1. Cross-site scripting (reflected)
1.1. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm [REST URL parameter 1]
1.2. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm [REST URL parameter 2]
1.3. http://www.bankofamerica.com/surveys/popup_visit.cfm [REST URL parameter 1]
1.4. http://www.bankofamerica.com/surveys/survey_popup_invoker.cfm [REST URL parameter 1]
1.5. http://www.bankofamerica.com/surveys/survey_select.cfm [REST URL parameter 1]
1.6. http://www.bankofamerica.com/findit/error.cgi [state cookie]
1.7. http://www.bankofamerica.com/surveys/flyout/HM_Arrays.js [state cookie]
1.8. http://www.bankofamerica.com/www/global/mvc_objects/images/1pixel_clear.gif [state cookie]
2. Cookie scoped to parent domain
2.1. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm
2.2. http://www.bankofamerica.com/surveys/survey_select.cfm
3. Cookie without HttpOnly flag set
3.1. http://www.bankofamerica.com/coremetrics/cmdatatagutils.js
3.2. http://www.bankofamerica.com/coremetrics/v40/eluminate.js
3.3. http://www.bankofamerica.com/global/mvc_objects/stylesheet/hs2_mvc_content_style.css
3.4. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm
3.5. http://www.bankofamerica.com/surveys/survey_select.cfm
6. HTML does not specify charset
6.1. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm
6.2. http://www.bankofamerica.com/surveys/survey_popup_invoker.cfm
6.3. http://www.bankofamerica.com/surveys/survey_select.cfm
7. Content type incorrectly stated
7.1. http://www.bankofamerica.com/favicon.ico
7.2. http://www.bankofamerica.com/global/images/new_Banklogo.gif
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys12dd0"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:44 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1409 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge8e738"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:44 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1409 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/popup_visit.cfm |
GET /surveysc4b84"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:55 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1539 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_popup |
GET /surveys78c6e"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:12 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1422 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys1b4d0"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:07 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1415 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /findit/error.cgi |
POST /findit/error.cgi HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica Content-Length: 184 Cache-Control: max-age=0 Origin: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O URL=http%3A%2F%2Fwww |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:31 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13458 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/flyout/HM_Arrays |
GET /surveys/flyout/HM_Arrays Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:00 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13458 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/mvc_objects |
GET /www/global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:34 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13458 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:35 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_VISITED_URLS Content-Length: 16269 <html lang="en-US"> <head> <script language="JavaScript" type="text/javascript"> <!-- var hParent = null; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys/survey_select Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:38 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_SHOWN_IN_LAST_6 Set-Cookie: SURVEY_SHOW_DETAILS=CTS Content-Length: 735 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /coremetrics/cmdatat |
GET /coremetrics/cmdatat Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://learn.bankofa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 14:10:29 GMT Content-length: 25169 Content-type: application/x-javascript Last-modified: Sat, 04 Dec 2010 22:18:57 GMT Etag: "6251-4cfabe51" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /* cmdatatagutils.js * $Id: cmdatatagutils-Compr * * Coremetrics Tag v4.0, 8/11/2006 * COPYRIGHT . 1999-2010 COREMETRICS, AN IBM COM ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /coremetrics/v40 |
GET /coremetrics/v40 Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://learn.bankofa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 14:10:29 GMT Content-length: 26681 Content-type: application/x-javascript Last-modified: Sat, 04 Dec 2010 22:18:57 GMT Etag: "6839-4cfabe51" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /*$Id: eluminate-Comprehensive ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/mvc_objects |
GET /global/mvc_objects Host: www.bankofamerica.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.bankofamerica |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:34 GMT Content-length: 27766 Content-type: text/css Last-modified: Sat, 18 Jun 2011 05:48:32 GMT Etag: "6c76-4dfc3c30" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /* top level font to cascade */ .standard-font {font-size: 71%; font-family : Verdana, Arial, Geneva, Helvetica, sans-serif;} .standard-font2 {font-size: 100%; font-family : Verdana, Arial, Geneva, He ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:35 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_VISITED_URLS Content-Length: 16269 <html lang="en-US"> <head> <script language="JavaScript" type="text/javascript"> <!-- var hParent = null; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys/survey_select Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:38 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_SHOWN_IN_LAST_6 Set-Cookie: SURVEY_SHOW_DETAILS=CTS Content-Length: 735 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/mvc_objects |
GET /global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:46 GMT Content-length: 46855 Content-type: application/x-javascript Last-modified: Mon, 23 Feb 2004 21:21:26 GMT Etag: "b707-403a6ed6" Accept-ranges: bytes /*HM_ScriptDOM.js * by Peter Belesis. v4.3 020605 * Copyright (c) 2002 Peter Belesis. All Rights Reserved. * Originally published and documented at http://www.dhtmlab.com/ * Available solely from INT Media Group. Incorporated under exclusive license. * Contact licensing@internet.com for more information. */ HM_IE5M = HM_IE && HM_Mac; HM_NS6 = (navigator.vendor == ("Netscape6") || navigator.product == ("Gecko")); if(HM_Konqueror) HM_IE = false; HM_IE5W = HM_IE && !HM_Mac; HM_IEp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/js/tc |
GET /robots.txt HTTP/1.0 Host: www.bankofamerica.com |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 14:10:35 GMT Content-length: 1298 Content-type: text/plain Last-modified: Sat, 19 Mar 2011 19:08:31 GMT Accept-ranges: bytes Connection: close User-agent: * # applies to all robots Disallow: /global # disallow indexing of restricted areas Disallow: /cfdocs Disallow: /thirdparty Disallow: /directbenefits Disallow: /groupbanking ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:35 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_VISITED_URLS Content-Length: 16269 <html lang="en-US"> <head> <script language="JavaScript" type="text/javascript"> <!-- var hParent = null; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_popup |
GET /surveys/survey_popup Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:36 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Content-Length: 8802 <!DOCTYPE html PUBLIC "-//W3C//DTD html 4 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys/survey_select Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:38 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_SHOWN_IN_LAST_6 Set-Cookie: SURVEY_SHOW_DETAILS=CTS Content-Length: 735 ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:37 GMT Content-length: 1406 Content-type: text/plain Last-modified: Thu, 01 Aug 2002 16:37:18 GMT Etag: "57e-3d4963be" Accept-ranges: bytes ..............h.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /global/images/new |
GET /global/images/new Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:19 GMT Content-length: 24065 Content-type: image/gif Last-modified: Sun, 25 Oct 2009 08:57:26 GMT Etag: "5e01-4ae412f6" Accept-ranges: bytes ......JFIF.....H.H.... .Exif..MM.*.............. ....'.. ....'.Adobe Photoshop CS3 Windows.2009:06:30 12:19:11......... ...[SNIP]... |