1. Cross-site scripting (reflected)
2.1. http://i1.ytimg.com/crossdomain.xml
2.2. http://i2.ytimg.com/crossdomain.xml
3. Silverlight cross-domain policy
5.1. http://i2.technet.microsoft.com/Areas/Sto/Content/Scripts/mm/global.js
6.1. http://i1.ytimg.com/crossdomain.xml
6.2. http://i2.ytimg.com/crossdomain.xml
Severity: | High |
Confidence: | Certain |
Host: | http://i1.services.social |
Path: | /search/Widgets/SearchBox |
GET /search/Widgets/SearchBox Host: i1.services.social Proxy-Connection: keep-alive Referer: http://technet.microsoft Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: omniID=1297806178674_91c6 |
HTTP/1.1 200 OK Content-Type: application/x-javascript ETag: a46670cfe3b6e9bb099f Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET P3P: CP=ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI Server: CO1VB34 Vary: Accept-Encoding Cache-Control: public, max-age=43201 Expires: Wed, 16 Feb 2011 09:46:45 GMT Date: Tue, 15 Feb 2011 21:46:44 GMT Connection: close Content-Length: 12791 if (typeof epx_core === 'undefined') { epx_loaded = false; epx_core = function(s) {this.s = s;} epx_core.prototype = { exec: function(func, checkFunc, retry) { if (retry) retry++; else retry = ...[SNIP]... archBox({"allowEmpty ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://i2.services.social |
Path: | /search/Widgets/SearchBox |
GET /search/Widgets/SearchBox Host: i2.services.social Proxy-Connection: keep-alive Referer: http://technet.microsoft Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=688642bf9d1 |
HTTP/1.1 200 OK Content-Type: application/x-javascript ETag: 194f795da69d3f2455d2 Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET P3P: CP=ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI Server: CO1VB36 Vary: Accept-Encoding Cache-Control: public, max-age=43200 Expires: Wed, 16 Feb 2011 11:02:24 GMT Date: Tue, 15 Feb 2011 23:02:24 GMT Connection: close Content-Length: 12790 if (typeof epx_core === 'undefined') { epx_loaded = false; epx_core = function(s) {this.s = s;} epx_core.prototype = { exec: function(func, checkFunc, retry) { if (retry) retry++; else retry = ...[SNIP]... archBox({"allowEmpty ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://i3.services.social |
Path: | /search/Widgets/SearchBox |
GET /search/Widgets/SearchBox Host: i3.services.social Proxy-Connection: keep-alive Referer: http://technet.microsoft Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=688642bf9d1 |
HTTP/1.1 200 OK Content-Type: application/x-javascript ETag: 8c5264eb2fa560f486e4 Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET P3P: CP=ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI Server: CO1VB34 Vary: Accept-Encoding Cache-Control: public, max-age=43200 Expires: Wed, 16 Feb 2011 11:04:48 GMT Date: Tue, 15 Feb 2011 23:04:48 GMT Connection: close Content-Length: 12822 if (typeof epx_core === 'undefined') { epx_loaded = false; epx_core = function(s) {this.s = s;} epx_core.prototype = { exec: function(func, checkFunc, retry) { if (retry) retry++; else retry = ...[SNIP]... se,"appId":"2","boxId": ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://i4.services.social |
Path: | /search/Widgets/SearchBox |
GET /search/Widgets/SearchBox Host: i4.services.social Proxy-Connection: keep-alive Referer: http://technet.microsoft Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=688642bf9d1 |
HTTP/1.1 200 OK ntCoent-Length: 12791 Content-Type: application/x-javascript ETag: 442552f5d5df6da5c409 Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET P3P: CP=ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI Server: CO1VB30 Cache-Control: public, max-age=43200 Expires: Wed, 16 Feb 2011 11:04:21 GMT Date: Tue, 15 Feb 2011 23:04:21 GMT Connection: close Vary: Accept-Encoding Content-Length: 12791 if (typeof epx_core === 'undefined') { epx_loaded = false; epx_core = function(s) {this.s = s;} epx_core.prototype = { exec: function(func, checkFunc, retry) { if (retry) retry++; else retry = ...[SNIP]... archBox({"allowEmpty ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://i1.ytimg.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.1 Host: i1.ytimg.com Proxy-Connection: keep-alive Referer: http://www.youtube.com/v Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/x-cross-domain Last-Modified: Fri, 27 Aug 2010 02:31:32 GMT Date: Tue, 15 Feb 2011 19:16:36 GMT Expires: Tue, 22 Feb 2011 19:16:36 GMT Vary: Accept-Encoding X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block Cache-Control: public, max-age=604800 Age: 7466 Content-Length: 102 <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://i2.ytimg.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.1 Host: i2.ytimg.com Proxy-Connection: keep-alive Referer: http://www.youtube.com/v Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Content-Type: text/x-cross-domain Last-Modified: Fri, 27 Aug 2010 02:31:32 GMT Date: Tue, 15 Feb 2011 20:24:31 GMT Expires: Tue, 22 Feb 2011 20:24:31 GMT Vary: Accept-Encoding X-Content-Type-Options: nosniff Server: sffe X-XSS-Protection: 1; mode=block Cache-Control: public, max-age=604800 Age: 3393 Content-Length: 102 <?xml version="1.0"?> <cross-domain-policy> <allow-access-from domain="*" /> </cross-domain-policy> |
