1. Cross-site scripting (reflected)
2. Password field with autocomplete enabled
2.1. http://en.wordpress.com/about/
2.2. http://en.wordpress.com/advanced-services/
2.3. http://en.wordpress.com/features/
2.4. http://en.wordpress.com/firehose/
2.5. http://en.wordpress.com/products/
2.6. http://en.wordpress.com/stats/
3. Cookie scoped to parent domain
4. Cross-domain script include
4.1. http://en.wordpress.com/about/
4.2. http://en.wordpress.com/advanced-services/
4.3. http://en.wordpress.com/features/
4.4. http://en.wordpress.com/features/
4.5. http://en.wordpress.com/firehose/
4.6. http://en.wordpress.com/products/
4.7. http://en.wordpress.com/products/
4.8. http://en.wordpress.com/stats/
5. Cookie without HttpOnly flag set
Severity: | High |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /public-charts/flot.php |
POST /public-charts/flot.php HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com Content-Length: 66 Origin: http://en.wordpress.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Content-Type: application/x-www-form Accept: text/html, */*; q=0.01 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 blog=14899185&target=stat |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:29 GMT Content-Type: text/html; charset=utf-8 Connection: close Vary: Accept-Encoding X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. Content-Length: 41346 <script type="text/javascript"> var graph = null, tooltip = null, previousFlotPoint = null; function yaxis_tick_formatter( val, axis ) { var dec = 0; if ( axis.max < 1 ) dec = 2; ...[SNIP]... styles[leftright] = x + xoffset; styles[topbottom] = y; tooltip = jQuery( html ).css( styles ).appendTo("body").show() } function bindTooltips( graph ) { jQuery("#stat-chart-posts4271d</script><script graph.unhighlight(); if ( item ) { item.series.color = '#ffae00'; graph.highlight( item.series, item.datapoint ); if ( pre ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /about/ |
GET /about/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:19:22 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:16:28 +0000 Cache-Control: max-age=126, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Set-Cookie: hiab=on; path=/; domain=.wordpress.com Link: <http://wp.me/P1-4f>; rel=shortlink X-nananana: Batcache Content-Length: 25362 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <div id="adminbar"> <form name="loginform" class="login-form" id="adminbarlogin" action="https://en <label class="login userlogin-label" id="userlogin_label"> ...[SNIP]... </span><input class="adminbar-input user-pass-input" type="password" name="pwd" id="user_pass" value="" tabindex="2" /></label> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /advanced-services/ |
GET /advanced-services/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:19:42 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:17:53 +0000 Cache-Control: max-age=191, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-7R>; rel=shortlink X-nananana: Batcache Content-Length: 24283 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <div id="adminbar"> <form name="loginform" class="login-form" id="adminbarlogin" action="https://en <label class="login userlogin-label" id="userlogin_label"> ...[SNIP]... </span><input class="adminbar-input user-pass-input" type="password" name="pwd" id="user_pass" value="" tabindex="2" /></label> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /features/ |
GET /features/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:18:22 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:13:46 +0000 Cache-Control: max-age=24, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Set-Cookie: hiab=on; path=/; domain=.wordpress.com Link: <http://wp.me/P1-66>; rel=shortlink X-nananana: Batcache Content-Length: 35391 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <div id="adminbar"> <form name="loginform" class="login-form" id="adminbarlogin" action="https://en <label class="login userlogin-label" id="userlogin_label"> ...[SNIP]... </span><input class="adminbar-input user-pass-input" type="password" name="pwd" id="user_pass" value="" tabindex="2" /></label> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /firehose/ |
GET /firehose/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:13 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:31:13 +0000 Cache-Control: max-age=300, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-jH>; rel=shortlink X-nananana: Batcache Content-Length: 24211 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <div id="adminbar"> <form name="loginform" class="login-form" id="adminbarlogin" action="https://en <label class="login userlogin-label" id="userlogin_label"> ...[SNIP]... </span><input class="adminbar-input user-pass-input" type="password" name="pwd" id="user_pass" value="" tabindex="2" /></label> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /products/ |
GET /products/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:30:54 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:26:04 +0000 Cache-Control: max-age=10, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-5u>; rel=shortlink X-nananana: Batcache Content-Length: 32461 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <div id="adminbar"> <form name="loginform" class="login-form" id="adminbarlogin" action="https://en <label class="login userlogin-label" id="userlogin_label"> ...[SNIP]... </span><input class="adminbar-input user-pass-input" type="password" name="pwd" id="user_pass" value="" tabindex="2" /></label> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /stats/ |
GET /stats/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 If-Modified-Since: Mon, 15 Aug 2011 16:12:52 +0000 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:12 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:27:49 +0000 Cache-Control: max-age=97, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-8R>; rel=shortlink X-nananana: Batcache Content-Length: 32635 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <div id="adminbar"> <form name="loginform" class="login-form" id="adminbarlogin" action="https://en <label class="login userlogin-label" id="userlogin_label"> ...[SNIP]... </span><input class="adminbar-input user-pass-input" type="password" name="pwd" id="user_pass" value="" tabindex="2" /></label> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /signup/ |
GET /signup/?ref=bigasso Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://wordpress.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 302 Found Server: nginx Date: Mon, 15 Aug 2011 16:16:59 GMT Content-Type: text/html; charset=utf-8 Connection: close X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. Set-Cookie: ref=bigassorangeonleft; path=/; domain=wordpress.com Location: https://en.wordpress.com Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /about/ |
