> <b class="bL"> </b><b class="bR"> </b> </div> <div class="clear10"></div> <div class="whiteModule mainContent"> <b class="tL"> </b><b class="tR"> </b> <div class="moduleContent"> <h1>The page you requested could not be found.</h1> <p>Please check the URL for proper spelling and capitalization. If you're having trouble finding a particular page try visiting the<br /> <strong><a href="http://www.pogo.com <div class="clear20"></div> </div> <b class="bL"> </b><b class="bR"> </b> </div> </div> </div> </body> </html> |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://burp/show/5 Cookie: s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:37:02 GMT Server: Apache-Coyote/1.1 Content-Length: 12415 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... fier; s.linkTrackVars=s } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://burp/show/5"; s.eVar2="pogo"; s.pageName="Template without FB Marketing Landing Page"; s.prop2="pogo"; s.eVar12="6618922560 s.campaign="free_internet s.channel="games"; s.prop7="POGO:games s.prop8="Non Authenticated"; if (typeof(omniture_java if (typeof(omniture_plugin s.eVar10=s.getTimeParting s.retrieveLightProfiles = 'lsccmp'; var s_code=s.t();if(s_code //--></script> </div> <!-- end of Omniture Tag --> <img src="http://network <div align="center"> <link rel="StyleSheet" href="/include/css/pogo <link rel="StyleSheet" href="/include/css/shared <link rel="StyleSheet" href="/include/css/shared <link rel="StyleSheet" href="/include/css/shared <div align="center"> </div> <table border=0 cellpadding=0 cellspacing=0 width=613 align=center> <tr> <td><img src="http://cdn.pogo.com </tr> </table> <div class="bodyContainer"> <script type="text/javascript"> AC_FL_RunContent( 'codebase','http:/ </script> <noscrip ...[SNIP]... |
GET /pogo-online-games/lp Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:37:06 GMT Server: Apache-Coyote/1.1 Content-Length: 12681 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... fier; s.linkTrackVars=s } if (s.linkTrackEvents != 'None') {s.linkTrackVars=s s.tl(source,'o',pageName) } s.referrer="http://www.pogo.com/pogo-online s.eVar2="pogo"; s.pageName="Template without FB Marketing Landing Page"; s.prop2="pogo"; s.eVar12="6618922560 s.campaign="free_internet s.channel="games"; s.prop7="POGO:games s.prop8="Non Authenticated"; if (typeof(omniture_java if (typeof(omniture_plugin s.eVar10=s.getTimeParting s.retrieveLightProfiles = 'lsccmp'; var s_code=s.t();if(s_code //--></script> </div> <!-- end of Omniture Tag --> <img src="http://network <div align="center"> <link rel="StyleSheet" href="/include/css/pogo <link rel="StyleSheet" href="/include/css/shared <link rel="StyleSheet" href="/include/css/shared <link rel="StyleSheet" href="/include/css/shared <div align="center"> </div> <table border=0 cellpadding=0 cellspacing=0 width=613 align=center> <tr> <td><img src="http://cdn.pogo.com </tr> </table> <div class="bodyContainer"> <script type="text/javascript"> AC_FL_RunContent( 'codebase','http:/ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://burp/show/5 Cookie: s_sess=%20s_cc%3Dtrue%3B |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:37:02 GMT Server: Apache-Coyote/1.1 Content-Length: 12415 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... <!-- end of Omniture Tag --> <img src="http://network <div align="center"> ...[SNIP]... <noscript> <object classid="clsid:D27CDB6E <param name="movie" value="media/Pogo_General ...[SNIP]... <li><a href="http://www.clubpogo ...[SNIP]... <li><a href="http://www.info.ea ...[SNIP]... <li><a class="popup||1021|600 ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... </div> <iframe width="1" height="1" hspace="0" vspace="0" frameborder="0" scrolling="no" src="http://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: prod.JID=3E01A5E24CD |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:30:21 GMT Server: Apache-Coyote/1.1 Content-Length: 12393 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... <!-- end of Omniture Tag --> <img src="http://network <div align="center"> ...[SNIP]... <noscript> <object classid="clsid:D27CDB6E <param name="movie" value="media/Pogo_General ...[SNIP]... <li><a href="http://www.clubpogo ...[SNIP]... <li><a href="http://www.info.ea ...[SNIP]... <li><a class="popup||1021|600 ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... </div> <iframe width="1" height="1" hspace="0" vspace="0" frameborder="0" scrolling="no" src="http://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive Referer: http://burp/show/10 Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D130 |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:39:27 GMT Server: Apache-Coyote/1.1 Content-Length: 12392 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... <!-- end of Omniture Tag --> <img src="http://network <div align="center"> ...[SNIP]... <noscript> <object classid="clsid:D27CDB6E <param name="movie" value="media/Pogo_General ...[SNIP]... <li><a href="http://www.clubpogo ...[SNIP]... <li><a href="http://www.info.ea ...