1. Cross-site scripting (reflected)
1.1. http://www2.fdic.gov/idasp/Header-report.asp [ReportFunction parameter]
1.2. http://www2.fdic.gov/idasp/Header-report.asp [ReportName parameter]
1.3. http://www2.fdic.gov/idasp/rpt_Financial.asp [compareIndicator parameter]
1.4. http://www2.fdic.gov/idasp/rpt_Financial.asp [demodte parameter]
1.5. http://www2.fdic.gov/idasp/DIRSInfoRequest.asp [Referer HTTP header]
1.6. http://www2.fdic.gov/idasp/DIRSInfoRequest.asp [Referer HTTP header]
1.7. http://www2.fdic.gov/idasp/frm_bhc.asp [Referer HTTP header]
1.8. http://www2.fdic.gov/idasp/rpt_Financial.asp [Referer HTTP header]
2.1. http://www2.fdic.gov/idasp/DIRSInfoRequest.asp
2.2. http://www2.fdic.gov/idasp/rpt_Financial.asp
3. Cross-domain Referer leakage
3.1. http://www2.fdic.gov/idasp/Header-report.asp
3.2. http://www2.fdic.gov/idasp/frm_bhc.asp
5. HTML does not specify charset
5.1. http://www2.fdic.gov/idasp/StruReportNew.asp
5.2. http://www2.fdic.gov/idasp/frm_bhc.asp
5.3. http://www2.fdic.gov/idasp/rpt_Financial.asp
6. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/Header-report.asp |
GET /idasp/Header-report.asp Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:58 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 29133 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>FDIC: Report Header</title> <script language="JavaScrip ...[SNIP]... <input type="hidden" name=ReportFunction value=Inst729fc style=x:expression(alert ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/Header-report.asp |
GET /idasp/Header-report.asp Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:55 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 29134 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>FDIC: Report Header</title> <script language="JavaScrip ...[SNIP]... <body onload="MatchOption('10c2ae2"style="x:expression ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/rpt_Financial.asp |
POST /idasp/rpt_Financial.asp HTTP/1.1 Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov Content-Length: 164 Cache-Control: max-age=0 Origin: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD ReportFunction=Inst |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:01:33 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 45035 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <!--REFFERPAGE=http:/ <HTML> <link r ...[SNIP]... <input type="hidden" name="compareIndicator" value="206e7"style="x:expression ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/rpt_Financial.asp |
GET /idasp/rpt_Financial.asp Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov Cache-Control: max-age=0 Origin: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:01:29 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 45041 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <!--REFFERPAGE=http:/ <HTML> <link r ...[SNIP]... <input type="hidden" name="demodte" value="d80c0"style="x:expression ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/DIRSInfoRequest |
GET /idasp/DIRSInfoRequest Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:04:10 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 27243 Content-Type: text/html Set-Cookie: SetCookie=OK; path=/idasp Cache-control: private <!-- Security Remediation Project --> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>FDIC: Questions, Suggestions, & Requests For SEARCH?H ...[SNIP]... <!--referpage=http://www ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://www2.fdic.gov |
Path: | /idasp/DIRSInfoRequest |
GET /idasp/DIRSInfoRequest Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www.google.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:04:08 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 27153 Content-Type: text/html Set-Cookie: SetCookie=OK; path=/idasp Cache-control: private <!-- Security Remediation Project --> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>FDIC: Questions, Suggestions, & Requests For SEARCH?H ...[SNIP]... <input type="hidden" name="inSystemName" value="SEARCH?HL=EN&Q=602CD"><A>D82D1BF3974" size="20" > ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/frm_bhc.asp |
GET /idasp/frm_bhc.asp Host: www2.fdic.gov Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD Referer: http://www.google.com |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:59 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 20393 Content-Type: text/html Expires: Fri, 08 Jul 2011 17:00:59 GMT Cache-control: private <!-- Security Remediation Project --> <html> <head> <title>FDIC: BHC Search Form</title> </head> <script language="javascript1.2"> <!-- //----------------------- ...[SNIP]... <!--referpage=http://www ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/rpt_Financial.asp |