Severity: | High |
Confidence: | Certain |
Host: | http://i3.technet |
Path: | /clientaccesspolicy.xml |
GET /clientaccesspolicy.xml HTTP/1.0 Host: i3.technet.microsoft.com |
HTTP/1.0 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI" X-Powered-By: ASP.NET ntCoent-Length: 339 Date: Tue, 15 Feb 2011 21:52:56 GMT Content-Length: 339 Connection: close <?xml version="1.0" encoding="utf-8" ?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="*"> <domain uri="*"/> </allow-from> <gra ...[SNIP]... |
Severity: | Medium |
Confidence: | Tentative |
Host: | http://i1.services.social |
Path: | /search/Widgets/SearchBox |
GET /search/Widgets/SearchBox Host: i1.services.social Proxy-Connection: keep-alive Referer: http://technet.microsoft Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: omniID=1297806178674_91c6 |
HTTP/1.1 400 Bad Request Content-Length: 1647 Content-Type: text/html Server: Microsoft-IIS/7.5 X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET P3P: CP=ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI Server: CO1VB32 Cache-Control: private, max-age=86400 Date: Tue, 15 Feb 2011 21:46:43 GMT Connection: close Vary: Accept-Encoding ...<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://i2.technet |
Path: | /Areas/Sto/Content |
GET /Areas/Sto/Content Host: i2.technet.microsoft.com Proxy-Connection: keep-alive Referer: http://technet.microsoft Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: omniID=1297806178674_91c6 |
HTTP/1.1 200 OK Cache-Control: public,max-age=1296000 ntCoent-Length: 163333 Content-Type: application/javascript Last-Modified: Thu, 27 Jan 2011 06:56:36 GMT Accept-Ranges: bytes ETag: "77bcc256efbdcb1:0" Server: Microsoft-IIS/7.5 P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI" X-Powered-By: ASP.NET P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI" X-Powered-By: ASP.NET Date: Tue, 15 Feb 2011 21:43:41 GMT Connection: close Vary: Accept-Encoding Content-Length: 163333 .../* * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js ...[SNIP]... $4)#7=s.mr($C,(vt@tt`Zvt) ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://i2.technet |
Path: | /platform/Controls |
GET /platform/Controls Host: i2.technet.microsoft.com Proxy-Connection: keep-alive Referer: http://technet.microsoft Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.98 Safari/534.13 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: MC1=GUID=688642bf9d1 |
HTTP/1.1 200 OK Cache-Control: public, max-age=15552000 Expires: Sun, 14 Aug 2011 02:31:36 GMT Last-Modified: Thu, 27 Jan 2011 07:13:21 GMT ETag: -1375583617 Server: Microsoft-IIS/7.5 P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI" X-Powered-By: ASP.NET X-AspNet-Version: 4.0.30319 Content-Type: text/javascript Cteonnt-Length: 62869 Vary: Accept-Encoding Date: Tue, 15 Feb 2011 23:04:29 GMT Connection: close Content-Length: 62869 var _om_gbls={omniGuidPath:"" ...[SNIP]... #7=s.mr($C,(vt@tt`Zvt)`fs ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://i1.ytimg.com |
Path: | /crossdomain.xml |
GET /robots.txt HTTP/1.0 Host: i1.ytimg.com |
HTTP/1.0 200 OK Content-Type: text/plain Last-Modified: Fri, 27 Aug 2010 02:31:32 GMT Date: Tue, 15 Feb 2011 21:21:03 GMT Expires: Tue, 15 Feb 2011 21:21:03 GMT Cache-Control: private, max-age=0 X-Content-Type-Options: nosniff Server: sffe Content-Length: 37 X-XSS-Protection: 1; mode=block User-Agent: * Disallow: / Noindex: / |
Severity: | Information |
Confidence: | Certain |
Host: | http://i2.ytimg.com |
Path: | /crossdomain.xml |
GET /robots.txt HTTP/1.0 Host: i2.ytimg.com |
HTTP/1.0 200 OK Content-Type: text/plain Last-Modified: Fri, 27 Aug 2010 02:31:32 GMT Date: Tue, 15 Feb 2011 21:21:05 GMT Expires: Tue, 15 Feb 2011 21:21:05 GMT Cache-Control: private, max-age=0 X-Content-Type-Options: nosniff Server: sffe Content-Length: 37 X-XSS-Protection: 1; mode=block User-Agent: * Disallow: / Noindex: / |