GET /about/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:19:22 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:16:28 +0000 Cache-Control: max-age=126, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Set-Cookie: hiab=on; path=/; domain=.wordpress.com Link: <http://wp.me/P1-4f>; rel=shortlink X-nananana: Batcache Content-Length: 25362 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s1.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /advanced-services/ |
GET /advanced-services/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:19:42 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:17:53 +0000 Cache-Control: max-age=191, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-7R>; rel=shortlink X-nananana: Batcache Content-Length: 24283 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s1.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /features/ |
GET /features/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:18:22 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:13:46 +0000 Cache-Control: max-age=24, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Set-Cookie: hiab=on; path=/; domain=.wordpress.com Link: <http://wp.me/P1-66>; rel=shortlink X-nananana: Batcache Content-Length: 35391 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp ...[SNIP]... </style> <script src="http://s0.wp.com/wp <script src="http://s0.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp <script type="text/javascript" src="http://s.skimre ...[SNIP]... </script> <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /features/ |
GET /features/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 If-Modified-Since: Mon, 15 Aug 2011 16:13:46 +0000 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:23 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:30:33 +0000 Cache-Control: max-age=250, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Set-Cookie: hiab=on; path=/; domain=.wordpress.com Link: <http://wp.me/P1-66>; rel=shortlink X-nananana: Batcache Content-Length: 35470 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </style> <script src="http://s2.wp.com/wp <script src="http://s2.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s1.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp <script type="text/javascript" src="http://s.skimre ...[SNIP]... </script> <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /firehose/ |
GET /firehose/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:13 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:31:13 +0000 Cache-Control: max-age=300, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-jH>; rel=shortlink X-nananana: Batcache Content-Length: 24211 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /products/ |
GET /products/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 If-Modified-Since: Mon, 15 Aug 2011 16:26:04 +0000 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:22 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:31:08 +0000 Cache-Control: max-age=286, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-5u>; rel=shortlink X-nananana: Batcache Content-Length: 32376 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s1.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </style> <script src="http://s0.wp.com/wp <script src="http://s0.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /products/ |
GET /products/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:30:54 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:26:04 +0000 Cache-Control: max-age=10, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-5u>; rel=shortlink X-nananana: Batcache Content-Length: 32461 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s2.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </style> <script src="http://s2.wp.com/wp <script src="http://s2.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s1.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /stats/ |
GET /stats/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 If-Modified-Since: Mon, 15 Aug 2011 16:12:52 +0000 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:12 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:27:49 +0000 Cache-Control: max-age=97, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-8R>; rel=shortlink X-nananana: Batcache Content-Length: 32635 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <link rel='stylesheet' id='post-reactions-css' href='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s0.wp.com/wp <script type='text/javascript' src='http://s1.wp.com/wp ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://s2.wp.com/wp ...[SNIP]... <![endif]--> <script type="text/javascript" src="http://s2.wp.com/wp ...[SNIP]... </script> <script type="text/javascript" src="http://edge ...[SNIP]... </noscript> <script type='text/javascript' src='http://s.gravatar ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp ...[SNIP]... </script> <script type='text/javascript' src='http://s2.wp.com/wp <script type="text/javascript" src="http://s.skimre ...[SNIP]... </script> <script type="text/javascript" src="http://b.scorec ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /signup/ |
GET /signup/?ref=bigasso Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://wordpress.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 302 Found Server: nginx Date: Mon, 15 Aug 2011 16:16:59 GMT Content-Type: text/html; charset=utf-8 Connection: close X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. Set-Cookie: ref=bigassorangeonleft; path=/; domain=wordpress.com Location: https://en.wordpress.com Content-Length: 0 |
Severity: | Information |
Confidence: | Certain |
Host: | http://en.wordpress.com |
Path: | /firehose/ |
GET /firehose/ HTTP/1.1 Host: en.wordpress.com Proxy-Connection: keep-alive Referer: http://en.wordpress.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __qca=P0-1122904968 |
HTTP/1.1 200 OK Server: nginx Date: Mon, 15 Aug 2011 16:31:13 GMT Content-Type: text/html; charset=UTF-8 Connection: close Vary: Accept-Encoding Last-Modified: Mon, 15 Aug 2011 16:31:13 +0000 Cache-Control: max-age=300, must-revalidate Vary: Cookie X-hacker: If you're reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header. X-Pingback: http://wordpress.com Link: <http://wp.me/P1-jH>; rel=shortlink X-nananana: Batcache Content-Length: 24211 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org generated ...[SNIP]... <p>Please contact us at firehose-2010@wordpress ...[SNIP]... |