GET /idasp/rpt_Financial.asp Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www.google.com Cache-Control: max-age=0 Origin: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:01:42 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 44918 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <!--REFFERPAGE=http://www <HTML> <link rel="stylesheet" href="print.css" ty ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www2.fdic.gov |
Path: | /idasp/DIRSInfoRequest |
GET /idasp/DIRSInfoRequest Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:04:05 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 27139 Content-Type: text/html Set-Cookie: SetCookie=OK; path=/idasp Cache-control: private <!-- Security Remediation Project --> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>FDIC: Questions, Suggestions, & Requests For ID</title> </head> <body BGCOLOR="white" text="black"> <basefont face="Arial, Helvetica" size="2"> <!-- Begin Content Header --> <!-- Last Updated Date: 1-21-2011 Time: 9:20AM Version: 1.6 --> <!-- ForeSee Code --> <script type="text/javascript" src="/foresee/foresee <link rel="stylesheet" type="text/css" href="/header/css/www2 <div id="header-container"> <!-- start of header container --> <!-- everything inside the header is held within this container --> <div id="header-nav"> <div id="header-nav-left <div id="header-nav-left"> <a target="_parent" href="http://www.fdic.gov <div id="fdic-logo"></div> </a> </div> <!-- close header-nav-left --> <div id="header-nav-right"> <div id="header-nav-right-top" <div id="fdic-title"></div> </div> <div id="header-nav-right <h1>Each depositor insured to at least $250,000 per insured bank</h1> </div> </div> <!-- close header-nav-right --> </div> <!-- close header-nav-left-container --> <div id="header-nav-right <div id="right-container-top"> <div id="web2"> <ul> <li><a target="_parent" href="http://www.fdic.gov <li><img src="/header/images/Web2 <li><a target="_parent" href="http://www.fdic.gov <li><img src="/header/images/Web2 <li><a target="_parent" href="http:/ ...[SNIP]... |
GET /idasp/DIRSInfoRequest Host: www2.fdic.gov Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:04:08 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 27012 Content-Type: text/html Set-Cookie: SetCookie=OK; path=/idasp Cache-control: private <!-- Security Remediation Project --> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>FDIC: Questions, Suggestions, & Requests For Non-FDIC Site</title> </head> <body BGCOLOR="white" text="black"> <basefont face="Arial, Helvetica" size="2"> <!-- Begin Content Header --> <!-- Last Updated Date: 1-21-2011 Time: 9:20AM Version: 1.6 --> <!-- ForeSee Code --> <script type="text/javascript" src="/foresee/foresee <link rel="stylesheet" type="text/css" href="/header/css/www2 <div id="header-container"> <!-- start of header container --> <!-- everything inside the header is held within this container --> <div id="header-nav"> <div id="header-nav-left <div id="header-nav-left"> <a target="_parent" href="http://www.fdic.gov <div id="fdic-logo"></div> </a> </div> <!-- close header-nav-left --> <div id="header-nav-right"> <div id="header-nav-right-top" <div id="fdic-title"></div> </div> <div id="header-nav-right <h1>Each depositor insured to at least $250,000 per insured bank</h1> </div> </div> <!-- close header-nav-right --> </div> <!-- close header-nav-left-container --> <div id="header-nav-right <div id="right-container-top"> <div id="web2"> <ul> <li><a target="_parent" href="http://www.fdic.gov <li><img src="/header/images/Web2 <li><a target="_parent" href="http://www.fdic.gov <li><img src="/header/images/Web2 <li><a target="_parent" h ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www2.fdic.gov |
Path: | /idasp/rpt_Financial.asp |
POST /idasp/rpt_Financial.asp HTTP/1.1 Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov Content-Length: 164 Cache-Control: max-age=0 Origin: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD ReportFunction=Inst |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:49 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 44988 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <!--REFFERPAGE=http:/ <HTML> <link rel="stylesheet" href="print.css" type="text/css" media="print" /> <HEAD> <TITLE>FDIC: Financial Report 10</TITLE> <BASEFONT size="2"> </HEAD> <script language="javascript1.2"> function SubReports(repName) { self.document.Submit self.document.Submit } function ChangeHeader() { if (parent.header.document { parent.header.document self.document.Submit } if(parent.document parent.document } </script> <BODY onload="ChangeHeader();" BGCOLOR="white" text="black" onunload="javascript:if( <script language="javascript"> function download_submit() { var strAction = window.top.header var pos = strAction.indexOf("_csv if (pos == -1) { strAction = strAction.substring(0, strAction.indexOf(".asp") } else { strAction = strAction.substring(0, strAction.indexOf("_csv } window.top.header window.top.header } function download_csv_submit() { var strAction = window.top.header var pos = strAction.indexOf("_csv if (pos == -1) { strAction = strAction.substring(0, strAction.indexOf(".asp") } window.top.header window.top.header } function printpage() { printwindow=window.op ...[SNIP]... |
