1. Cross-site scripting (reflected)
1.1. http://help.livingsocial.co.uk/ics/support/default.asp [deptID parameter]
1.3. http://help.livingsocial.co.uk/ics/support/default.asp [Referer HTTP header]
2. Cookie without HttpOnly flag set
2.1. http://help.livingsocial.co.uk/ics/support/KBFolder.asp
2.2. http://help.livingsocial.co.uk/ics/support/default.asp
2.3. http://help.livingsocial.co.uk/ics/support/splash.asp
4. HTML does not specify charset
5. Content type incorrectly stated
Severity: | High |
Confidence: | Certain |
Host: | http://help.livingsocial |
Path: | /ics/support/default.asp |
GET /ics/support/default.asp Host: help.livingsocial.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 09 Jul 2011 10:50:52 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: ParaturePortalSessionID Set-Cookie: ParaturePortalDeptID Vary: Accept-Encoding Content-Length: 3905 <HTML> <HEAD> <!-- ****** PRODAPP7-A ****** --> <base href="http://help <!--<script src="../ic1Browser.js">< <script type="text/javascript" src="/ ...[SNIP]... <frame title="Left Navigation" name="cypLeft" src="KBFolder.asp?deptID ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://help.livingsocial |
Path: | /ics/support/default.asp |
GET /ics/support/default.asp Host: help.livingsocial.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 09 Jul 2011 10:50:52 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: ParaturePortalSessionID Set-Cookie: ParaturePortalDeptID Vary: Accept-Encoding Content-Length: 3911 <HTML> <HEAD> <!-- ****** PRODAPP6-A ****** --> <base href="http://help <!--<script src="../ic1Browser.js">< <script type="text/javascript" src="/ ...[SNIP]... <frame title="Left Navigation" name="cypLeft" src="KBFolder.asp?deptID ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://help.livingsocial |
Path: | /ics/support/default.asp |
GET /ics/support/default.asp Host: help.livingsocial.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Referer: http://www.google.com |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 09 Jul 2011 10:50:52 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: ParaturePortalSessionID Set-Cookie: ParaturePortalDeptID Vary: Accept-Encoding Content-Length: 3883 <HTML> <HEAD> <!-- ****** PRODAPP8-A ****** --> <base href="http://help <!--<script src="../ic1Browser.js">< <script type="text/javascript" src="/ ...[SNIP]... <SCRIPT language="javascript"> //used to maintain session in case of timeouts var sessionDeptID = 15232; window.name="support"; var backNavUrl = "http://www.google.com function exitSupport() { //if there are no referers or is a popup, then close if ((backNavUrl == "") || (backNavUrl == "popup")) { try { window.close(); } catch (e_close) {} // ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://help.livingsocial |
Path: | /ics/support/KBFolder.asp |
GET /ics/support/KBFolder.asp Host: help.livingsocial.co.uk Proxy-Connection: keep-alive Referer: http://help.livingsocial User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: IsMyCookieEnabled=Yes; ParaturePortalDeptID |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 09 Jul 2011 10:50:47 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: ParaturePortalSessionID Vary: Accept-Encoding Content-Length: 6363 <script type="text/javascript"> var CYRACLE_HOST = "s5.parature.com"; var DEBUG = 'false'; </script> <html> <head> <meta http-equiv='content-type' content='text/html; charset=utf-8 ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://help.livingsocial |
Path: | /ics/support/default.asp |
GET /ics/support/default.asp Host: help.livingsocial.co.uk Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: private Date: Sat, 09 Jul 2011 10:50:45 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: ParaturePortalSessionID Set-Cookie: ParaturePortalDeptID Vary: Accept-Encoding Content-Length: 3819 <HTML> <HEAD> <!-- ****** PRODAPP7-A ****** --> <base href="http://help <!--<script src="../ic1Browser.js">< <script type="text/javascript" src="/ ...[SNIP]... |
Severity: | Low |
Confidence: | Firm |
Host: | http://help.livingsocial |
Path: | /ics/support/splash.asp |
GET /ics/support/splash.asp Host: help.livingsocial.co.uk Proxy-Connection: keep-alive Referer: http://help.livingsocial User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: IsMyCookieEnabled=Yes; ParaturePortalDeptID |
HTTP/1.1 200 OK Cache-Control: private Connection: close Date: Sat, 09 Jul 2011 10:50:47 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Set-Cookie: ParaturePortalSessionID Vary: Accept-Encoding Content-Length: 11989 <script type="text/javascript"> var CYRACLE_HOST = "s5.parature.com"; var DEBUG = 'false'; </script> <HTML> <HEAD> <meta http-equiv='content-type' content='text/html; charset=utf-8 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://help.livingsocial |
Path: | /ics/support/inc/folder |
GET /ics/support/inc/folder Host: help.livingsocial.co.uk Proxy-Connection: keep-alive Referer: http://help.livingsocial User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: IsMyCookieEnabled=Yes; ParaturePortalDeptID |
HTTP/1.1 200 OK Content-Length: 13016 Content-Type: application/x-javascript Last-Modified: Wed, 06 Jul 2011 15:43:12 GMT Accept-Ranges: bytes ETag: "0288069f33bcc1:1603d" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 09 Jul 2011 10:50:46 GMT //*********************** // You are free to copy the "Folder-Tree" script as long as you // keep this copyright notice: // Script found in: http://www.geocities.com // Author: Marcelino Alves Martins (martins@hks.com) December '97. //*********************** function Folder(desc, folderID, nItems, href, closeSrc, openSrc, target) //constructor { this.desc = des ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://help.livingsocial |
Path: | /ics/support/accounts |
GET /ics/support/accounts Host: help.livingsocial.co.uk Proxy-Connection: keep-alive Referer: http://help.livingsocial User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: IsMyCookieEnabled=Yes; ParaturePortalDeptID |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Length: 460 Content-Type: text/html Last-Modified: Tue, 29 Mar 2011 13:32:53 GMT Accept-Ranges: bytes ETag: "80301ece15eecb1:1603d" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 09 Jul 2011 10:50:46 GMT <html><head><style> .bkdgd { background: #262626; width:100%; height:56px;padding:10px 0px 0px 11px} .title {display:block; background: url(http://a4.ak.lscdn ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://help.livingsocial |
Path: | /ics/inc/js/portalAj |
GET /ics/inc/js/portalAj Host: help.livingsocial.co.uk Proxy-Connection: keep-alive Referer: http://help.livingsocial User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.77 Safari/534.24 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: ParaturePortalDeptID |
HTTP/1.1 200 OK Cache-Control: max-age=604800 Content-Length: 74 Content-Type: application/x-javascript Last-Modified: Wed, 06 Jul 2011 16:08:38 GMT Accept-Ranges: bytes ETag: "04711f7f63bcc1:1603d" Vary: Accept-Encoding Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET Date: Sat, 09 Jul 2011 10:50:45 GMT PARATURE.ajax.gateway |