[SNIP]... <li><a class="popup||1021|600 ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... </div> <iframe width="1" height="1" hspace="0" vspace="0" frameborder="0" scrolling="no" src="http://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:30:17 GMT Server: Apache-Coyote/1.1 Content-Length: 12361 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... <!-- end of Omniture Tag --> <img src="http://network <div align="center"> ...[SNIP]... <noscript> <object classid="clsid:D27CDB6E <param name="movie" value="media/Pogo_General ...[SNIP]... <li><a href="http://www.clubpogo ...[SNIP]... <li><a href="http://www.info.ea ...[SNIP]... <li><a class="popup||1021|600 ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... </div> <iframe width="1" height="1" hspace="0" vspace="0" frameborder="0" scrolling="no" src="http://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive Referer: http://burp/show/9 Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D130 |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:39:04 GMT Server: Apache-Coyote/1.1 Content-Length: 12412 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... <!-- end of Omniture Tag --> <img src="http://network <div align="center"> ...[SNIP]... <noscript> <object classid="clsid:D27CDB6E <param name="movie" value="media/Pogo_General ...[SNIP]... <li><a href="http://www.clubpogo ...[SNIP]... <li><a href="http://www.info.ea ...[SNIP]... <li><a class="popup||1021|600 ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... </div> <iframe width="1" height="1" hspace="0" vspace="0" frameborder="0" scrolling="no" src="http://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /pogo-online-games/lp |
GET /pogo-online-games/lp Host: www.pogo.com Proxy-Connection: keep-alive Referer: http://burp/show/5 Cache-Control: max-age=0 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: s_pers=%20s_nr%3D130 |
HTTP/1.1 200 OK Expires: 0 Cache-Control: max-age=0, private Content-Language: en-US Content-Type: text/html;charset=UTF-8 Vary: Accept-Encoding Date: Fri, 24 Jun 2011 13:37:09 GMT Server: Apache-Coyote/1.1 Content-Length: 12416 <html> <head> <title>Pogo.com - The Ultimate Online Gaming Experience!</title> <link rel="StyleSheet" href="/v/FO57ZA/include <sc ...[SNIP]... <!-- end of Omniture Tag --> <img src="http://network <div align="center"> ...[SNIP]... <noscript> <object classid="clsid:D27CDB6E <param name="movie" value="media/Pogo_General ...[SNIP]... <li><a href="http://www.clubpogo ...[SNIP]... <li><a href="http://www.info.ea ...[SNIP]... <li><a class="popup||1021|600 ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a class="popup||800|600|yes ...[SNIP]... <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... <li><a href="http://www.ea.com <li><a href="http://www.ea.com ...[SNIP]... </div> <iframe width="1" height="1" hspace="0" vspace="0" frameborder="0" scrolling="no" src="http://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /v/FSMQBg/include/js |
GET /v/FSMQBg/include/js Host: www.pogo.com Proxy-Connection: keep-alive Referer: http://www.pogo.com/pogo User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: prod.JID=3E01A5E24CD |
HTTP/1.1 200 OK Age: 4950 Date: Fri, 24 Jun 2011 12:15:40 GMT Expires: Wed, 22 Jun 2016 12:15:40 GMT Cache-Control: max-age=157680000 Content-Length: 8840 Connection: Keep-Alive Via: POGO-EDGE ETag: W/"8840-1301347758000" Last-Modified: Mon, 28 Mar 2011 21:29:18 GMT Content-Type: text/javascript Vary: Accept-Encoding Server: Apache-Coyote/1.1 // copyright ea.com 2007 // This js allows the use of 'progressive enhancement' markup using class attributes rather than inline javascript. // @see http://domscripting.com ...[SNIP]... <img src="path/to/image.gif" class="imgover" /> // make sure your hover image is named image-over.gif // jsainz@ea.com 2007-03-02 Markup.imgOvers = function() { if (!document.getElementById var aPreLoad = new Array(); var sTempSrc; var aInputs = document.getElements var aImg = docum ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.pogo.com |
Path: | /include/css/pogo.css |
GET /include/css/pogo.css HTTP/1.1 Host: www.pogo.com Proxy-Connection: keep-alive Referer: http://www.pogo.com/pogo User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: prod.JID=3E01A5E24CD |
HTTP/1.1 200 OK Age: 5183 Date: Fri, 24 Jun 2011 12:15:43 GMT Content-Length: 4640 Connection: Keep-Alive Via: POGO-EDGE ETag: W/"4640-1294693595000" Last-Modified: Mon, 10 Jan 2011 21:06:35 GMT Content-Type: text/css Vary: Accept-Encoding Server: Apache-Coyote/1.1 <style TYPE="text/css"> <!-- .aa {font-family:Arial, Helvetica, sans-serif} img {border-width:0} .default {font-family: Arial, Helvetica, sans-serif; font-size: 12px; color: #000000} .dflt {font-fami ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.pogo.com |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.pogo.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: prod.JID=3E01A5E24CD |
HTTP/1.1 200 OK Age: 5199 Date: Fri, 24 Jun 2011 12:15:40 GMT Connection: Keep-Alive Via: POGO-EDGE ETag: W/"766-1118367449000" Last-Modified: Fri, 10 Jun 2005 01:37:29 GMT Content-Length: 766 Server: Apache-Coyote/1.1 ...... ..............(... ...@..................... ...[SNIP]... |