POST /idasp/rpt_Financial.asp HTTP/1.1 Host: www2.fdic.gov Proxy-Connection: keep-alive Content-Length: 164 Cache-Control: max-age=0 Origin: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD ReportFunction=Inst |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:01:16 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 191 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <script language="javascript1.2"> top.document.location </script> |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/Header-report.asp |
GET /idasp/Header-report.asp Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:35 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 29087 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <title>FDIC: Report Header</title> <script language="JavaScrip ...[SNIP]... <li><a target="_parent" href="http://service ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/frm_bhc.asp |
GET /idasp/frm_bhc.asp Host: www2.fdic.gov Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:51 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 20312 Content-Type: text/html Expires: Fri, 08 Jul 2011 17:00:51 GMT Cache-control: private <!-- Security Remediation Project --> <html> <head> <title>FDIC: BHC Search Form</title> </head> <script language="javascript1.2"> <!-- //----------------------- ...[SNIP]... </b> bank holding company information can be found by visiting the website of the <a href="http://www.ffiec ...[SNIP]... <li><a target="_parent" href="http://www.usa.gov/ ...[SNIP]... <li><a target="_parent" href="http://www.fdicoig ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /favicon.ico |
GET /favicon.ico HTTP/1.1 Host: www2.fdic.gov Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ASPSESSIONIDSSTAADSD |
HTTP/1.1 404 Not Found Content-Length: 12231 Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Fri, 08 Jul 2011 17:00:47 GMT <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> ...[SNIP]... <!-- Instruction: change the link text and href value of "Insert_Content_Email ...[SNIP]... <a href="mailto:webmaster@fdic.gov">webmaster@fdic.gov</a> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/StruReportNew.asp |
GET /idasp/StruReportNew.asp Host: www2.fdic.gov Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Connection: close Date: Fri, 08 Jul 2011 17:00:35 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Type: text/html Set-Cookie: SetCookie=OK; path=/idasp Cache-control: private <!-- Security Remediation Project --> <html> <head> <title>FDIC: Institution Directory</title> </head> <frameset id='myFrameset' frameborder='0' border='0' framespacing='0' rows='162, ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/frm_bhc.asp |
GET /idasp/frm_bhc.asp Host: www2.fdic.gov Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:51 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 20312 Content-Type: text/html Expires: Fri, 08 Jul 2011 17:00:51 GMT Cache-control: private <!-- Security Remediation Project --> <html> <head> <title>FDIC: BHC Search Form</title> </head> <script language="javascript1.2"> <!-- //----------------------- ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www2.fdic.gov |
Path: | /idasp/rpt_Financial.asp |
POST /idasp/rpt_Financial.asp HTTP/1.1 Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov Content-Length: 164 Cache-Control: max-age=0 Origin: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Content-Type: application/x-www-form Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD ReportFunction=Inst |
HTTP/1.1 200 OK Date: Fri, 08 Jul 2011 17:00:49 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Content-Length: 44988 Content-Type: text/html Cache-control: private <!-- Security Remediation Project --> <!--REFFERPAGE=http:/ <HTML> <link r ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www2.fdic.gov |
Path: | /idasp/images/Menu_Bottom |
GET /idasp/images/Menu_Bottom Host: www2.fdic.gov Proxy-Connection: keep-alive Referer: http://www2.fdic.gov User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SetCookie=OK; ASPSESSIONIDSSTAADSD |
HTTP/1.1 200 OK Content-Length: 8675 Content-Type: image/png Last-Modified: Thu, 21 Oct 2010 21:39:04 GMT Accept-Ranges: bytes ETag: "6aa2fe616871cb1:4a5a" Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Fri, 08 Jul 2011 17:00:45 GMT ......JFIF.....H.H..... ...[SNIP]... |